--- title: "Tanya Janca -- Secure Guardrails" url: https://appsecpodcast.com/tanya-janca-secure-guardrails/ date: 2024-07-09 duration_seconds: 3890 season: 11 episode: 17 guests: ["Tanya Janca"] topics: ["Secure Development", "Security Testing", "Cloud and Infrastructure", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/15383701-tanya-janca-secure-guardrails.mp3 video: https://www.youtube.com/watch?v=xoITqZgRs3I transcript: true --- # Tanya Janca -- Secure Guardrails *July 9, 2024 · 1 hr 5 min · Season 11, episode 17* with [Tanya Janca](https://appsecpodcast.com/guests/tanya-janca/) on [Secure Development](https://appsecpodcast.com/topics/secure-development/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Cloud and Infrastructure](https://appsecpodcast.com/topics/cloud-and-infrastructure/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/15383701-tanya-janca-secure-guardrails.mp3) · [Video](https://www.youtube.com/watch?v=xoITqZgRs3I) ## Show notes Tanya Janka, also known as SheHacksPurple, discusses secure guardrails, the difference between guardrails and paved roads, and how to implement both in application security. Tanya is an award-winning public speaker and head of education at SEMGREP and the best-selling author of ‘Alice and Bob Learn Application Security’. Tanya shares her insights on creating secure software and teaching developers in this episode. Tanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She's also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya's been coding and working in IT for over 25 years. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Tanya Janca: → [Tanya Janca on LinkedIn](https://www.linkedin.com/in/ranakhalil1) → [Alice and Bob Learn Application Security](https://shehackspurple.ca/books/) Mentioned in this episode: → [Alice and Bob Learn Application Security](https://shehackspurple.ca/books/) → [Semgrep](https://semgrep.dev/) → [Tanya Janca – What Secure Coding Really Means](https://youtu.be/HpD_7JvK_-A) → [The Expanse Series](https://www.jamessacorey.com/) → [Alice and Bob Learn Application Security](https://www.wiley.com/en-us/Alice+and+Bob+Learn+Application+Security-p-9781119687405) → [Tanya Janca (SheHacksPurple)](https://shehackspurple.ca/) → [Azure DevOps](https://azure.microsoft.com/en-us/products/devops) → [Microsoft Security Response Center (MSRC)](https://www.microsoft.com/en-us/msrc) → [Microsoft Defender for Cloud](https://www.microsoft.com/en-us/security/business/cloud-security/microsoft-defender-cloud) → [Content-Security-Policy (MDN)](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy) → [Scott Helme](https://scotthelme.co.uk/) → [Kim Wuyts](https://twitter.com/wuytski) → [Executive Order 14028](https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity) → [OWASP SAMM](https://owaspsamm.org/) Chapters: 00:00 Meet Tanya Janca: Secure Guardrails 05:09 Oh, that's so cool. So what, what are you excited about 06:49 Oh, that's great. That's, yeah, it's a, that's a fun thing 10:05 I was like, no, no, I'm good. And it was like 12:05 So based on the example that you just shared there, Now 15:55 Would you like to use the wrapper library 17:36 Am I willing to break the build 19:41 Oh, actually, you know what 22:39 What's the role of making it easy with the paved road 24:58 Right 26:53 Makes sense. Makes sense. That's, that's, uh, it's helpful just to 30:18 I have to go rotate the secret, yada, yada, yada, right 32:58 Like, because getting into buildings when you should not is a 34:18 No, no, it's good. It's good. So I guess one more 37:48 Someone else told me she did that and it said, this 40:19 All right. One more guardrail topic. And this is one that 43:05 Right 46:24 It's time for her to come back again. She has been 47:38 No 50:13 We've all gotten those though for, for plenty of times in 53:34 Um, and so then we talked about it and I'm like 57:14 So I'm going to do the top programming frameworks as well 61:11 Oh, nice. Very cool. Very cool. So, just to kind of ## Transcript *11,618 words · assemblyai* **0:00 Chris Romeo:** Tanya Jenka, also known as She Hacks Purple, is the bestselling author of Alice and Bob Learn Application Security. She's also the head of education and community at Semgrep, sharing content and training around teaching everyone to create secure software. Tanya's been coding and working in IT for over 25 years. She's won countless awards and has been everywhere from public service to tech giants, writing software, leading communities, founding companies, and securing all the things. She's an award-winning public speaker, an active blogger, and has delivered hundreds of talks on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives. Tanya joins us to discuss secure guardrails, the difference between guardrails and paved roads, creating secure guardrails, and we even unpack whether there's such a thing as a privacy guardrail. **0:54 Robert Hurlbut:** The Application Security Podcast is brought to you by Security Journey. **0:58 Tanya Janca:** We help enterprises reduce vulnerabilities through application security education for developers and everyone in the SDLC. **1:05 Robert Hurlbut:** Learn more at securityjourney.com. **1:06 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of Devichi, a general partner at Curve Ventures. Normally, I'm joined by my good friend, Robert Horvath, Robert was having some connectivity issues. I'm convinced he was trying to connect to this recording via a 2400 baud modem, and he just didn't have the settings right. For those people that remember, he had 7. I don't remember what the other option was. N zero. I don't remember what the N stood for, what you could change it to. But those that have been around a long time will get that joke. And if you ever used a modem and you made the settings wrong, super excited to have Tanya Jenkins, very well known. Across our industry here. And I did a little bit of calculating. This is Tanya's 4th appearance on the podcast, and that ties her with Jim Manico for most appearances. And she and Jim are, are one below the first place, Adam Szostak, who has made 5 appearances on the Application Security Podcast. But if you want to catch any of those other episodes that Tanya did with us over in the past, There was an episode on hacking APIs with DevSwap. There was another one on DevSwap, the movement. And then in October of '23, we talked about what secure coding really means. So if you want to go back and check out any of those, feel free to tap into all of the things we've talked about in the past, and you'll hear Tanya's origin story way back in that 2017 episode. So instead of an origin story, Tanya, I'm trying to reach out to the kind of lighter side of application security. And I want to encourage people to go outside. So what are your hobbies that you like to do that do not include technology? **3:02 Robert Hurlbut:** So in 2022, I bought a hobby farm. And so before that, I was really obsessed with gardening. And I had dug up my front lawn and my back lawn, And made 17 raised beds with my significant other. And then we built 2 greenhouses together and it was like, there's no space left on any of the property at all that we're not growing something. **3:30 Tanya Janca:** So I was like, I think it's time to get some acres. And so, um, we have 3 really big greenhouses and we just bought a 4th one. And as I was telling you before we started recording, a very exciting gardening or farming milestone? We bought our first tractor. **3:48 Robert Hurlbut:** Oh yeah, it's used and it's old and I have to learn to drive manual, but you're going to see cute pictures of me with a straw hat on it starting very soon. **3:57 Chris Romeo:** Oh, that's great. That's, uh, I also recently, I wouldn't say that I've gone down the farming route yet, but have bought some property and in the process of Spending a lot more time outside. So that's, I think there's a, there's a kind of an angle for all of us in technology here. You got to find something to do outside. You got to put the computer down. And I think I've said this before, but I'm going to say it again. When I hear about people that work in front of a computer for 8 hours a day, and then they switch to another computer to play games for 8 more hours, it's like, people, let's go outside. There's got to be something to do outside. **4:36 Tanya Janca:** I have an Oura ring and it's, it measures my stress and it's really funny, Chris. **4:42 Robert Hurlbut:** So I remember the first couple of times I saw it, I thought it was broken, but when I go into my garden, the stress meter, it's literally so low it can't measure any. Like it goes, it completely goes off the chart. **4:57 Tanya Janca:** There's no measurable stress. **4:58 Robert Hurlbut:** It's like, you're so zen. And sometimes it's like, you're really zen right now. Keep that up. **5:03 Tanya Janca:** I'm like, no problem. Why did you have to alert me? Aura, shut up. **5:07 Robert Hurlbut:** I'm in my garden. **5:08 Chris Romeo:** Oh, that's so cool. So what, what are you excited about that you're growing for this year? So I mean, it's like something new maybe. **5:16 Robert Hurlbut:** So last year, actually the year before I started growing dahlias, last year I started growing lilies. And