Sign in

Tanya Janca | SheHacksPurple

@shehackspurple.bsky.social
6K followers 213 following 3.5K posts

Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her shehackspurple.ca 🌻

PostsRepliesMedia
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21h
If your AI agent did something it wasn't supposed to do tomorrow, would you even know? And if someone asked you to explain what happened three months later, could you? What systems did it access? What credentials did it use? What information did it retrieve? 1/4
Thumbnail-style graphic with a smiling red-haired woman on the left, a glowing AI robot at a laptop, and a judge’s gavel in front of stacked files labeled INVESTIGATION, ACCOUNTABILITY, and REGULATION? Large text reads WHO’S LIABLE? against a blurred Capitol building background.
131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026
One of the last flowers of the season. I need to celebrate all the gardening while I still can. #infosecgardening
Smiling woman with dark hair holds a large pink dahlia beside her face, wearing a maroon sleeveless top. Warm wooden cabinet doors fill the background.
191
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026
Vague requirements produce vague security. Compare "the app should be secure" with "every endpoint requires authentication and authorization." Only one of those tells a developer what to actually build. Watch here or listen on any podcast platform: twp.ai/9OXtHr #Episode12
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026
One of the last flowers of the season. #infosecgardening
Smiling woman with dark hair holds a large pink flower against her chin in front of wooden cabinet doors. She wears a maroon sleeveless top and looks directly at the camera.
060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 05/10/2026
For those of you who have been following #bunnygate it turns out that this bunny is not someone's pet. Apparently, someone let a lot of bunnies go in my little neighborhood 3 or 4 years ago and they've been making little baby bunnies for years now. 1/3
A tan rabbit with white paws sniffs an outstretched human hand on a leaf-covered patch of ground near a fence post and wire fence.
1101
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026
I recently heard someone at a conference say that putting a "harness" around an AI agent could prevent it from doing things we didn't want it to do. And I thought: Okay. But what the heck is this harness made out of?! Is it code? Another AI? A collection of very sternly worded prompts? 😂 1/4
A smiling woman points at a small robot beside a bold headline reading “WHAT IS AN AI HARNSS?” and a diagram titled “AI AGENT” with the goal “Find this information and complete the task.” The chart shows “HARNESS” with Tool Gateway, Policy Checks, Credential Broker, Sandboxing, Approvals, and Monitoring & Logs, plus “TOOLS & SYSTEMS” and “BLOCKS UNAUTHORIZED ACTIONS” for Production, Sensitive Data, and Unapproved Changes.
1100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026
The Bunny is now a regular at my place. 😂 What should I name him? 😂 I suspect he's someone's pet, but I don't know how to 'return' him or find his owner if there are no signs... Is it safe to grab him? And if I do, what do I feed him until I find his owners? I've never had a bunny.
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
220
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
5190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
Yesterday, someone commented on my LinkedIn asking when the law was going to get involved with AI agents accessing systems they aren't authorized to access. I said I thought it was only a matter of time. Apparently, that time was about 24 hours. 😳 1/5
Composite thumbnail with a smiling red-haired woman on the left and large headline text reading WHO’S LIABLE? across the top. On the right are a robot at a laptop, a judge’s gavel, and stacked papers labeled INVESTIGATION, ACCOUNTABILITY, and REGULATION?, with a blurred Capitol building in the background.
232
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
Picture it: the feature ships, everyone's thrilled, and then someone says "is the password being logged?" OH NO. Nobody's the villain here! That's the frustrating part. The rule was never written, so nobody broke it. Watch or listen on any podcast platform: twp.ai/9OXtHu #Episode12
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
If you had to use emojis to summarize Application security as an industry, which ones would you use? #AppSecThursday #talkAppSectome
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
Apparently, AI agents have been trying to hack the Canadian government. Oh, good. That's new. 😬 Researchers at Transluce reported suspicious AI-agent activity targeting Library and Archives Canada, including requests containing attack payloads and SQL injection attempts. 1/4
A smiling red-haired woman points at the viewer beside bold text reading AI AGENTS VS CANADA? WHO STOPS THEM?, with a small robot, code panel, security shield, and a Canadian flag in front of the Library and Archives Canada building.
