Embracing Security: Insights into Developer Education and AI Risks with Liran Tal – Techstrong Unplugged EP47
Liran Tal, director of developer advocacy at Snyk, talks about the art of teaching developers application security. He explores engaging methods like Capture the Flag and card games, emphasizing how “hacking” can build better security awareness. Liran shares his journey from software development to security education, the importance of understanding an attacker’s mindset, and the critical role of fun in learning.
Transcript
Welcome back to Textron Unplugged. My name is Cassandra Chen, and today we have Al Correct. Hey, Cassandra, how are you doing?
Doing Well. Can I introduce yourself? Yes.
Uh, my name is Liron. I'm a developer advocate at sncc, which basically means I enjoy teaching developers about security, so application security topics and stuff like that, how to write secure code. Can you talk a little bit about how you do security education?
Uh, yes. So there's like several ways of doing that where you're like teaching developers at conferences or events or just having, you know, fun workshops. Um, I think specifically having fun is like a really good trait of doing it.
So for example, I would say if we are making it like a, like a fun, like giving them like a puzzle to solve to developers related to security, they actually like really connect to it. And so in security there's this, uh, game called, uh, like capture the flag, which comes obviously from like the gaming aspect of it. Uh, so you essentially try to like maybe hack a system and get the flag, get something in the system.
So I find that developers and like probably a lot of people as well, just like find out like a fun activity, like an escape room, trying to figure out to bunch of activities and trying to like access the system in different ways. So like, that's one way of asking security. Oh, You mentioned hacking.
Like normally we think of security as a good thing and hacking as a bad thing. So how are the two related? Um, a good thing or bad and a bad thing For security, I would say good security is often invisible.
That's kind of like the curse of security because like, until you get hacked until like something bad happens, you really like, don't know, right? It's, it's kind of like invisible. So until you get hacked, until there's like a data bridge until something goes wrong, like security is invisible, no one can like pay attention to it.
So that aspect is maybe like the bad part of it. Uh, Like why do we wanna teach developers how to hack? How to hack?
I think putting them on, uh, on a space where they, where they know how to hack, like they understand how an attacker mindset works, uh, in those kind like CTF games, we kinda like give them an appreciation to why writing secure code. Why like using, you know, secure practices when they, when they write code, when they ship production apps is important because they can see how sometimes easy it is or how sometimes the mistakes are made in a simpler way, um, to like that they shouldn't have done that before. So you really understand why security is important when you hack the code yourself.
I think it gives you one perspective. Yes. Are there any other ways that you teach security, which you find interesting?
Um, well I think it, they're all somewhat related to gaming. So for example, um, there's like a cars game, so if you like, uh, I, I've been to one recently actually, uh, in Vegas, in Defcon, uh, there was, uh, gig Guardian was a company who was like sponsoring one of the boots there. And what they had is this, um, secrets game.
So you get a card, like a physical deck of cards, they all have secrets in them. You don't know what is an actual true secret and what is not. And you have to like filter it pretty fast.
Like, you know, also like win like get on the leaderboard and you can like sometimes make a mistake and you think something is a secret and really it's not or other, other way around. And so I think like those kind of like activities around like having a game, having, you know, something fun to do, it is, uh, is a, is a fun way of teaching it. Um, for these games, like are they targeted at a certain age of developers?
Um, no, definitely not. I think some may require some kind of like pre-experience, like understand the concept, but like secrets is like very shallow, like understanding, like I think any, any, any age, any experience level is, is relevant. So do you think that even older developers can benefit from learning security?
Oh yeah. I think everyone can benefit from knowing security, application security and information security. Everything in and around it is, is just sometimes so far away from reach because like focused as developers to just like, you know, get on the backlog, get bug fixes, get features done, and all the other crosscutting concerns like security, like sometimes, uh, performance and testing and those kind of things get kind like, you know, trickle down because they're not as important, but it is and everyone can win from it.