this year my partner and I cleared away a bunch of extra trees. And so now I have a 50-foot by maybe 70-foot dahlia garden. So we're talking like thousands of dahlias. **5:38 Tanya Janca:** So last year people came, I planted them because I think they're pretty. And this lady said, hey, could I buy some? And I'm like, obviously those are for sale. **5:46 Robert Hurlbut:** And before I knew it, I'd made $2,000 from like just clipping the extra flowers. And I still like having some for myself and friends and stuff. And so this year we're actually exerting effort to that end. **5:58 Tanya Janca:** And my first lily and my first dahlia bloomed right before I left. And so I suspect I'm going to get back from San Francisco and be just like in this explosion of flowers. And I didn't used to like flowers, Chris. **6:12 Robert Hurlbut:** I was like, you can't eat them. What are they good for? And then, and then one day, like, I, my friends started growing them. **6:18 Tanya Janca:** I'm like, they are really pretty. **6:19 Robert Hurlbut:** Like, I get it. **6:20 Tanya Janca:** And then I cut some flowers and I gave them to my neighbor and the look in her face of like utter joy and happiness. She's like, for me? **6:29 Robert Hurlbut:** I'm like, yeah, Diane. And she just like, her face just like crumbled with happiness. **6:34 Tanya Janca:** And so I discovered you could just give flowers to almost anyone and they're really happy. I'm like, what? Like, I've been doing this my whole life. I really like flowers. It turns out I'm full middle-aged woman now. I drink Coke Zero too. **6:48 Chris Romeo:** Oh, that's great. That's, yeah, it's a, that's a fun thing to share there about. It's a way to lighten up somebody else's day just by thinking of them. And I think it's a bit of a metaphor for just the current state of the world. People don't exert kindness and niceness towards other people. Like, I feel like they used to when I was growing up. And a lot of times people were yelling at me for things I was doing when I was growing up, but It seems like it was a different era though, right? Where people were more friendly, they were nicer to each other. And I think the pandemic, we lost a little bit of that, but you're bringing a little bit of it back at a time just by bringing flowers to, uh, to people around your community and, uh, putting smiles on people's faces. That's really cool. **7:33 Tanya Janca:** Thank you. **7:34 Chris Romeo:** Well, I guess we should talk about application security in some regard. I mean, this is almost turned into the The, uh, technology, the, the Technologists That Farm podcast is almost what we, we turned into here, which would've been, I think, pretty interesting. I would've listened to that if somebody ever created it. But okay, I guess the, the topic you wanted to, to chat about now, and it's one that I've been thinking about quite a bit as well, is this idea of secure guardrails. And so I thought we'd start with just, let's just define this. Let's work up a definition. I think most people have probably heard the term, but I've really not seen really great definitions laid out. I've seen people say, well, this is a secure guardrail, but not really give me a definition. So, let's start there. **8:19 Robert Hurlbut:** Okay. **8:21 Tanya Janca:** So, it started, well, basically, at SemRep, someone was like, yeah, secure default, a secure guardrail. **8:30 Robert Hurlbut:** And I was like, those are not the same thing. And they kind of looked at me because I felt very strongly about that. **8:37 Tanya Janca:** And to me, a secure guardrail is some sort of technical implementation that tries to get you— it tells you, hey, you're not doing what you should do from a security perspective. Go back to the paved road. Go back to the secure default or whatever the secure coding policy is. **8:56 Robert Hurlbut:** Go back. **8:56 Tanya Janca:** So, you've done something you shouldn't have done, and it's some sort of alert, or maybe there's a red squiggly in your IDE, or maybe it's blocking you. **9:05 Robert Hurlbut:** from checking in your code 'cause there's a secret in there, whatever the thing is, but basically something to the effect of, you've gone down the wrong path. **9:17 Tanya Janca:** Where a secure default is, this is what we would like you to do. This is the most secure way to do the thing. **9:23 Robert Hurlbut:** We try to make it a default in every opportunity so that it's easiest to do the thing we want you to do. So, the first time I ran up against one of these was when I was at Microsoft and I was making— so, I was on your podcast at the time and I was making really terrible demos, like terribly insecure demos, so that I could show off what not to do. And then we would fix it together and then show them what you should do. **9:52 Tanya Janca:** And so, I checked in a connection string and Azure DevOps was like, hey, That looks like a connection string you're trying to check in, and there's a secret in there, and I don't think so. **10:05 Robert Hurlbut:** And I was like, no, no, I'm good. And it was like, mm-mm, no. And, you know, Azure DevOps and I had a little argument, and then I said, I'm a dev, so I won, right? I'm like, you think a technical control can stop me? **10:16 Tanya Janca:** And so I checked it in, and then my boss calls me and he's like, Tanya, Azure just called me and told me you checked a secret into production. And like, oh, I'm developer relations. **10:30 Robert Hurlbut:** All I do is make demos. **10:31 Tanya Janca:** I'm not allowed to touch production. **10:33 Robert Hurlbut:** But yes, I did check a pretend secret into a demo database with nothing in it except 2 records that are for my demo. **10:42 Tanya Janca:** And I have a firewall around it, et cetera. **10:44 Robert Hurlbut:** And I'm like, but yeah, I did that. And then he's like, oh, Azure's angry with you. That's really funny. **10:49 Tanya Janca:** Like you're making demos and you got it all upset. And then, I had a beep on my phone, and then Microsoft Security Incident Response team called me. Yeah, and they didn't find it funny like me and my boss did, that Azure was upset with me. **11:05 Robert Hurlbut:** And the fact that I triggered a real security incident with my pretend demo secrets was not a way to make friends or influence people. And I had to spend some time kind of earning back some trust there. **11:19 Tanya Janca:** But, but I, but it alerted me, hey, you're not doing what you should do. You're going off-roading, right? **11:26 Robert Hurlbut:** And I was like, I know I'm doing that. I am comfortable doing that because this is intentional. It's a demonstration of what not to do. **11:33 Tanya Janca:** The secret doesn't actually go anywhere, et cetera. But if it had been a real secret and it had been a mistake, it would've been pretty helpful, right? And that we would've avoided a real security incident. **11:45 Robert Hurlbut:** So, so the idea of a guardrail is just, hey, that's not what we're— **11:51 Tanya Janca:** that's not what we do here. **11:53 Robert Hurlbut:** We think you should do this. And so any sort of technical control that does that, just the same as like what real physical guardrails do on a road, right? It's like, it's clear, if you're hitting a guardrail, you've got a problem. **12:04 Chris Romeo:** Okay, so based on the example that you just shared there, Now I'm wondering, are there 2 different types of guardrails? Or should there be 2 different types of guardrails? And I'm just totally making this up on the fly. Is there, or should there be a guardrail that is non-bypassable? Meaning, should there have been a guardrail that you couldn't get around? Like, and then there's one that is a little bit more fluid, that a lot like is what you experienced with the Azure DevOps example. Where you, it said you shouldn't do this, but then you kind of had a way to get around it. Like, is there, so are there 2 different types then in your mind? **12:46 Robert Hurlbut:** Okay. So that's a good question. And no one's asked me that before. So I'm going to be annoying and pass the question back to you. **12:54 Tanya Janca:** Do you think there's a technical control that can stop a really good software developer? **12:59 Chris Romeo:** I think there's a technical control that can stop 99 out of 100. Really good software developers, not 100 out of 100, but I think, I think there's, and when I, 'cause when I think about this issue, I think with the guardrail, it's supposed to be designed in such a way that you can't, like it gives you freedom in the middle. Like you could, you can drive in the, in the, the lane, you can go into the other lane to pass people. You can even go on the shoulder. And do something a little bit crazier, but you can't go off the side of the mountain though. Like you're, it's keeping you there. And so now I'm starting to think like, is it, is it a guardrail then if you were able to bypass the control? That's, and I'm really literally just noodling this live here. This isn't something I've spent a lot of time thinking about. **13:53 Tanya Janca:** So a real guardrail, like on a road, you can drive through it. It in by accident, if you're, you know, high speeds getting hit, et cetera, or