🦜 SheHacksPurple
@shehackspurple.ca@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
By Tanya Janca
Your feed and you don't want it here? Just
e-mail the birb.
The Psychology of Bad Code Part 4 – Copy Paste
https://shehackspurple.ca/2026/04/07/the-psychology-of-bad-code-part-4-copy-paste/
Published: April 7, 2026 23:11
This is a series. The first blog post is here, #2, #3, and this is the forth. The behaviour: Copy and Pasting from online forums What this looks like in the real world This often shows up when we are stuck, frustrated, or rushed. This is often used to…
The Psychology of Bad Code Part 3 – Vibe Coding
https://shehackspurple.ca/2026/02/16/the-psychology-of-bad-code-part-3-vibe-coding/
Published: February 17, 2026 01:45
This is a series. The first blog post is here, the second is here, and this is the third. For the rest of this series, I am going to follow a similar format for each post/behavior. I will name the behavior, then various biases and heuristics that I believe…
The Psychology of Bad Code Part 2 – Building Systems That Support Secure Developer Behavior
https://shehackspurple.ca/2025/12/23/the-psychology-of-bad-code-part-2-building-systems-that-support-secure-developer-behavior/
Published: December 23, 2025 18:17
In my previous blog post, I introduced the topic of applying behavioral economics to application security programs, using proven behavioral economic interventions to help us avoid known bad developer behaviors (including ones I know I am guilty of). In…
The Psychology of Bad Code
https://shehackspurple.ca/2025/11/27/the-psychology-of-bad-code/
Published: November 28, 2025 00:44
In this blog series I will explore several known bad developer behaviors that lead to insecure software, as well as how we can combat them by applying behavioral economic interventions. This series is an expansion upon my thoughts from my conference talk…
How To Get Your First Job In Cybersecurity
https://shehackspurple.ca/2025/11/21/how-to-get-your-first-job-in-cybersecurity/
Published: November 22, 2025 06:15
– By someone who really wants you to succeed! Finding your first job in cybersecurity (which us security nerds call ‘InfoSec’) can feel overwhelming. There are way too many job titles, technologies, and acronyms to keep track of. There’s also no clear…
Metrics, Models, and Mindsets: A Conversation About the Future of AppSec
https://shehackspurple.ca/2025/11/13/metrics-models-and-mindsets-a-conversation-about-the-future-of-appsec/
Published: November 13, 2025 21:57
Recently I hosted a webinar called “Metrics, Models, and Mindsets: The Future of Application Security” with: Our goal was simple: talk honestly about where application security is going, and what’s actually working (and not working) in real teams today.…
Software Supply Chain: Bigger (and Scarier) Than We Realize
https://shehackspurple.ca/2025/11/10/software-supply-chain-bigger-and-scarier-than-we-realize/
Published: November 10, 2025 22:04
When we talk about the software supply chain security, most people think only of dependencies (open-source libraries and frameworks). But the supply chain is so much more than just that. It’s everything we use to build, test, and release our software: our…
Why we need to start giving significantly more specific security advice
https://shehackspurple.ca/2025/11/09/why-we-need-to-start-giving-significantly-more-specific-security-advice/
Published: November 9, 2025 20:08
Recently, I had a great conversation with my friend Adam Shostack about a petition I started for the Canadian government to adopt a Secure Coding Policy that I wrote. Adam pointed out that my policy is very specific. Much more so than other government…
Vibe Check: A Panel Discussion at SecTor 2025
https://shehackspurple.ca/2025/10/01/vibe-check-a-panel-discussion-at-sector-2025/
Published: October 2, 2025 00:38
I had the opportunity to join an incredible panel at SecTor (a Black Hat event) in Toronto alongside Chad Breslin, Brett Grady, and Ian Hassard. We dove into the world of Vibe Coding! What it is, the risks it introduces, and how to use AI to write safer,…
What it’s Like to Record an Audiobook
https://shehackspurple.ca/2025/09/09/what-its-like-to-record-an-audiobook/
Published: September 10, 2025 02:23
I recently flew to Ottawa to record the narration for my second book, Alice and Bob Learn Secure Coding, and it was a LOT of work! From September 1st to to 7th, 2025 I recorded 6 hours a day at The Cave recording studio. Focusing on reading highly…