Tanya Janca, We Hack Purple | RSA Conference 2023
Tanya discusses what software developers should do (and not do) during a security incident.
Transcript
This is texturung TV. Well, hey, welcome back to rsac here in San Francisco 2023. It's great to be back together and we are together.
So many of us are attending this year. So many more than even last year. Well that's a different vibe of different feel and where have lots of great conversations about technology about people about kind of passions things that we believe in and a lot of different topics which kind of fits really well all the above with our next guest which is Tanya Janka.
Who is CEO and founder of we hacker welcome. Thank you so much for having me. Thank you.
It's good to finally meet you. We've talked over emails and linkedin's and of course red and hurt a lot of your activities. So you've got a well we'll get into some of your talks and your you know, how people know you from RSA, but tell us a little bit about yourself and tell us about about weak purple.
And so I started programming as a teenager and then I got my first job at 18. So I've I've been in cyber and infosec and it in general for 26 years. Oh and I I focus on the security of software.
So application security and I'm kind of obsessed. I wrote a book called Ellison Bob learn application security. And and yeah, and I ended up starting we hack purple because people kept asking me.
Hey, you're really good at that secure coding thing. Could you come train our devs and then it just turned into a big online community and Online Academy live training a podcast and it just kind of just keeps growing that Allison Bob about secular and security really is kind of one of the things that germinated into well the training and activities that you do so it's still there today. Yes.
Absolutely. I started on the next book Alice and Bob are going to learn secure coding next. Oh, that sounds like a great way.
We definitely need that book. I'd love to hear what there's a lot of things we could talk talk about. Why did doing hack her fall out?
We act purple. Why was that the path that you chose you could have gotten a job at a lot of different companies. They're gone different down different career paths.
Why do your own thing? Why do this thing? I actually tries out Microsoft and I traveled a while.
I did a lot of things and I left Microsoft to start a company with someone else and then once we actually started working together, it's like oh you actually want this and I actually want that and so we split spectacularly in nine weeks. So if you're gonna fail very fast that's good figure that out early love those people don't but then I wasn't sure what I was going to do next. And so I put it out onto Twitter.
I'm like, what do you think I should do and people said basically we have all these developers. None of them are writing secure code. None of them know what to do.
Could you come help with this? Could you help us build our app SEC program and then my friend Karen we're still said You know, I would I would happily buy you a latte every month because I read your blogs and watch all your videos. What if you put just some of your content behind to pay well and so I I did that and the first month for seven dollars a month.
I paid my mortgage. Wow, so thank you for the support for everyone. Yeah.
Lot of folks it's free now though because basically like the academy and the live training and all these other things start paying for everything and I was like, why should we have a financial barrier to information? And this is a thing. I feel pretty passionate about which is where I wrote a book if you want to make money don't write a book.
Yeah, I've heard that before but if you really want to help move the industry forward and share information writing a book writing a Blog making videos like awesome, like people like you you are right now summoning lots of information. That's a great information Yeah. So basically I just wanted to share as much as I could but also still pay my bills and so far.
It's been going really. Well. That's fantastic.
Well at RSA what's interesting is you're talking so much more about apps like even a year ago. It's certainly four or five years ago in the network security world. We all know what is their response means right someone's hack into our system and so on our data and what do we do to lock it down and respond Etc what is incident response?
from an abstract developer perspective This is such a good question. So when I started doing application security, I didn't mean to become an incident responder. But at some point in the first couple weeks someone's like Tanya there's a thing happening.
Can you just take a look? And before I know it I'm like writing a Powershell script and deosuke ossification code and just kind of running around trying to help them with the thing and As the years went on and like every couple of weeks or months, they'd be like we need you again. I started seeing incidents where software developers and helped us folks who were very well meaning completely ruined a security incident like spoil all the evidence accidentally make things take longer.
They're like all handle this and then a disaster happens and my great now I'm getting media requests. And so when I was doing secure coding training one of the companies I work for or I was working with they said, you know what you and I were talking about that the other day about how sometimes devs like they don't mean to but they don't tell you about security incident because they don't know how to spot it or they do this or they do that, you know this year when you come to our training could you just do like just a little bit at the end on that? And so I ended up adding it to every single training and people started telling me.
Okay, so our incidents get reported faster, they get resolved faster. Devs aren't spoiling all the evidence anymore. Our apis art really slow.