on purpose, which I would think would be extremely rare, right? **14:10 Robert Hurlbut:** But I would say that certain things I want in blocking mode. **14:15 Tanya Janca:** Like, to be quite frank, if it looks like a secret, I'd really like it to be in blocking mode, period, right? Because Azure DevOps did not stop me. **14:24 Chris Romeo:** Yeah. **14:25 Tanya Janca:** And what if I was just, what if I was belligerent and it was a real secret? **14:30 Robert Hurlbut:** And I was like, listen, you know, this is due today. I just gotta do it. **14:33 Tanya Janca:** I'll switch the secret later. Right? **14:35 Robert Hurlbut:** Um, one of the other devs on my team, she was livestreaming and she accidentally showed her secret to everyone while she was livestreaming just by accident. **14:45 Tanya Janca:** And she's like, oh no. Uh, and so she rotated it live and, and then hid the new secret successfully, right? **14:52 Robert Hurlbut:** Mm-hmm. **14:53 Tanya Janca:** But she's like, that was the longest 30 seconds of my career where it was like, oh gosh, I hope my audience are not jerks today and trying, trying to do something. Right. And so, um, and, and all of her followers, like nothing happened. Everything was fine. **15:09 Robert Hurlbut:** Right. **15:09 Tanya Janca:** But if you could block a secret, I think that's something you would wanna block for sure. But there's some things where I think it's less important. **15:18 Robert Hurlbut:** So you might wanna have a guardrail. **15:20 Chris Romeo:** Yeah. **15:21 Tanya Janca:** So let's say you have a coding guideline and you want everyone to use camelCase. If someone doesn't use camelCase, are you going to make their whole day terrible and like, be like, no, I'm sorry, you can't go to, you can't check your code in? Is it worth it? **15:37 Robert Hurlbut:** Are we going to create a lot of friction with our software developers if we have hundreds of things, but maybe there's hundreds of like Warnings, I'd like to give them like maybe a little squiggly line that's like, hey, you're using innerHTML. **15:52 Tanya Janca:** That's not advisable unless you use this wrapper library. **15:55 Robert Hurlbut:** Would you like to use the wrapper library? **15:57 Tanya Janca:** Wink, wink, wink. **15:58 Robert Hurlbut:** So either please don't use this function or use it with the wrapper. **16:02 Tanya Janca:** We're not seeing that combination we want to see, right? And then if the developer doesn't do it, does that issue an alert for the security team to talk to them? Are they not allowed to check in their code? **16:14 Robert Hurlbut:** I think that. **16:15 Tanya Janca:** The more times you block a developer, the less likely they're going to be friendly with the security team, especially if it's like something that's not the end of the world. **16:25 Robert Hurlbut:** So innerHTML, for those listening, is— **16:27 Tanya Janca:** it's often the cause of cross-site scripting when it, when it's used without really good input validation or sanitization or escaping and then output encoding. **16:38 Robert Hurlbut:** So you can have a really bad day. **16:39 Tanya Janca:** If you use it without a wrapper library. **16:43 Robert Hurlbut:** And so, but, but if you're using a wrapper library that your AppSec team built for you, maybe you're having a great day, right? So, I feel, I feel like that would be something worth blocking on, but maybe there's a lot of other things where it's like, do I wanna pick a fight with a developer about this? **17:01 Tanya Janca:** I don't know if it's worth it. **17:02 Robert Hurlbut:** So, I would say some blocking, some not blocking. Mm-hmm. So, Quite often, definitely blocking secrets when you check in. **17:11 Tanya Janca:** I would say if I have an IDE plugin from a SaaS, have like those red squigglies to tell you all the things I don't like, all my feelings. **17:19 Robert Hurlbut:** But then when you go to check the code in, maybe the CI/CD is like, I'm gonna break on innerHTML, but I'm not, I don't care about camelCase. **17:28 Tanya Janca:** Maybe there'll be an email later of your poor form. Like, why are all your variables terribly named? Or whatever, right? **17:35 Robert Hurlbut:** But am I willing to break the build? I don't know. **17:38 Chris Romeo:** I could see some of that being dependent on the organization type, the vertical. Like, I could see financial organizations being very stringent because they just tend to be more stringent with their policies when it comes to everything that they do. But because they're protecting our money from being transferred to somebody else's account, that's the culture that exists in those places, but it's based on the amount of risk that they have in running their business. And so I could see some of those kind of, I like that idea of blocking versus, I don't want to call them open guardrails, but non, maybe non-blocking, I think might've been the word you used, blocking versus non-blocking. So I think that's something that makes sense to have that amount of Control, because there's some things, like you said, that are non-negotiable and there's other things that are, that are, that can be negotiated. Okay. Paved roads. So you hear guardrails and paved roads, and I think Netflix was one of the organizations that popularized both of these terms. From your perspective, what's, what is a paved road then? And then what's the, what's the difference and, and how do they work together or do they oppose each other? How do you see these? Working. **18:58 Tanya Janca:** I would, I would say a paved road, in my opinion, is the same thing as a secure default. So it's the path we would really like them to follow. So as an example, we want you to not use innerHTML, or let's say like the with statement in JavaScript. We're like, hey, it's kind of dangerous. We'd prefer you not use it, like just at all. I don't care if there's a wrapper library, we'd just really like it if you didn't. Okay. So every time we see that, maybe there's other functions that we would rather direct you to, or maybe we're just like, no way, Jose. So the paved road does not have the with statement in it. **19:41 Robert Hurlbut:** Oh, actually, you know what? **19:41 Tanya Janca:** Let me give you a better example. Let's say there's a function you'd really like them to use instead. Okay. So like the, um, Speaking of some secure coding lessons I gave recently, but let's say we really want you to use certain security headers. That's on the paved road. The paved road is we use these security headers here at this org. That's what we do. And so we see, oh, you don't have those security headers in this code. That's weird. You're not, you're, you're off-roading. You're not on the paved road. We'd really like you to use these. **20:13 Robert Hurlbut:** And, and we use them in this way. **20:15 Tanya Janca:** Like, let's say there's pre-made settings. **20:17 Robert Hurlbut:** So. **20:18 Tanya Janca:** When I teach secure coding, I actually have like a cheat sheet with literally exactly what I would prefer that you, you do so that they can just turn it into a policy. Granted, I open it at their desk, copy paste mindlessly for everything other than Content Security Policy header, which is more complex, but I still want you to use it. **20:36 Robert Hurlbut:** But so it's like, this is the paved road. **20:39 Tanya Janca:** This is the road we'd like you to go down, the one that includes security headers. And so It's a, the default is that we do use them. **20:47 Robert Hurlbut:** And if you're not using them, maybe you need an exception, right? **20:51 Tanya Janca:** Like maybe you need a written exception as to why you are not using HSTS or whatever it is. **20:58 Robert Hurlbut:** And like, if you're not, there better be a good reason. You know what I mean? Okay. **21:03 Tanya Janca:** I feel strongly about security headers. Anyway, the point is, I'm a little obsessed. We, we in Scott Helm, we like I already went on this topic a lot, but the paved road being that this is a path that the security team has specifically planned out for you. So there's lots of coding that you're going to do all day long that the security team, like, we want it to be secure, but we haven't thought it all out because it's not important to us because there's no security control involved and there's no known bad functions. There's no design flaw or threat that we're aware of. So just freestyle, do whatever you want. **21:41 Robert Hurlbut:** But, you know, let's say you're doing authentication. **21:43 Tanya Janca:** It's like, this is how we do it here. This is how we manage sessions here. **21:47 Robert Hurlbut:** This is, you know, we don't cache sensitive data and we always classify our data and we label our data. **21:53 Tanya Janca:** So you should darn well know when you cache stuff, if you're caching something sensitive, right? And so if you see a bunch of data that's not labeled in the database, problem. **22:04 Chris Romeo:** Right? **22:04 Tanya Janca:** And so, the idea of the, in my opinion, the paved road is like, this is stuff we've planned out for you that's the best way to do it for, and like, that's from the security team. I bet that there's lots of senior developers who have