Tanya Janca | SheHacksPurple  

7K Followers
645 Following
4.3K Posts

Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security!
She/her/lady/woman. shehackspurple.ca

Secure Coding Training and Public Speaking Inquiries & other:
Tanya (at) shehackspurple (dot) ca

#AppSec, #DevSecOps 🌻

SheHacksPurplehttps://shehackspurple.ca
Newsletterhttps://newsletter.shehackspurple.ca

Hi! If you are Canadian, I NEED YOUR HELP. Please call your member of parliament and ask them to vote YES on petition e-7115. Watch the video to learn more!

https://twp.ai/E5A0j7

Petition: https://twp.ai/4hpWKz

SheHacksPurple: Please call your member of parliament

YouTube

It’s interactive, you can ask questions live, and everyone is welcome, whether you’re new or experienced.

👉 RSVP here:
https://twp.ai/uH9CZq

Or just show up: https://twp.ai/bWUDna
4/4

Alice and Bob Learn Secure Coding: Chapter 2 | SheHacksPurple

Join me live on Sunday May 10th for a deep dive into Chapter 2 of Alice and Bob Learn Secure Coding! I’ll be joined by my friend Ray Leblanc, and together we’re going to spend two hours unpacking the foundations of application security in a way that’s ...

SheHacksPurple

cryptography and protecting sensitive data
modern browser security features and headers

If you’ve ever wondered what “secure by design” actually looks like in practice, this is the chapter where it starts to click.
3/4

This chapter is packed with the core practices every developer should know, including:

following a secure SDLC
input validation and output encoding (with real examples)
authentication, authorization, and session management
secrets and password management
2/4

I’m hosting another live book stream, and this one is all about the foundations of secure coding.

On May 10, 11 am-1 pm PST, I’ll be joined by Ray LeBlanc to walk through Chapter 2 of Alice and Bob Learn Secure Coding.

https://twp.ai/4hpVR8
1/4

I was on Talk Python to Me, with Michael Kennedy, and, just like last time, it was GREAT! We talked about the #OWASP Top Ten, and so much more. Listen here: https://twp.ai/4hpWKu
Also: OMG that face I'm making! :P

Every time we install a dependency, copy a snippet, grab something from Stack Overflow, or accept AI-generated code, we are making a trust decision. Let’s make those decisions carefully. Watch the full podcast episode to learn why this matters and how to think about it more safely.

https://twp.ai/E5AeiL

It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to ‘give back’? Use this thread and hashtag to connect

Episode #2 of DevSec Station is out!

Listen on any podcast platform or watch here:
https://twp.ai/E5A0ix
https://twp.ai/4hpWKp

I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions.

Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜

Listen to the full episode with Vinit Patel now!

YouTube: https://twp.ai/E5A0iy
Spotify: https://twp.ai/9OUlWu
Apple Podcasts: https://twp.ai/4hpWKq