Now. It turns out you know, there were bots in other attacks happening and like this has been so good. And so someone said, hey, could you maybe do a talk on that?
And then text wrong said hey, do you have a new talk on anything? And we actually you know what? I do.
I do have a talk. Well, it's great you're doing this because even in the in the network security traditional security world, there's a lot of just people issues emotions and that I do something wrong and I want to say the wrong thing or get myself in trouble, you know, so that there's just even knowing that something's coming. And what do I do?
How do I deal with it? And you don't want the first time to be when it is when the bots of you know got in control or whatever. It might be knowing what the process is and what my role is and as well as how to do it how to do it.
Well without making mistakes or ruining evidence. It's available thing to note. Then you then you kind of have at least a little bit of confidence walking through the process the first time.
Yes, I think this might sound ridiculous, but I find it. Okay. So when I as a developer, I feared the security team they were Department of no telling me how I I'm a crappy Dev and I shouldn't have had bugs Etc.
And so then if I noticed something wrong, I would have been afraid to tell the security team and so the biggest message of the whole talk is just if you see something please say something I will never be angry for a false alarm. I I will be angry if you're like, oh for the past six weeks like group and suffering with this and it's been really terrible and then we and then I find my data for sale on the dark web. So please tell us if you're listening and you're a software developer or help desk person and you see something just just say something the worst case is oh, we looked into it and it was nothing but thanks for telling us.
What is that helps? So that the time you do need to report something that's really serious or even if you're not sure you've already had conversations, right? You've already built a relationship.
It's okay to go talk to them. They're not going to fight. You're not gonna bite you've had that dialogue about.
Oh, that's okay. We figured it out. We work together solve it or not.
And that way when it does happen because it will happen. It's not if it happens to everyone everybody has to deal with this so You're working on you're working on a path. You've already laid.
Yes. Good work down. Thank you.
I hope so. I hope more of them tell us what's going on and it just to help us do a better job because for application security so network security you work with all the network folks, right you work with them infrastructure folks us abstract people. Guess who we work with we work with the developers and if the developers fear us we are not going to have a very good we're not going to do a good job.
It really we really need to have a good relationship, you know, and and I'd hurt this recently on another guess that we had talked with a couple weeks ago even just something as simple as don't turn off or unplug the server when an attack is happening. We all want to unplug from the network and do things isolate. Yes, but you might ruin an encryption that's in the you know in the middle of happening.
And by the way, you don't get that data back most of the time yes. Yes, and yes, so it's good. Whatever you do.
Yes disconnect, but don't turn it off. Good thing to know. Are you doing any talks about incident response here?
I did one already on. Tuesday with tech strong. I knew the answer to my question.
Yes, the talk I'm doing today is how it's a workshop actually and it's how to do static analysis in a devops environment in the cicd and not tick everyone off in your entire organization because I many times they're like, oh I'll just feel like the SAS tool in there and now my eight minute pipeline takes like two hours and like you're very unpopular. And then Thursday, I'm giving the opening keynote for RSA about devsecops worst practices. So all the things I've seen go wrong over and over and over I work with Ians research.
So I've worked with over 300 different absec teams now over the years and I've just seen these 15 things go wrong constantly and it's like so what is it how to spot it and how to please don't do that that's important to know what not to do like we talked about earlier. Okay, and thanks for being part of the devops connective secops event on Tuesday. My pleasure.
Thank you stock was really well. I was doing interviews so I didn't get to see it, but I'll get to see the recording so which which folks will be able to check out by the way on Tech strong. You know isn't your first rodeo you've taught you've been to RSA and toxic many many places, but I know from talking with you, you're kind of known as the security Champion person or security Champion lady or whatever.
The term is you used which is I guess. Okay. That's it's not a bad moniker if you're gonna have a handle, but remember you buy not a bad thing.
So tell us a little bit about that talk and what's happened since last year having that conversation. Yeah, so maybe two years ago. So when I did abstract full-time before I started running my own company, I built a security Champions program.
Then the next company I went to I built one there and then the next one I had started building one when Microsoft grabbed me then I started working with ions research and turned out a lot of companies. Like how can we scale our abstract program? We have one apps that person and we have like 500 developers according to get habits 500 to 1 now.
That's not good ratio. Oh wait. Yeah, and so they're like, how can we scale that like, okay, so you basically you attract people to your your abstract person by doing talks or newsletter.