style guides and other things that they want to see, and stuff they've built, like functions and that, or classes, whatever, libraries that they really want everyone to use. And it doesn't have to do with security, it has to do with speed, it has to do with style, whatever it is, right? **22:33 Robert Hurlbut:** Yeah. **22:33 Tanya Janca:** Because I've worked at lots of places like that. And so the paved road, the way we want you to go. **22:38 Chris Romeo:** What's the role of making it easy with the paved road from your perspective? Like, and we could just use the, we continue on the headers example, but how do you make headers, do we even dare go, how do you make content security policy a paved road so that it's something that's How can you make it easier for developers? Because I swear there's only like 5 people that understand it total in the world. Apparently you and Scott are 2 of them. I don't know who the other 3 are. They should stand up and raise their hand. But how do you, how do you package that up and make it easier? **23:13 Robert Hurlbut:** Okay. So one thing is training, right? You and I both do or have done lots of training. **23:21 Tanya Janca:** So you teach everyone about it. So content security policy header. the Swiss Army knife of security, right? **23:29 Robert Hurlbut:** It does so many things. But usually what I do specifically, so all the other headers do one thing. Content Security Policy header, it does a whole bunch of cool things. **23:40 Tanya Janca:** And so I generally start with the cross-site scripting defenses, 'cause it does more than this. It's great. But that's what I start with, because cross-site scripting sucks. **23:50 Robert Hurlbut:** And so, and I would like everyone to have less of it. including malicious actors. **23:55 Tanya Janca:** And so I start with that. So I'm like, Content Security Policy header, it's like an SBOM for your app, right? It's a list of all the scripts. It's just an SBOM for your scripts, right? Any third-party things that you're going to let load part of your app, you got to list them out. And I've had developers complain about it, like, oh, do you have to, do you have to like be organized about the app you built? Well, maybe that was be terrible. Yeah, like, of course, you know what's in there. We're just asking you to actually document it because they, they built it, right? Um, and so educating them, making something easy. **24:37 Robert Hurlbut:** So giving them an example of it being implemented, being an example of exactly the way you would like it to be implemented, like each part of the feature, each setting that you would like by default. I'm literally making a PDF. **24:49 Tanya Janca:** So when I teach after, I'm like, here's the PDF checklist for logs, what to log, what not to log. Here's the checklist for this. Here's the checklist for that. **24:58 Robert Hurlbut:** Right? **24:58 Tanya Janca:** So make it literally mindless if you can, so they can copy and paste or print it out, put it at their desk or whatever. **25:04 Robert Hurlbut:** And then for content security policy header, so scaling it can be a pain if, if you have not kept track of any of that in all your legacy stuff, I would say starting with every new Having Content Security Policy header. **25:20 Tanya Janca:** So every new app has it. **25:21 Robert Hurlbut:** And then as you open up old apps, so maybe once a year you do a pen test, maybe that's when CSP starts happening and you just implement the one feature, like listing the scripts. **25:31 Tanya Janca:** And then maybe eventually you talk about forms, et cetera. **25:33 Robert Hurlbut:** Right. And like roll out the features one at a time. **25:37 Tanya Janca:** I feel, I think earlier you asked like, why do we have to make it easy? **25:43 Robert Hurlbut:** And the reason is because otherwise it ain't getting done. **25:46 Tanya Janca:** Right. **25:47 Robert Hurlbut:** Right? If we make it really hard, if we make sure there's a ton of friction, and we don't care about the usability on the side of the software developer, like, we're competing, Chris, you and I, as security folks, we're competing, we're competing with customers asking for features, we're competing with their boss telling them, hey, there's this backlog of whatever tickets you got to go do, we're competing with, like, all these other, like, the usability, the UX people, all this stuff. Right? **26:14 Tanya Janca:** And we're just one of their many priorities. They're our only priority. They're— I'm sure you've heard this before, but like, I feel, and lots of us AppSec feel, they're our customers. **26:26 Robert Hurlbut:** And we are trying to help them make more secure apps. **26:30 Tanya Janca:** And if we have a ton of friction and slow their work down, and especially if we seem not nice or respectful, it's just, Would you want to work with someone like that? **26:41 Robert Hurlbut:** No. Would you? Would you like— and you have like 6 different groups all telling you things they need you to do. **26:47 Tanya Janca:** That guy's gonna be last, in my opinion, in experience. **26:52 Chris Romeo:** Makes sense. Makes sense. That's, that's, uh, it's helpful just to differentiate guardrails, paved roads, putting all these pieces together. So now, let's talk about creating a secure guardrail. And we'll have to use a different example. I feel like we've talked about headers. People are, people are like, probably thinking of all these headers. But how about, how about another example? Like, what, how would we create a secure guardrail for something else? **27:19 Robert Hurlbut:** Okay, so you need a technical control to try to alert or stop the developer from doing the thing. **27:32 Tanya Janca:** So, some options. **27:33 Robert Hurlbut:** So I worked at a SaaS company, so I realize I'm very biased, but SAST works really well, but there's lots of SAST, so you don't have to use ours. You can just use any SAST that lets you write custom rules, which is a whole lot of them. So let's say you have a coding guideline and there's certain, just these functions are no-nos. **27:51 Tanya Janca:** So like eval or exec, we don't want you using those, let's say. **27:58 Robert Hurlbut:** We certainly don't want you passing a variable to them. **28:02 Tanya Janca:** The variables change. **28:04 Robert Hurlbut:** And so we have a guardrail. **28:07 Tanya Janca:** So we write a custom rule that looks for this list of functions that we don't like, we the security team fear. **28:14 Robert Hurlbut:** And then it just alerts you, hey, we don't use those functions here. **28:19 Tanya Janca:** If you're not sure what to do, come talk to the security team or whatever. Sometimes it's that this is the old function and this is the new function. **28:28 Robert Hurlbut:** I have a bunch of those. I'm writing my next book and I have what to do in various languages, but then I have a what not to do. And so it's like, don't use this function, literally use that one. **28:39 Tanya Janca:** Don't use this one, use that one. It's the new one. **28:42 Robert Hurlbut:** Um, and, and so that would be great, like just giving them the advice that says, hey, so we saw you're using this, we don't use this here. Instead, we would prefer, like it says in the secure coding guideline that you agreed to when you worked here, that we use this one instead. **28:58 Tanya Janca:** And almost all developers are like, oh, yeah. **29:03 Robert Hurlbut:** You know what I mean? They're not— a lot of them, they'll get the warning, you know, if they have time to look at it. If for some reason they don't, like maybe they'll miss it, but they look at it and it's like, don't use this one, use this one. It does the same thing, especially if it has the same parameters. Yeah. **29:18 Tanya Janca:** It's very easy to switch out. It's a really low bar to ask them to hop over versus some other things security asks for, like, hey, could you implement OAuth instead of SAML? **29:31 Chris Romeo:** Or, you know what I mean? **29:32 Tanya Janca:** Like, could you switch this framework? Could you update this whole framework? Is that a problem? **29:37 Robert Hurlbut:** Yeah, it is. **29:38 Tanya Janca:** That's some work, right? So anything that you would like them to do, If you, like, from a technical perspective, if you can think of a way to find it. **29:50 Robert Hurlbut:** So custom SAST rules is one. **29:54 Tanya Janca:** When they check their codes in, their code in, doing a pre-commit hook for secrets or pre-commit hook for something that's very high priority, because pre-commit means it's not been saved yet. **30:06 Robert Hurlbut:** And the magic of that, so like, let's say Tanya's connection string. **30:10 Tanya Janca:** was real, once we check the code in, then it goes into our history, and then that secret's spilled. **30:17 Robert Hurlbut:** Then I have to go rotate the secret, yada, yada, yada, right? **30:21 Tanya Janca:** If it's before it's checked in, it tells me I've made this boo-boo, I can stop it. **30:25 Robert Hurlbut:** I don't have to rotate the secret. I just have to fix my boo-boo. **30:29 Tanya Janca:** It can save some time and stop a security incident from happening. So other technical controls, So when I