O'reilly book cover, "Yolo commit edition"
"Yolo is not a security strategy!"
O'reilly book cover, "Yolo commit edition"
"Yolo is not a security strategy!"
Canada is one step closer to mandatory secure coding in government software.
Petition e-7115 is live!
If you can sign, please do it today:
π https://twp.ai/9PaqLN
This is how we make real change. π
Question for people whose title is "security researcher": besides bug bounty submissions, how do you make money? What other options are there for monitizing security research? Honest question.
Important question for software developers: what do you wish you knew more about in regard to creating more secure software? If you could suddenly know something, like Neo in the matrix, what would it be?
I will see if I can help.
Tanya Janca on stage
Thank you to everyone who came to my keynote at #vipss today! π₯³
This is such an original idea. I can't wait. Thanks!
Come see my keynote, 'Insecure Vibes' at 12:00 at Victoria International Privacy and Security Summit today! #vipss
Come see my keynote, 'Insecure Vibes' at 12:00 at Victoria International Privacy and Security Summit today! #vipss
I made my picks. We don't get to WATCH the event? I was hoping to watch...
Brad Edwards
Brad Edwards is kicking off his AI-related keynote at #VIPSS in Victoria BC.
Every signature matters. Β π
2/2
Iβve been working toward this for years, and it finally happened.
Canada now has a parliamentary petition to require secure coding in federal software. If you care about cybersecurity, public safety, and better government tech, please sign:
π https://twp.ai/9Pbk5I
1/2
Brochure only: https://twp.ai/Imurr5
2/2
Most security training fails because it teaches rules, not behavior. Iβve put together a new training brochure that explains how I focus on habit-building, developer trust, and real-world secure coding.
If that sounds good...
π https://twp.ai/9PaNSx
1/2
So weird!!!!
Perhaps you have a big submission for the bluesky folks.
though.fun?
so tempting to click random links... damnit...
What I want to see is:
Trust changing events
Pipeline and artifact integrity signals
Anomalous publishing behaviour
When WEIRD stuff happens
Not "developer surveillance"
Like internal developer productivity tools (engineering intelligence) platforms, ++
And I mean, for security purposes, not creepy time tracking or something.
Thoughts?
2/2
Is there a tool on the market that monitors DEVELOPER telemetry? What THEY are doing, not the apps? For instance, which packages they download, extensions they install, code they copy and paste, AI assistants they use, communication methods, etc?
1/2
I miss him already.
If youβve been trying to make supply chain security feel more practical and more human, this oneβs for you.
Hope to see you there!
Tickets here: https://twp.ai/9Pbev9
2/2
Iβm so excited to be keynoting and hosting a workshop at SnowFroc β26 in Denver, April 16β17!
My keynote is: βThreat Modeling Developer Behavior: The Psychology of Bad Codeβ
My workshop: Supply Chain Isn't Just Dependencies Anymore: Defending Developers, Tooling, and Builds
1/2
Agreed
Brochure only: https://twp.ai/NTYlGX
Feedback welcome. Always.
2/2
I finally put all my secure-coding training into one place π
New brochure is up, with what I actually teach, who itβs for, and what teams get out of it.
If youβre curious (or responsible for training devs):
π https://twp.ai/9PZ1gL
1/2
Almost 40 years in Net/Sec/Eng and always willing to give back. #Networking, #Firewalls, #Hacking, #Linux, #Security, #Architecture and more. Don't want to connect yet? No biggie. Have yourself some tcpdump101.com to get started on building PCaps on a variety of platforms. π
#CyberMentoringMonday
Looking to learn or inspire? Make sure you're following @shehackspurple.bsky.social and show some love.
Itβs #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to βgive backβ? Use this thread and hashtag to connect
I can't wait to add it to my vocabulary
Thank you Chris!