Uh, can you think of any like specific security incidents where like, Uh, so many, uh, I dunno. The recent one was, uh, I think much in the news, uh, was the exit details. That was an interesting, uh, kind of crossroad of several things happening.
So potentially like nation state actors, like a very major uh, uh, incident in which, uh, an open source package, a library that is installed in like, you know, regular computer systems, uh, gets, uh, you know, gets someone else malicious actors, uh, to kinda like pay a key, a key role in there and potentially like slip in back doors and Trojans and that can like, integrate a lot of things. Uh, both like how open source works, uh, the importance of, you know, libraries, uh, and like ownership for that. Uh, you know, CICD practices, supply chain security, there's like a lot of goes into it.
And that story alone could like, you know, pivot into different, uh, uh, education parts that we could better empower developers like understand how to kind like practice, uh, in a, in a more safe way for, for the ecosystem. And have you always been in the security space? Like do you feel I'm actually a, a developer gone into teaching developers about security because I kind of care about security, but uh, my, my background is totally not security.
It is, um, has been being a developer myself. So kinda like transitioning into, uh, enjoying security to a lot of, uh, to a good extent, uh, writing about it, you know, being able to like, you know, talk to my colleagues about security aspects and practices when you are building our apps. And, uh, I think like anyone can transition into a security space.
So do you think things have been more fun since you transitioned to security? Um, this job has been more fun in general doing that. Yes.
Um, going back a little further, like how did, how did you get into technology? Um, it's, I don't know if it's a, it's a regular path, but, you know, I've been, uh, my, my dad was, uh, was like in and around computers back then when I was a kid, um, which is like 94 or five or so, um, to, he was really, uh, kinda like, you know, building app apps and like what would be an excel back then, uh, for his business. And I was like, just spending a lot of time, you know, in front of the computer doing a lot of things.
And I think my, my surroundings were basically around that. So I kind got into computers and the moment I was kind of like learning, uh, uh, basic cubase editor thing, like building my own programs was like very satisfying that I could actually do that. So, um, that really got me hooked onto computers.
And from there, uh, you know, I kinda like knew that all I wanted to do was basically work on, you know, software development all day. So whatever the, uh, kinda like the, the journey it took, um, school work experience, whatever that was just turning into into that has been kind of what I was, uh, envisioning it from childhood. I think it's a lot of fun that computers let you create things.
Yes. I, I think that's the key aspect of it, being able to create something sometimes out of nothing. And at this conference, are you giving a talk?
Uh, yeah, just in and hour actually. So it's gonna be fun, I hope. Do you wanna tell me a little bit about what your talk is about?
What is this? Um, it's uh, it's much related to less obviously security fun games. Um, I am basically going to tell developers how even though these days there's a lot of hype around AI and you know, generative AI chat, GPD, uh, coding assistance in their, uh, integrated development environments, then why having that is actually sometimes a security concern.
Uh, so my talk is gonna have like live hacks and demos of the coding assistance, um, auto completing and suggesting vulnerable code that we could exploit. And I think until developers like see that in practice, they sometimes don't even think about it. So that's gonna be, uh, that's gonna be my ambition to show them how bad things can happen as well.
So they have like the mindsets of, you know, more responsible person when they work with ai. I think that's an interesting topic 'cause AI is really popular and we're like training developers to use co-pilot. Yes, I would say, I don't know, trading developers is one thing.
I think we're kind of like going into a defacto state where we're having so, so having a gen AI tool, like a coding assistant is not, I think, inherently bad. We use them and that's, that's gonna be I think the future. That's, there's no denial for that, but I think the way that we make use of that technology and the amount of responsibility we apply to it is going to be a decisive factor in terms of what is the quality of the end products that we produce as developers at the end of the day.
And I think that is something that needs a bit more kind of awareness and education onto what could potentially go wrong. I think what's really important, I think so too. I think we've had a really good talk today, so thank you.
Thank you so much, Cassandra.