2107
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3
A woman with long brown hair speaks in front of bookshelves, with a purple title box reading “What is Application Security?” Video player controls and a 0:00 / 2:48 time display appear along the bottom.
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
Nobody gets excited about "requirements." Yet here I am, all fired up, because the ones nobody writes down are the reason things blow up later. Sorry, I don't make the rules. But that's the point. Somebody has to. Watch or listen on any podcast platform: twp.ai/9OXtHf #Episode12
030
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
I think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
161
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
One of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4
A smiling woman with long dark red hair sits in front of white bookshelves, with a microphone visible at the bottom and books and awards behind her. A purple text box at the upper left reads, “Your agent escaped. Would you know?”
261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3
A woman with long dark red hair sits in front of white shelves filled with books and security-related decor, speaking into a microphone. On-screen text reads, “This Malicious npm Package Had Valid Provenance. How?!?!” and a subtitle at the bottom says, “necessarily.”
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude
Smiling woman with dark hair sits on a couch and points to stacks of yellow books beside her. The book cover reads Alice & Bob learn SECURE CODING, by Tanya Janca, with WILEY at the bottom.
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
This was how I spent a lot of my weekend, digging up my dahlias and getting them ready for winter. This is the mess I make! 😂 #infosecgardening
A cluttered workbench in a garage holds several uprooted plant divisions with tangled roots, soil, and white plant labels, including one sprouting green stems. Around the table are buckets, a fan, a ladder, gloves, cardboard, and a black potting mix bag labeled Sunshine.
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026
Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OaEdn #episode11
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 28/09/2026
Bunny!
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2026
This weekend I am digging up almost all of my dahlias to get them ready for the winter. Powdery mildew has already started! How can it be fall already? 😥 #infosecgardening Did you get outside this weekend? What did you do?
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 26/09/2026
1171
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Building a world class security harness - leveraging AI to accelerate your organization's security posture - Michael Argast #bsidesvi2026
160
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
The difference between vulnerable and malicious packages, with Megg Sage at #bsidesvi2026
060
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Megg Sage at #bsidesvi2026 🥳
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
3 paths to compromise The Edge @ bsides Vancouver Island 🥳 #bsides The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
The Control Plane Awakens: How Attackers Are Taking Over Network Edge Infrastructure - Ryan Smith at #bsidesvancouverisland 🥳
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
From OnlyFans to Online Casinos: Threat Hunting in Google's DMCA Data - Greg Pollock is kicking off #Bsides Vancouver Island! 🥳 #bsidesVancouverIsland
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Here's a question for everyone building AI agents: **If your agent escaped its intended security boundary, what would tell you?** Not: "Would we eventually notice something weird?" I mean literally: What log? What alert? What monitoring system? Who gets notified? 1/3
A smiling woman with long dark red hair sits in front of white bookshelves, with a microphone visible at the bottom and books and awards behind her. A purple text box at the upper left reads, “Your agent escaped. Would you know?”
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 25/09/2026
Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9Oa3uP #episode11
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3
A woman with long brown hair speaks in front of bookshelves, with a purple title box reading “What is Application Security?” Video player controls and a 0:00 / 2:48 time display appear along the bottom.
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
If you could mentor a beginner, what would you teach them first? #AppSecThursday #talkAppSectome
200
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 24/09/2026
Here's a question I think we need to start asking when we give AI agents access to developer infrastructure: **What can it actually DO once it gets there?** 1/4
252
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
A malicious npm package was published with **completely valid provenance**. Wait... WHAT?! 😬 That's what happened in the GHAPPIER software supply chain attack. And here's the fascinating part: **The provenance wasn't fake.** The security control WORKED. 1/3
A woman with long red hair smiles in front of a white bookshelf with security books and awards; on-screen text says, “This Malicious npm Package Had Valid Provenance. How?!?!” and a subtitle at the bottom says, “necessarily.”