worked at Microsoft, they have this thing called— they've renamed it like 3 times when I worked there, and they've renamed it several times since I left. **30:45 Robert Hurlbut:** So I think it's currently called Azure Defender. **30:49 Tanya Janca:** But basically, they have this list of recommendations. And the top one was always, if you can buy something in Azure, turn on MFA right now. Run, don't walk. **30:58 Robert Hurlbut:** And so what if when the developer logs in, it checks to see if they have MFA? What if for every single account that can change your CIs, like anything in your CI/CD, it checks that you have MFA enabled? **31:15 Tanya Janca:** Because risk. Have you seen the new OWASP Top 10 for CI/CDs? **31:21 Robert Hurlbut:** So, I've seen some of those. I had not seen all of those. I saw this talk at BSides Vancouver about it, and I'd been meaning to read the documents. I'm like, great, I can just go to a talk and have this guy named Farshad tell me all about it. **31:31 Tanya Janca:** It's great. **31:32 Robert Hurlbut:** And it didn't even have all the disasters I've seen, right? And it has some— **31:37 Tanya Janca:** has 10 really terrible things. **31:39 Robert Hurlbut:** And so what if, you know, the first time they log into the CI/CD, it's like, you don't have MFA turned on, you're going to turn that on before you're allowed to configure a CI from now on. **31:52 Tanya Janca:** That's a guardrail, right? **31:54 Robert Hurlbut:** And then if you disable it, it's like, cool, you're logged out till you turn it back on. **32:00 Tanya Janca:** And so all of these things can be guardrails, right? Like, it sounds odd, but things too, like in, um, we were talking about physical guardrails, like not on a road, but for instance, in a building. **32:13 Robert Hurlbut:** So where the— **32:14 Tanya Janca:** I did top secret work, I did counterterrorism work, and that's all I'm allowed to say. But we had all these different levels of security And I remember one of them was this turnstile, and you would go in and they'd have to recognize you, like visually recognize you. And so you'd already like done your badge, and you'd done this, and you'd done that. **32:35 Robert Hurlbut:** And then there was like a certain number of staff, and if they didn't know you, they inked you out of the turnstile. **32:41 Tanya Janca:** And so guardrail. **32:45 Robert Hurlbut:** So that's more like defense in depth, but we're trying to figure out what. **32:50 Tanya Janca:** what could be a physical security guardrail other than a physical guardrail, like, that knocks you literally physically back onto the road. **32:57 Robert Hurlbut:** But like, because getting into buildings when you should not is a whole thing. Mm-hmm. And when I visit the Semgrep office, it's like, what if someone ends up here that shouldn't? And we were talking about this morning, so the biggest IT company in Canada used to be called Nortel, and the Canadian government took them over, all their offices over. **33:24 Tanya Janca:** They had these huge campuses, and they found multiple listening devices in every single room. And now we know why they went out of business. Like, going to different places, like every competitor knew what they were doing. And so I, I was like, we should like sniff all our rooms, right? **33:43 Robert Hurlbut:** Because I'm paranoid. And so it's like, do we have a thing where it's like, if you come in and you have something that looks like, like, then you're not allowed in? It's like, that looks like a listening device. **33:53 Tanya Janca:** Although with phones, that's really hard. **33:55 Robert Hurlbut:** But anyway, there's, but any sort of technical control that tries to knock you back into what you should be doing, like you didn't bring your badge today. **34:03 Tanya Janca:** Well, I'm sorry, I guess you have to walk home. That's a big lesson. **34:06 Robert Hurlbut:** But maybe you have to sign a document. Maybe you have to have someone lock, walk you in, whatever the thing is to encourage the correct behavior that we really want to see. I know that was a tangent. **34:17 Tanya Janca:** I'm sorry. **34:17 Chris Romeo:** No, no, it's good. It's good. So I guess one more specific question on secure guardrails. And that is, when does it make sense to put a guardrail in place from day one? Or is this something that you have to kind of grow into? **34:38 Robert Hurlbut:** Hmm. So that's another thing we were talking about internally. So I'm making this new course and I want to talk about how to act. So a lot of people at conferences talk about secure guardrails, but it's not like, this is how you do it. Because if we want people to do it, then we need to— some of them, they'll just go run off and do it. **35:01 Tanya Janca:** But a lot of people, if you show them how, you'll get more of the results. **35:05 Robert Hurlbut:** Like, if I want my devs to do this, I need to show them how. **35:08 Tanya Janca:** And so, we are talking about that, and I feel that your AppSec program should have a certain level of maturity for how many you're gonna have, right? **35:18 Robert Hurlbut:** So, I think for any organization ever, the first secure, the first 2 would be, you gotta have MFA if you're going, like, you have to have MFA if you're able to edit the CI, if you're able, to delete other people's code. If you, if you have administrative privileges on these extremely powerful systems, you have MFA or no. And the other one would be the secret check-in. **35:41 Tanya Janca:** So, I think every org could benefit from those, period. Even if your AppSec program's somewhat nonexistent, I feel it would offer value. But some are a lot more complex. **35:52 Robert Hurlbut:** Like, if you don't have a coding guideline, if you don't have, like, let's say your AppSec team is one pen tester who only gets to 10% of all your projects and doesn't really offer guidance at this point. 'Cause there, there are a lot of programs that are like that, and that's okay. That's okay that you're starting where you're at, right? Like, we have someone on staff that has this skillset, we're gonna start with this. But I don't think it would make sense to sit there and be like, all of these different things are, are banned and you should be doing something else. Like, maybe that's not gonna go well, or maybe, um, So, writing a secure, a wrapper library. **36:32 Tanya Janca:** So, developers write wrapper libraries for lots of reasons. So, let's say my C# app wants to call a C++ app because it needs to do some weird backend thing with an embedded system. Okay, so I'm gonna write a wrapper library so it can call that. That's cool. **36:48 Robert Hurlbut:** But the AppSec team writing wrapper libraries for security reasons, like, that could be a big lift, especially if none of them know how to code. **36:54 Tanya Janca:** And some AppSec teams, no one knows how to code, and that's okay. **36:57 Robert Hurlbut:** They can offer value in other ways. Yeah. **36:59 Tanya Janca:** ways. **37:00 Robert Hurlbut:** But if you do have some that are nerd-errific, uh, like me, that wrote code for many more of their life than they did not, then it's like, okay, cool, I'm gonna write one where— so my friend Clint was telling me about this. He's like, so you tab off the line if you use this old MD5 hash that we did not want people using anymore, and you would tab off of it, and then the wrapper library would show up and change the name to really insecure MD5 hash, what you doing? **37:34 Tanya Janca:** To give this feedback right away. And like, the dev could continue on, right? But they're gonna see that like their eyes are telling them that just changed. That's weird. Oh, look what it says. **37:47 Robert Hurlbut:** Someone else told me she did that and it said, this is why we can't have nice things. And she would just put that for every single function she didn't want them using. But if there's no AppSec team to go ask, what am I supposed to do instead? Then maybe you've just left the dev confused or insulted, right? **38:04 Tanya Janca:** So, I feel like you have to have a certain level of maturity for several different types of guardrails. **38:10 Robert Hurlbut:** So, you want to make sure that you have a team that's gonna back you up and support the thing you're doing. And you are checking a secret into your code. **38:21 Tanya Janca:** I'm hoping most developers are like, Okay, yeah, you're right. We know not to do that. **38:25 Chris Romeo:** Mm-hmm. **38:26 Tanya Janca:** But what if you don't have a secret management tool and they just are like, well, great, what do I do? 