I have all these things to do to try to get them to talk to you and once you find someone that keeps talking to you you're like, hey, do you want to be a security champion? And so that person's like your Advocate on that team and so you just talk with them. You're like, what are you working on?
How can I help you? Like is there some security stuff happening where you're not sure? Oh, you need that.
I'll go get it for you. And then before you know what you have this team of people where you have. person from every developer group And you can teach all of them stuff you want them to do.
So if we bring in let's say a static analysis tool. I want them to help me choose it so that I pick something that actually works for them. And then I train all of them how to be like little ninjas and then they go back they're like the awesome person on their team that knows all the security stuff and then I don't have to try to get to know 500 devs.
I have to know 40 of them and they become sort of my people if that makes sense. And so then you can have one person actually serve hundreds of developers effectively. And so as I start doing this at ions research, I became the security Champions League.
Yes. So then I I made a talk on it like oh, this is the recipe I follow and I've actually done the talk more than once at the same conference like the next year because people are like no no everyone you gotta do it again. So I've given it I don't know like 40 times or something.
Yeah, so it turns out this is a recipe that companies can actually afford and it actually works. There's a lot of apps sex stuff you can spend money on. But you don't always get the result that you want like the return on investment.
And so it turns out educating developers and helping them do their job securely is a really good way to actually scale security throughout your company. But there's the people side of this too. It's not just tools and I just technology like you like you were describing what occurred to me is they also go back to a group who trusts them already knows them.
They know maybe not all 100 people. They may be working maybe but they've already got a reputation in that Community, right and they can be more easily work with Okay. What do we do?
What you find out? What are we supposed to be doing in? How do we do this?
So it doesn't, you know get in front of us to make a slow down. The other thing. I think that's interesting about we hack purple is your approach is it isn't all one style, you know, if you're someone who loves to connect with people and enjoys the conversation there's the community that's available.
If you're the kind of person like and necessarily want to go sit around a bunch of people and yeah get a mile. I'm happy to talk on you know, slack or chat or or read a newsletter kind of thing. It's like fit your style, right?
Yes. I actually worked really hard on accessibility. So I'm dyslexic.
And I learned French as an adult. It's very hard to learn a second language as an adult just generally but if you're dyslexic, it's quite hard. And so I went to a special school where they talked about the 21 different learning styles.
And so we don't do all 21 and we hack purple but my book and all the teachings and everything were always like how many different ways can we deliver this message? And so that's why we have a podcast. We have a community.
We have a newsletter we have on demand courses we have live in person or virtual courses because it doesn't always work for everyone and I I literally want every single day of to make more secure software. This is important to me. That's why I wrote the book and made no money.
And I feel like a lot of I see a lot of training where it's just one way and that's the only way and then as a result a lot of not everyone like maybe 80% of people will get it but then there's 20% of people left by the wayside. And I remember when I started learning about infosec there was this course by this lady named Sonny where And she's a secure coding little ninja she's awesome. And she made it free and On Demand.
So some videos I was like, oh I get it. Awesome. But some I'm like I have to watch this like five times like this is like really complex abstract Concepts like SQL injection is a really abstract weird completely out of left field type of thing for a software developer because it's like why would you ever do that?
Because it works but yes. Yeah, that's where it is weird. Yeah, and she would explain it with words.
Then she would show us with code then she would show us exploiting it then she would tell a stories and she explained in all these different ways and I was like, I need to buy all of her books. Yeah. She's pretty amazing good stuff to learn.
Well wish you the best of luck with the rest of your dogs and it appearances and also with weak purple and you know, we'll get to do some more stuff deck strong together. So I'm working folks find out more if the newsletter join the community whatever activities I'd like to be part of absolutely. So if you want to find me It just look up she hacks purple all one word, and that's me pretty much all over the internet.
I have one impersonation site, but it's on like page two of Google. So just stay on page one of Google and you'll be okay, and then we hack purple so community that we had purple if you want to join the community, every single thing in the community is free, including the courses and all the events, and then there's the academy and we have basically like really low cost courses for individuals, and then we have the podcast so all the podcast platforms. com blog.
We have a lot of stuff. Actually. I'm like, oh we have family if that so just look up we hack purple and you will find me you'll find all the things and all of our other professors and our entire Community fantastic what time you thank you.
It's been a pleasure talking and look forward to getting some more in the future. Wonderful guests like Tanya. We have more folks coming up.
So please stay tuned and we're having a lot of fun here at our say see 2023. Thanks John. My pleasure.





