I *may* have bought a new guitar. ☺️ It's new-to-me, and so pretty!
Obviously I need a new amp now, right???
Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security!
She/her/lady/woman. shehackspurple.ca
Secure Coding Training and Public Speaking Inquiries & other:
Tanya (at) shehackspurple (dot) ca
I *may* have bought a new guitar. ☺️ It's new-to-me, and so pretty!
Obviously I need a new amp now, right???
Supply chain security is not just “check the package, ship the thing.”
That is like locking your front door while leaving every window open and a snack out for the raccoons. Cute? Yes. Secure? Absolutely not. #episode4
Watch: https://twp.ai/S9Cc3j
Listen: https://twp.ai/9OXdHT
I’m excited for the next book stream 😊 For Chapter 5 of *Alice and Bob Learn Secure Coding*, I’ll be joined by Katie Paxton-Fear to cover technology-specific security practices and what secure coding looks like across different architectures and platforms.
RSVP: https://twp.ai/9OYU1V
1/2
I planted my dahlias less than two weeks ago. Look at my beautiful little plant babies! 😍😍😍 I'm so excited to see them grow. #infosecgardening
It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to ‘give back’? Use this thread and hashtag to connect
October (Security Awareness Month) will be here before we know it, and my calendar is officially open for bookings! If you're looking for engaging security content that software developers will actually enjoy, I'd love to help.
tanya AT shehackspurple DOT ca
1/4
I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions.
Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜
Listen to the full episode with Vinit Patel now!
YouTube: https://twp.ai/IlpKBf
Spotify: https://twp.ai/9OUpnX
Apple Podcasts: https://twp.ai/4hpabT
Another Psychology of Bad Code blog post! Let's talk about Shiny New Tech, and how to secure it!
https://shehackspurple.ca/2026/05/06/the-psychology-of-bad-code-part-5-shiny-new-tech/
I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions.
Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜
Listen to the full episode with Vinit Patel now!
YouTube: https://twp.ai/E5A0iy
Spotify: https://twp.ai/9OUlWu
Apple Podcasts: https://twp.ai/4hpWKq
I’m thrilled to share that I’ll be teaching at Black Hat USA this August!
My training is Secure Coding for Embedded Systems in C and C++.
If you write firmware or low-level code, we’ll dig into the security pitfalls that show up again and again in C and C++ and practice fixing them together.
Lots of vulnerable code. Lots of practical fixes. Lots of ways to build safer software.
🎥 Watch the short video below
🔗 Save your seat: https://twp.ai/9OWHiO
If you’ve ever felt like application security explanations were overly academic, painfully vague, or impossible to apply in real life, this book stream is for you 💜
https://twp.ai/9OWM1z
#appsec
1/3
The sneakiest supply chain attacks are not loud. They are boring-looking, easy to miss, and often invisible at first. Which is honestly what makes them so effective. Watch the full episode at DevSec Station to learn more.
It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to ‘give back’? Use this thread and hashtag to connect
I’m so excited to be teaching at OWASP Global AppSec EU 2026 in Vienna, June 22–26!
I’m delivering a 1-day training: “API Security: Hands-On Secure API Design and Hardening.”
If you want practical, developer-friendly techniques you can use immediately, you’ll love this.
Registration here: https://twp.ai/NTbMK7
More information on my session here: https://twp.ai/E6Grvz
I joined The Secure Disclosure to talk OWASP Top 10, vibe coding, broken access control, and why “we’ll fix security later” remains one of our industry’s most cursed little traditions.
Spoiler: secure coding is not magic. It is a skill. We should probably teach it. 💜
Listen to the full episode with Vinit Patel now!
YouTube: https://twp.ai/IlpLor
Spotify: https://twp.ai/9OUrQj
Apple Podcasts: https://twp.ai/4hpcEf
We’re live tomorrow at 11:00am PST!
I’ll be joined by Ray LeBlanc to walk through Chapter 2 of Alice and Bob Learn Secure Coding.
This is the “get the fundamentals right” chapter:
1/2
I’m doing another live book stream 😊
June 3, 8:00 am PST, I’ll be diving into Chapter 3 of Alice and Bob Learn Secure Coding with Scott Helme.
This chapter, “Improving”, is one of my favourites because it’s all the “okay but how do I actually do that?” stuff.
Dear followers, are you a developer, a security professional, or something else?
Come join Ray LeBlanc and I RIGHT NOW (on the hour) to talk about chapter 2 of my book!
https://twp.ai/9OWPH4
It’s #CyberMentoringMonday!!!! Are you looking for a professional mentor or to learn more about InfoSec? Are you experienced and willing to ‘give back’? Use this thread and hashtag to connect