'Cause I, I was, I was teaching secure coding somewhere, Chris, and they're, they're like, okay, so we're supposed to check it into our secret management tool. **38:41 Robert Hurlbut:** And I was like, yeah. And they're like, we asked for one 2 years ago and it's been in option analysis with AppSec this whole time. And then the AppSec team all looked at the floor. And they're like, so what do we do, Tanya? **38:53 Tanya Janca:** And I was like, okay, let's talk about less insecure options than putting it in clear text in your code, right? Because there, there are less bad things to do. **39:04 Robert Hurlbut:** And then the AppSec team after was like, yeah, that project kind of got left behind because of this and that. **39:11 Tanya Janca:** And I'm like, I think it's pretty important. **39:13 Robert Hurlbut:** And like, and then we did like a little scan and they're like, But so if you don't have a secret management tool, and that's what you're doing, like, they need to know what to do after, like, like, if there's no secure default, if there's no answer, all you've done is caused a problem. **39:30 Tanya Janca:** Like, our job is not— **39:31 Robert Hurlbut:** so I have this discussion a lot, Chris. **39:34 Tanya Janca:** Our job is not to find vulnerabilities. Our job is to reduce organizational risk in meaningful ways. **39:41 Chris Romeo:** Yeah. **39:42 Tanya Janca:** I don't want to find 40,000 vulnerabilities. I'd much rather fix 5,000 than just find 40 and not fix any. **39:52 Robert Hurlbut:** And so, yeah, if we, we don't want to go rub their nose in something and then offer zero assistance. **39:58 Tanya Janca:** So a certain level of maturity, such that you can support each guardrail properly and socialize it and teach everyone about it before it whacks someone in the nose. **40:08 Robert Hurlbut:** I would, I would like to know it was coming before I get the slap on the wrist. **40:15 Tanya Janca:** Yeah. **40:18 Chris Romeo:** All right. One more guardrail topic. And this is one that I haven't heard anybody talk about yet. And this is the idea of a privacy guardrail. And so I'm curious, in your opinion, is that even something that you think is possible? And we take this idea of a guardrail and shift it from a secure guardrail to a private guardrail. **40:41 Tanya Janca:** Yes. **40:44 Robert Hurlbut:** And I love it. **40:46 Tanya Janca:** So I went to OWASP Global AppSec in early 2023 in Dublin, and I saw Kim Watts speak about it. So I'm a fan now. And I saw her speak about the idea of threat modeling privacy, and it kind of exploded my brain. And I went from Stride to Stripe from then on. So the P for privacy, and I was just like, I love it. **41:17 Robert Hurlbut:** And, um, and I am no privacy expert, just to be clear, but I'm a fan of privacy. Whenever I can now, I try to sprinkle it and add it on to the security mandate because it's like, I have their attention, let's do everything I can. And so I would say definitely there's some privacy things. So I was teaching earlier this week and I was talking about security headers and I was like, yeah, you can go to securityheaders.com. My friend Scott made this site and you can scan your site. **41:46 Tanya Janca:** So one of the devs did it like during the lesson and he pointed out, oh, we're missing these 3 headers at this company. And one of them was permissions policy, which is all the different HTML5 things like turning on your camera, turning on your microphone, etc. **42:04 Robert Hurlbut:** And I was telling them, okay, so you might think, oh, I'm not going to turn those on, so it doesn't matter. But like, I have a blog. **42:11 Tanya Janca:** What if I have an ad and then the ad tries to turn it on? And then it's going to ask the user, hey, do you want to turn on your microphone? It's like, why does she hacks purple want to like Watch me while I read her blog. She's a creeper. **42:24 Robert Hurlbut:** So it could just harm. **42:25 Tanya Janca:** It could harm your reputation. It harms your users' privacy, right? **42:29 Robert Hurlbut:** And so I was explaining how you could turn that off. **42:32 Tanya Janca:** The other thing was referrer policy, and I'm sorry to go back to security headers, but that's telling the next website the page that you were on, and maybe it's incredibly embarrassing medical problem dot com slash. **42:46 Robert Hurlbut:** I so definitely have positive test results that I have such medical condition. That is private. **42:53 Tanya Janca:** That's no one's business. Or what if you're on like a bankruptcy page or something else, like anything that's private? Maybe you're just going to like paint your brand new tractor purple and it's none of anyone's business. **43:05 Robert Hurlbut:** Right? It's like, hey, they don't get to see what shade of purple. It's a surprise. **43:12 Tanya Janca:** Whatever it is, right? So one privacy guardrail could be, did you turn on these specific things? Another one would be names of variables. So names of variables are, like, to be quite frank, like, really revealing, right? **43:28 Robert Hurlbut:** And so maybe you could have a guardrail that's like, you're going to put this to the screen. **43:34 Tanya Janca:** Like, I can see you're putting this to the screen. **43:36 Robert Hurlbut:** And it says, And it has like underscore sensitive, or, or it has, you know, date of birth, and date of birth is considered personally identifiable information. And like, we just don't put that on the screen here. **43:52 Tanya Janca:** So if you add a list of variable names or field names, like from the database or table names specifically, that are sensitive, maybe it rings an alert that maybe it's a soft guardrail, like we talked about. **44:04 Robert Hurlbut:** And it's like, you are putting this sensitive field from the database, or this variable name has a sensitive word in it, and we suspect there's sensitive data in it, and you're putting it to the screen. **44:15 Tanya Janca:** Are you sure? Just like, remind them, right? **44:19 Robert Hurlbut:** It just has a red squiggly, and then maybe you can accept it and say, ignore this, I do accept this risk, or I am aware that this is sensitive. **44:26 Tanya Janca:** So I feel like there could be privacy built into that, especially if you built that into the plan from the beginning. **44:34 Robert Hurlbut:** Like, when I wrote my first secure coding guideline, Chris, it sucked. **44:38 Tanya Janca:** It wasn't very good. **44:41 Robert Hurlbut:** It wasn't very clear. **44:42 Tanya Janca:** It wasn't 100% actionable. Also, the developers are like, Silverlight? We don't use Silverlight, Tanya. What's wrong with you? You clearly searched this crap on the internet. But I'm getting better and better at it, and each one has been more and more useful, effective, actionable, et cetera. And so, if you wrote privacy, into a coding guideline, or if you built it into your secure system development lifecycle, you had a privacy software developed, like privacy-focused or privacy-informed, maybe, SDLC. **45:13 Robert Hurlbut:** Like, I feel like you really could do that, but you would need a person that advocates for that. **45:18 Tanya Janca:** So I'm trying to advocate for it more. I'm still, to be quite blunt, security obsessed, and I definitely miss things. **45:24 Robert Hurlbut:** But Yeah, I— **45:27 Tanya Janca:** sounds weird, but that talk by Kim really changed my opinion of a lot of things. Yeah, I should say thanks to her, probably. **45:36 Chris Romeo:** No, she's— Dr. Woods is incredible. She's one of our advisory board members for DaVinci, because we wanted to have her perspective on threat modeling and her expertise on privacy weigh into what we're trying to do. And so she's— I'm a big Big Kim Woods fan. So love that. I was in that talk as well. I remember that talk she did in Dublin. So it was amazing. **45:59 Tanya Janca:** And maybe we should challenge her. It was a 3-minute. **46:01 Chris Romeo:** Yeah. It was the ice skip. Yep. So we'll challenge her to, to tackle this topic of privacy guardrails. I'll mention it to her next time, next time we chat and see if she'll carry it forward and maybe she can come back with something that will help us even more based on her expertise. **46:16 Tanya Janca:** You should have her on the show. **46:19 Robert Hurlbut:** And then I can watch the show. Selfish. **46:23 Chris Romeo:** It's time for her to come back again. She has been a little while. So, all right. So we got to transition to the lightning round. And normally this is Robert's thing. So I'm just going to make my way through it here. I think I can, I'll, I'll, I'll try to keep us on, on focus here. But first question in the lightning round is, what is your most controversial opinion on application security? And more importantly, why do you hold this view? **46:48 Robert Hurlbut:** So, I think that the executive order that told everyone that they absolutely had to make SBOMs was a miss, because I do think SBOMs offer value, but I would much, much, much have preferred that instead they're— they said, you know, you have to do software composition analysis, and if there's critical vulnerabilities that are reachable, You have to either A, alert all your customers, or B, fix them within X number of days. That would have reduced organizational risk across our entire industry. **47:23 Tanya Janca:** Instead, we have lots of people making these SBOMs, and some people are getting value out of it, and a lot of people aren't. **47:29 Robert Hurlbut:** Like, lots and lots of my customers are like, we worked our butts off to make them, and none of our customers want to look at them. **47:35 Tanya Janca:** I'm like, did you see my SBOM? Would you like to see it? **47:37 Chris Romeo:** No? **47:38 Robert Hurlbut:** Okay. **47:39 Tanya Janca:** And they, they worked really hard, and other security initiatives got