Security bugs aren't usually caused by 'bad developers'. More often, they're the result of good developers making rational decisions under deadlines, competing priorities, and imperfect systems.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca explores why common secure coding mistakes are often incentive problems rather than knowledge problems. You'll learn why insecure patterns emerge, why simply telling developers to "be more careful" doesn't work, and how changing your development environment can make secure coding the easiest path forward.
You'll learn:
- why good developers still introduce security vulnerabilities
- how deadlines, delivery pressure, and operational complexity influence coding decisions
- why 'shame and blame' doesn't improve software security
- several practical examples of how to replace insecure patterns with more secure ones
- how to identify recurring shortcuts and improve them instead of fighting them
Tanya shares several real-world examples of secure coding shortcuts that teams make every day (from copy-pasted authentication checks to inconsistent secret handling) and explains why these decisions are understandable in the moment, even though they create security problems over time (also known as 'security drift'). She also demonstrates how small changes to defaults, shared libraries, and team patterns can eliminate entire classes of recurring mistakes.
If you do just one thing after listening to this episode:
Identify one insecure pattern that keeps showing up in your team's code base and ask why it exists before trying to eliminate it. If you don't know the why, you can't fix it. Then replace that shortcut with an easier, more secure path.
DevSec Station is a podcast by Tanya Janca (SheHacksPurple), focused on short, practical lessons that help software developers build more secure software.
Follow Tanya:
- https://shehackspurple.ca
- https://newsletter.shehackspurple.ca
- https://youtube.com/@shehackspurple
- https://linkedin.com/in/tanya-janca
- https://tanyajanca.com
This episode is sponsored by Maze.
One of the biggest problems in security right now is that every vulnerability scanner says everything is critical, and honestly, no one has time for that.
Maze uses AI agents to investigate vulnerabilities in context, so you can focus on the issues that are actually exploitable in your environment, not just theoretically scary.
Their AI agents also generate and prioritize fixes that knock out multiple vulnerabilities at once, which is honestly the kind of scaling that security teams need right now.
Learn more about Maze https://mazehq.com/devsec
Fler avsnitt av DevSec Station
Visa alla avsnitt av DevSec StationDevSec Station med Tanya Janca | SheHacksPurple finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
