Tanya Janca | SheHacksPurple's Avatar

Tanya Janca | SheHacksPurple

@shehackspurple

Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her https://shehackspurple.ca 🌻

5,794
Followers
208
Following
2,592
Posts
26.04.2023
Joined
Posts Following

Latest posts by Tanya Janca | SheHacksPurple @shehackspurple

O'reilly book cover, "Yolo commit edition"

O'reilly book cover, "Yolo commit edition"

"Yolo is not a security strategy!"

06.03.2026 21:57 πŸ‘ 11 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

Canada is one step closer to mandatory secure coding in government software.

Petition e-7115 is live!

If you can sign, please do it today:
πŸ‘‰ https://twp.ai/9PaqLN

This is how we make real change. πŸ™

06.03.2026 03:38 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

Question for people whose title is "security researcher": besides bug bounty submissions, how do you make money? What other options are there for monitizing security research? Honest question.

06.03.2026 00:57 πŸ‘ 1 πŸ” 2 πŸ’¬ 2 πŸ“Œ 0

Important question for software developers: what do you wish you knew more about in regard to creating more secure software? If you could suddenly know something, like Neo in the matrix, what would it be?

I will see if I can help.

05.03.2026 22:19 πŸ‘ 3 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Tanya Janca on stage

Tanya Janca on stage

Thank you to everyone who came to my keynote at #vipss today! πŸ₯³

05.03.2026 22:18 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is such an original idea. I can't wait. Thanks!

05.03.2026 22:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Come see my keynote, 'Insecure Vibes' at 12:00 at Victoria International Privacy and Security Summit today! #vipss

05.03.2026 19:00 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Come see my keynote, 'Insecure Vibes' at 12:00 at Victoria International Privacy and Security Summit today! #vipss

05.03.2026 19:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I made my picks. We don't get to WATCH the event? I was hoping to watch...

05.03.2026 16:18 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Brad Edwards

Brad Edwards

Brad Edwards is kicking off his AI-related keynote at #VIPSS in Victoria BC.

04.03.2026 19:50 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Every signature matters. Β πŸ™
2/2

04.03.2026 00:50 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

I’ve been working toward this for years, and it finally happened.

Canada now has a parliamentary petition to require secure coding in federal software. If you care about cybersecurity, public safety, and better government tech, please sign:
πŸ‘‰ https://twp.ai/9Pbk5I
1/2

04.03.2026 00:49 πŸ‘ 10 πŸ” 2 πŸ’¬ 2 πŸ“Œ 0

Brochure only: https://twp.ai/Imurr5
2/2

03.03.2026 19:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Most security training fails because it teaches rules, not behavior. I’ve put together a new training brochure that explains how I focus on habit-building, developer trust, and real-world secure coding.

If that sounds good...
πŸ‘‰ https://twp.ai/9PaNSx
1/2

03.03.2026 19:25 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

So weird!!!!

Perhaps you have a big submission for the bluesky folks.

03.03.2026 06:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

though.fun?

so tempting to click random links... damnit...

03.03.2026 05:32 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

What I want to see is:
Trust changing events
Pipeline and artifact integrity signals
Anomalous publishing behaviour
When WEIRD stuff happens

Not "developer surveillance"

03.03.2026 05:31 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Like internal developer productivity tools (engineering intelligence) platforms, ++

And I mean, for security purposes, not creepy time tracking or something.

Thoughts?
2/2

03.03.2026 05:10 πŸ‘ 3 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Is there a tool on the market that monitors DEVELOPER telemetry? What THEY are doing, not the apps? For instance, which packages they download, extensions they install, code they copy and paste, AI assistants they use, communication methods, etc?
1/2

03.03.2026 05:10 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

I miss him already.

03.03.2026 04:06 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

If you’ve been trying to make supply chain security feel more practical and more human, this one’s for you.

Hope to see you there!

Tickets here: https://twp.ai/9Pbev9
2/2

03.03.2026 03:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m so excited to be keynoting and hosting a workshop at SnowFroc ’26 in Denver, April 16–17!

My keynote is: β€œThreat Modeling Developer Behavior: The Psychology of Bad Code”

My workshop: Supply Chain Isn't Just Dependencies Anymore: Defending Developers, Tooling, and Builds
1/2

03.03.2026 03:33 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Agreed

03.03.2026 03:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Brochure only: https://twp.ai/NTYlGX

Feedback welcome. Always.
2/2

02.03.2026 23:07 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

I finally put all my secure-coding training into one place πŸ‘€
New brochure is up, with what I actually teach, who it’s for, and what teams get out of it.

If you’re curious (or responsible for training devs):
πŸ‘‰ https://twp.ai/9PZ1gL
1/2

02.03.2026 23:07 πŸ‘ 6 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
tcpdump101.com - Build Packet Captures Online Build PCaps for: tcpdump, Fortigate, Check Point 'fw monitor' and Cisco ASA.

Almost 40 years in Net/Sec/Eng and always willing to give back. #Networking, #Firewalls, #Hacking, #Linux, #Security, #Architecture and more. Don't want to connect yet? No biggie. Have yourself some tcpdump101.com to get started on building PCaps on a variety of platforms. πŸ’š

#CyberMentoringMonday

02.03.2026 17:07 πŸ‘ 7 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Looking to learn or inspire? Make sure you're following @shehackspurple.bsky.social and show some love.

02.03.2026 17:08 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to β€˜give back’? Use this thread and hashtag to connect

02.03.2026 17:01 πŸ‘ 4 πŸ” 2 πŸ’¬ 1 πŸ“Œ 1

I can't wait to add it to my vocabulary

02.03.2026 02:47 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Thank you Chris!

01.03.2026 17:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0