dropped to meet this executive order. And I feel like if you're going to like throw the gauntlet down, I just— **47:51 Robert Hurlbut:** there's so many better things they could have thrown it at. And so that is my controversial take. And I'm sorry, Alan, who is probably upset with me, Alan Friedman, who talks about this a lot. Sorry, bud. Yeah, I still think you're great. I still think they offer value, but I think we could have hit harder and reduced risk more. **48:11 Chris Romeo:** Yeah, I'm with you. I agree. All right, how about a billboard message? If you could display a single message on a billboard at the RSA or Black Hat conference, what would that billboard say? **48:22 Tanya Janca:** Be nice to software developers. It's a lot of us aren't. **48:28 Robert Hurlbut:** A lot of software developers They hate security folks. We make their lives very difficult. **48:33 Chris Romeo:** We're, we're friction. **48:36 Tanya Janca:** They are like, imagine them as a whole bunch of cats, and there are a lot of security folks that just walk up and pet 'em backwards all day long. **48:42 Chris Romeo:** Whoa. Right? **48:46 Tanya Janca:** And what if, what if we were just always like, we worked hard to get along, to reduce friction, to be respectful, to be helpful, instead of This is my mandate, I gotta get it done. **48:58 Robert Hurlbut:** We think, how can I do this in a way where they still wanna have a coffee with me during coffee break? Like, they don't have to be my best friend, but when they see me, they smile and they certainly do not hide under their desk. 'Cause I, not my best day, but I remember once I saw the security person and we had like half desks, and then I just like shrunk down really quickly and my boss saw and he was like, Oh. And I was like, so busted right now. And he's like, stand up. And I was like, it's just Dr. **49:35 Tanya Janca:** Know's coming and he's just gonna derail one of my projects. I know it. **49:40 Robert Hurlbut:** And so, yeah, be nice to devs. **49:42 Chris Romeo:** I got this, I got this view of like you as Neo in The Matrix in the first movie when he's hiding from the agent the first time and he's ducking behind And then, uh, Morpheus is telling you, okay, in 5 seconds, I want you to move to the other side of the hallway. Like, I'm imagining Tanya trying to move away from the, uh, the agent, security agent who's trying to come and find you. **50:04 Tanya Janca:** Oz was not impressed with me. **50:09 Robert Hurlbut:** I got like the, you are an immature child kind of look. **50:12 Chris Romeo:** We've all gotten those though for, for plenty of times in our career. If you're not pushing the envelope enough, if somebody's not a little bit annoyed with you. That's my theory of life. So how about a book recommendation? Anything you could share with the audience? **50:28 Tanya Janca:** So I wanted to— **50:33 Robert Hurlbut:** The Expanse is the best sci-fi ever written, in my opinion, and I will, I will die on that hill. So if you want to read some sci-fi, and I love sci-fi, like tweet at me the sci-fi you like and I'll probably tell you I read it. Um, but definitely. **50:50 Tanya Janca:** So if you, if you want to relax and do some, like, listen to The Expanse and go garden on your tractor. Um, but before, um, we were talking, so the Canadian government released this parenting course through an app and it's free. **51:07 Robert Hurlbut:** And I'm going to find out the name so we can put it in the show notes. And, uh, I'm a stepmama and I want to be a good parent. **51:13 Tanya Janca:** So I like read all these parenting books and stuff. And the most impactful one of all of them. **51:17 Robert Hurlbut:** Yeah. **51:18 Tanya Janca:** I've been using this, this lesson on adults all the time. And it's, so if someone's super upset, what I used to do, which is what my parents did, I tried to solve their problem for them because I thought that's how you show you care. But it turns out that really effing annoys people. People do not appreciate that. It turns out what almost everyone wants is for you to understand how they feel and help them understand how they feel and know that you basically Like to validate their opinion is valid and that you understand how they feel and, and then they'll calm down and then they usually solve their problem right away. And so for instance, like, you know, my little one is crying and there is ice cream on the ground and I'm just like, I'll get you more ice cream, right? Like I solve it. **52:06 Robert Hurlbut:** But instead I'm like, oh, that must, that must be so disappointing. And so we can do this with adults. **52:11 Chris Romeo:** Yeah. **52:12 Robert Hurlbut:** And I don't mean to be patronizing, but I mean, like, they come to our office and they're just like, you just broke my belt and it was a false positive. **52:22 Tanya Janca:** And it's like, oh God, that's awful. **52:24 Robert Hurlbut:** They're like, yeah. **52:25 Tanya Janca:** I'm like, that, that must really make you frustrated. **52:30 Robert Hurlbut:** They're like, yes. **52:31 Tanya Janca:** I'm like, does it feel like we wasted your time? They're like, yeah, it really does. And I just, try to elaborate the, the thing, uh, and then they calm down and I'm like, I agree with you. Yeah, that sucks. Can we, can we fix it together? **52:48 Robert Hurlbut:** They're like, yeah. **52:49 Tanya Janca:** And then obviously you must actually then go do the action and fix the thing, right? **52:54 Robert Hurlbut:** You can't be like, yeah, I'll buy you new ice cream. **52:56 Tanya Janca:** Psych. **52:57 Robert Hurlbut:** And then, and then not do it. And, and it turns out this actually works really well with positive things. **53:03 Tanya Janca:** So like one of my friends got promoted. And I was like, do you feel like you finally got recognized and people finally appreciate you? **53:10 Robert Hurlbut:** She's like, yeah. And like, I just kind of went through and she's like, it sounds weird, but I felt so much more proud. **53:18 Tanya Janca:** Like, um, one of the women I mentor, she got accepted to a conference for the first time. **53:23 Robert Hurlbut:** And like, it's not a huge one. Like, she's like, oh, it's not a big one. **53:26 Tanya Janca:** Like, when do you speak at? And I'm like, I speak at baby conferences too. And you better believe it. The first conference I did was not ginormous. **53:34 Robert Hurlbut:** Um, and so then we talked about it and I'm like, you know, isn't it cool this? And like, do you feel that? And at the end of the conversation, she's like, I feel so proud now. **53:43 Tanya Janca:** I feel really, really proud and really good. And I wanna call my mom. **53:48 Robert Hurlbut:** And I just wasn't that psyched about it, but like, it hadn't really sunk in how I felt yet. **53:54 Tanya Janca:** And she's like, how'd you do that? **53:56 Robert Hurlbut:** I'm like, parenting course. **53:57 Chris Romeo:** That's great advice. That's, uh, there's lessons to be learned. **54:02 Tanya Janca:** And, and also that all this time where I kept trying to solve problems for people, it turns out that doesn't make people feel good. **54:11 Robert Hurlbut:** And if instead you like process all the feelings kind of together, and then you can come up with a solution that you both came up with together, so you feel, you both feel good about it, uh, that's like 100 times better, especially for like future relationship stuff. And I was like, oh man, I wish someone told me that when I was like 5. **54:29 Chris Romeo:** Yeah. No, that's good. It's good stuff to know. Good stuff to, to be able to reflect and, and then share with other people so they can put it into action. So, uh, then you mentioned the next book. What, uh, I haven't heard about the next book yet, so I'd love to know more about it. **54:45 Robert Hurlbut:** Okay. So I have submitted 9 chapters of Alice and Bob Learn Secure Coding. And I have 5 chapters left and I'm partway through one of them and I'm really humming now. **54:58 Tanya Janca:** And I took 2 weeks off next month to just write and farm, obviously. Um, 'cause it's July, it's gonna be amazing. Yes. **55:06 Robert Hurlbut:** And I took another week in August because I'm gonna finish this book. **55:13 Tanya Janca:** I swear, publisher, do not fire me. **55:16 Robert Hurlbut:** If you listen. But, uh, so this book is gonna be similar to the first book with the idea that Alice and Bob have things happen to them. **55:24 Tanya Janca:** Alice goes on a date with a pen tester. She does not go on another one because he does not tell the truth. But, um, the idea of explaining complex concepts in multiple ways with a story, with like a technical definition. **55:41 Robert Hurlbut:** I have less diagrams in this book, but way more stories. And so it covers, so the, it's got 3 parts. **55:49 Tanya Janca:** And the first part, which is already written, completed, everything, is agnostic secure coding guidance. **55:56 Robert Hurlbut:** So it applies to literally every language. And so it, it's not like in C#, do this. It's, it's very, um, high level. So we talk about, I talk about input validation for a lot of pages and then how after, if you must accept special characters, then you