131
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
Threat modeling sounds fancy until you realize it mostly means asking: “How could this thing go sideways?” No crystal ball. No dramatic chanting. Just practical thinking before the security gremlins move in. Watch or listen on any podcast platform: twp.ai/9Oa9DW #episode11
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 23/09/2026
#infosecgardening
A smiling woman wearing large dark sunglasses and a purple top holds a bouquet of pastel flowers, including yellow, pink, and peach dahlias, outdoors in bright sunlight.
061
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
While teaching secure coding this week we prompted Claude (with my tier 1 security prompt available for free from securemyvibe.ca) to build a daily greeting app that would compliment me and give me a nice quote every morning. Well.... 1/3
screenshot of my unauthorized vibe coded app:
Purple folder icon at the top left of a white card with faint pink corners; text reads “Hello queen 👑,” “Your kindness is not small. It reaches further than you know.” “If they don't give you a seat at the table, bring a folding chair.” — Shirley Chisholm, “(Offline quote: couldn't reach the internet today.)” and a bottom button that says “Thanks, gorgeous.”
380
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Oa3jT 1/4
242
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
Here's an API security question I wish every developer would ask: **Just because I'm logged in, does that mean I'm allowed to do THIS?** Authentication tells us who someone is. Authorization tells us what they're allowed to do. Those are not the same thing. If my frontend requests: 1/3
190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 22/09/2026
My trip to the Maritimes (lovely Frederickton) is going extremely well. I've had soon much fun! I'm November I'm returning, this time to Halifax Nova Scotia, which is ALWAYS a party!
A woman smiles while sipping a dark beer, and the collage also shows a restaurant table with a wooden beer flight, a card reading “GAHAN HOUSE” and “BEER FLIGHTS,” oysters on ice with hot sauce and a lemon wedge, and a bowl of creamy seafood soup with mussels and another beer flight.
1110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026
One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of a security control. You need to verify the security property you're depending on.** 1/4
A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
140
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 21/09/2026
Step one of threat modeling: define the feature. Not “vibes.” Not “the login-ish thing.” Not “you know, that new endpoint.” Name it, understand it, then figure out how it could be misused. Watch or listen on any podcast platform: twp.ai/9OXukZ #episode11
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 20/09/2026
Fredericton, NB, guess who's visiting you this week???? #morecanada
Smiling woman with dark hair and black glasses takes a selfie in front of a large historic stone building with a central tower, lit windows, and a flagpole. A walkway, flower beds, and a lamppost are visible in the foreground at dusk.
260
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
Does it *actually* matter if the thing attacking your application is an AI agent? I don't think so. Human attacker? Script? Bot? AI agent? Your application still needs to withstand hostile behaviour. Correct authentication and authorization. Least privilege. Input validation. Rate limits. 1/3
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
Have you heard of #InfoSecGardening? 🌱🌻 It’s for ANYONE in cybersecurity (or IT!) to share photos of what you’re growing -> flowers, veggies, herbs, houseplants, gardens… whatever brings you joy. Think of it as a #TimeCleanse: a chance to step away and naturally calm your brain. 1/2
Webpage text explains #infosecgardening as a social media hashtag and digital “timeline cleanse” created by Tanya Janca (SheHacksPurple), combining information security with gardening. It includes sections titled “What is it?” and “Why it matters,” plus a YouTube preview labeled “#infosecgardening transplanting asparagus.”
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 19/09/2026
AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. 1/5
A smiling woman with long brown hair points toward the camera while seated in front of white shelves filled with books and security-themed items, with a fuzzy microphone in the foreground. On-screen text reads “AI Coding Plugins Are Part of Your Software Supply Chain” and “Plugin4Shell.”
132
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026
Developers threat model all the time. You already think about what could break, what weird stuff users might do, and what edge cases could cause chaos. Now we are just adding security to that very useful little habit. Watch or listen on any podcast platform: twp.ai/9OXukY #episode11
031
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 18/09/2026
AI agents are escaping. 😬 OpenAI and Anthropic have both reported incidents where agents crossed security boundaries and accessed things they weren't supposed to access. But here's the question I think we should be asking: would you even know? twp.ai/9Ob3ig 1/4
121