sanitize them out or escape them. And like, we wanna validate that we're accepting what we want, you know, what's an approved list versus a block list, why block lists suck so much, et cetera. **56:20 Tanya Janca:** So then section 2, which is the part I'm halfway done. Um, so I, I've done so far the top 10 programming languages, so the most popular, and I took a lot of surveys to figure out what everyone feels. So C, C++, C#, et cetera, Java, Python. Um, advice of what to do and what not to do for all of them. **56:44 Robert Hurlbut:** And so I've already started using that content to speak at conferences. So I'm speaking at AppSec PNW in Vancouver, um, June 16th or 17th. It's both days. **56:53 Tanya Janca:** I forget which day. I think I'm speaking the 16th, but obviously go to both days, uh, for only $64. Anyway, I'm trying to help them promote the conference 'cause it's OWASP and I love OWASP. **57:04 Robert Hurlbut:** Um, but I'm, I'm gonna give a, a whole lesson about writing secure JavaScript. **57:08 Tanya Janca:** And not using that with statement. And so that's section 2. **57:14 Robert Hurlbut:** And so I'm going to do the top programming frameworks as well. So like, what are some of the cool features you should be using and what are some that are no longer valid that you should not be using? Like Python 2, grow up. It's Python 3 now. Say goodbye. But, and then section 3 is a secure system development lifecycle. Oh, in section 2, I'm also going to cover big classes of bugs and not necessarily the OWASP Top 10, 'cause I feel like it's been covered to death, but like, what is a race condition? Like, what does that mean? **57:46 Tanya Janca:** It's like big ideas of, or, you know, what is authentication and, and when it's broken, what can go wrong? And like, how does it get broken? The most common, et cetera. And so, I'm, I'm not covering like CWEs really. It's more, it's a bit broader than that, but so that developers understand, oh, this is why there's steam coming out of Chris's ears when he is telling you he found this thing, that they understand why. **58:14 Robert Hurlbut:** Because I feel like a lot of security folks, when we do education, will be like, oh, HTTP request smuggling, which is like super specific. **58:22 Tanya Janca:** It doesn't apply that often. And devs just can't memorize hundreds of bugs. But if we have them in big classes of the most important, like most damaging, terrifying types of bugs, I feel like that might go better. So we'll see if people like it or not. In the first book, I did the top 10, the OWASP top 10 risks to web applications for those who hide under rocks. **58:47 Robert Hurlbut:** Um, but yeah, I want— **58:49 Tanya Janca:** I wanted to cover it in a, a new, different Tanya way, 'cause I've had a lot of people say like, oh, why don't you just cover Um, OWASP SAM, or why don't you just cover— **59:00 Robert Hurlbut:** I'm like, 'cause, 'cause OWASP SAM exists. **59:02 Tanya Janca:** You should read that. It's good. You should read it. **59:05 Robert Hurlbut:** But someone wrote it already. I'm trying to write something new in a different way that might appeal to more people or might, um, teach them in a different way that clicks. And I'm, I, I'm not sure if we covered this before, Chris, but I'm dyslexic. Like, not a person that says they're dyslexic because they made a spelling error, but an actual dyslexic person. And so I learn differently. **59:27 Tanya Janca:** Mm-hmm. **59:28 Robert Hurlbut:** And so when I, I started doing training, I had already learned French as a second language, which is extraordinarily hard for dyslexic folks. **59:36 Tanya Janca:** And so I went to a dyslexic school for adults and there's 21 different learning styles. And so I learned all about this and I was like, so that's why I don't learn when I take certain courses because they just do one style. And if that style's not my style, it's not gonna work for me. And so a lot of people need to hear about it and then do it, or they need to see it and then hear it. And so I try to do as many of those as I can to just try to get the message across, like, as much. So that's my main goal is just, I, I wanna try to help people write more secure code. **1:00:13 Robert Hurlbut:** And you do not write a book 'cause you wanna make money, Chris. Let me tell you, there are Walmart greeters out there making more per hour than I am writing this book. **1:00:20 Tanya Janca:** But, uh, I really want it to exist. Yeah. So I wish I, I have the fire under my butt now cuz I'm, I'm in the home stretch. **1:00:32 Robert Hurlbut:** I can do this. Yep. **1:00:35 Tanya Janca:** Awesome. **1:00:35 Chris Romeo:** Well, we look forward to seeing it hit the, hit the internet bookstores everywhere. Um, that'll be exciting and, uh, sounds like it could be before the end of 2024. **1:00:48 Robert Hurlbut:** No, unfortunately. So I'm gonna finish it way, way, way before that. But the printing cycle at Wiley, there's a printing cycle in January and I, I'm gonna miss it because I'm not getting my book in by the end of June. I know it's gonna take into July and August, which means then it'll be March or April, but it should be ready for RSA. And I've already talked SynGrep into buying like hundreds of copies and giving them away. So. **1:01:11 Chris Romeo:** Oh, nice. Very cool. Very cool. So, just to kind of wrap up our conversation on guardrails, what would you say then is just a quick key takeaway that you can leave with the audience here? Maybe point them to something they can go for more information too. **1:01:30 Robert Hurlbut:** Okay. **1:01:32 Tanya Janca:** So, I would say, like, the key information is we all have things we wish devs would do. If you can pick out some really important ones, figure out if you can find a technical control to nudge them that way. **1:01:50 Robert Hurlbut:** If you— if it's a custom SaaS rule, if it's, you know, when they check the code and it stops them, if it's a thing that pops up on the screen, whatever it is that you can do that is low friction, that can get those really important things It's worth doing. There's a really high return on investment, especially if you, you test it out just on one team, a team that likes you, get feedback, tune, tune, tune, and then roll it out. And then you get to— **1:02:20 Tanya Janca:** and then you just get to get that return on investment of like, oh, no one's using that terrible function that caused all those security incidents anymore. And that I feel this is proactive security. Yeah. Instead of just reacting and cleaning up messes, it's like, what if we stopped security incidents before they happened sometimes? **1:02:39 Robert Hurlbut:** Um, so I'd really like to stress that people should consider that. Um, I'm building, um, an online course that will be free. I don't know what it's called yet, but it's going to be like something like implementing secure guardrails. I don't know what it's going to be called yet, but basically I'm going to try to give like concrete examples of exactly how to do a couple of them. **1:03:01 Tanya Janca:** And how to kind of look at your program, see where you're at, try to identify some. But I find the main thing, Chris, with guardrails is just ideas of what to make a guardrail about. So I'm really hoping, um, really hoping that I can encourage people by giving them super specific examples. And actually, um, so starting in July, I'm doing this thing called Rules with Tanya, where I'm just going to do like an open office hours for 2 hours on the internet each month. **1:03:29 Robert Hurlbut:** Where I'm just gonna write custom rules. **1:03:32 Tanya Janca:** And so if people wanna join me, you can, and I'm gonna tweet all about it and stuff. But the idea is, is then people can come and share their guardrail ideas with me and I can share them with them. **1:03:43 Robert Hurlbut:** And then every time someone has a great idea, I'm gonna write about it. **1:03:47 Tanya Janca:** Um, so haha, I'm going to share cool ideas. **1:03:51 Robert Hurlbut:** And so I'm, I'm really hoping people actually join me because if I just hang out by myself, it will be awkward. **1:03:56 Chris Romeo:** Yeah. **1:03:59 Tanya Janca:** Wish me luck, Chris. **1:04:01 Chris Romeo:** The topic may switch to farming if you're just there by yourself. **1:04:05 Tanya Janca:** So you may not be able to get any answers. Well, then I'm just going to write Alice and Bob rules. **1:04:09 Robert Hurlbut:** I'll just write Alice and Bob rules. All the bad functions I don't want to see anymore, I'm just going to write them up. **1:04:15 Chris Romeo:** Put them all down. Well, Tanya, it's always a treat to connect with you, to have a conversation. So this has been excellent just to dive into guardrails and paved roads and privacy and farming and tractors and all the things that we managed to cover here. So thanks for being a part of the show. And we look forward to your next visit. Well, I'll hold Adam off until we get you to number 5. So you're in the lead for, for tied for first place. So thanks for, for spending the time with us. **1:04:44 Tanya Janca:** Chris, I can't wait to see you at OWASP Global AppSec. --- Source: https://appsecpodcast.com/tanya-janca-secure-guardrails/