Sign in

Tanya Janca | SheHacksPurple

@shehackspurple.bsky.social
6K followers 213 following 3.5K posts

Secure Code Trainer - Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her shehackspurple.ca 🌻

PostsRepliesMedia
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 2h
One of the last flowers of the season. #infosecgardening
Smiling woman with dark hair holds a large pink flower against her chin in front of wooden cabinet doors. She wears a maroon sleeveless top and looks directly at the camera.
040
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5h
They also named it Tanner with me today, because apparently this little guy visits them all the time too. 3/3
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5h
That's why it seems so docile, and comfortable with humans. They said not to feed it, because there's way too many of them and they keep eating all of the farmers Fields. So there's no responsibility here for me to find its owner. 2/3
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 5h
For those of you who have been following #bunnygate it turns out that this bunny is not someone's pet. Apparently, someone let a lot of bunnies go in my little neighborhood 3 or 4 years ago and they've been making little baby bunnies for years now. 1/3
A tan rabbit with white paws sniffs an outstretched human hand on a leaf-covered patch of ground near a fence post and wire fence.
191
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8h
Restrictions need to be enforced somewhere the agent cannot simply bypass them. I introduce this concept in my latest video about the reported AI-agent activity targeting Library and Archives Canada. 🎥 twp.ai/9OblJl 4/4
twp.ai
youtu.be
What Happens When an AI Agent Doesn't Take No for an Answer?
050
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8h
**A harness is not automatically a security boundary.** If your harness blocks the production deployment tool, but the agent still has unrestricted terminal access AND production credentials... Well, congratulations. You now have a very fancy control with a giant hole in it. 😂 3/4
250
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8h
Turns out, an agent harness is generally software that surrounds the AI model and manages how it operates. It can coordinate tool access, execution, credentials, approvals, and other capabilities. But here's the important security distinction: 2/4
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 8h
I recently heard someone at a conference say that putting a "harness" around an AI agent could prevent it from doing things we didn't want it to do. And I thought: Okay. But what the heck is this harness made out of?! Is it code? Another AI? A collection of very sternly worded prompts? 😂 1/4
A smiling woman points at a small robot beside a bold headline reading “WHAT IS AN AI HARNSS?” and a diagram titled “AI AGENT” with the goal “Find this information and complete the task.” The chart shows “HARNESS” with Tool Gateway, Policy Checks, Credential Broker, Sandboxing, Approvals, and Monitoring & Logs, plus “TOOLS & SYSTEMS” and “BLOCKS UNAUTHORIZED ACTIONS” for Production, Sensitive Data, and Unapproved Changes.
170
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9h
Question for you: What's one security control you've added (or changed) specifically because your team started using AI coding tools? I'd love to hear what people are actually doing right now. #AppSec #AISecurity #SecureSoftwareDevelopment 5/5
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9h
Limiting blast radius. We don't need AI to be perfectly predictable. We need systems that can safely survive a 'surprise'. 🎧 Season 2, Episode 1: Your AI Worked 59 Times. What About the 60th? twp.ai/9Obuha 4/5
twp.ai
- YouTube
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9h
If an AI assistant has access to sensitive files, credentials, tools, or deployment capabilities, we need independent controls that don't rely on the AI consistently making good decisions. Least privilege. Independent security checks. HUMAN approvals for consequential actions. 3/5
100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9h
In the latest episode of DevSec Station, I share a real classroom experience where one AI-generated result behaved very differently from the other 59. It reminded me of something important: A prompt is NOT a security boundary. 2/5
100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 9h
Question for everyone using AI coding assistants or agents: **Are you designing your security controls around what you've ASKED your AI to do, or what it's actually CAPABLE of doing?** Because those are two very different things. 1/5
A smiling woman with long dark hair appears on the left against a blue tech-themed background. Large text reads “DevSec Station” with a yellow label reading “SEASON 2 • EPISODE 1,” plus code and security shield icons and a stylized railroad scene at sunset.
241
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 04/10/2026
The Bunny is now a regular at my place. 😂 What should I name him? 😂 I suspect he's someone's pet, but I don't know how to 'return' him or find his owner if there are no signs... Is it safe to grab him? And if I do, what do I feed him until I find his owners? I've never had a bunny.
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
220
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
💯
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
I'm curious what other AppSec and AI practitioners think (that's you). What security controls do you see as essential for AI agents? And what are we still not sure about? What are your 'may haves'? Article: twp.ai/9Obx3f #AppSec #AISecurity #SecureCoding #AIAgents 6/6
twp.ai
www.theguardian.com
OpenAI says its review into hacks, including on Australian government sites, is costing $500,000 a day
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
🔥 AI agents are no exception. 🔥 If we're building AI to improve efficiency and reduce costs, we also need to consider the potential costs of NOT designing for security, containment, least privilege, and observability from the start. Otherwise, all those savings can disappear. 😥 5/6
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
But I DO think there's an important lesson here for the rest of us. 👂 We've spent over a decade talking about shifting security left (or at least I have). Building security requirements into software from the beginning, rather than trying to bolt them on after something goes wrong. 4/6
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
I don't want to criticize OpenAI in this post. They're at the forefront of an emerging technology, and we don't know what security controls they originally implemented, what worked, what didn't, or what unexpected challenges they encountered. They are literally inventing this as they go along. 3/6
100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
According to recent reporting, OpenAI is reviewing approximately 50 PETABYTES of data to reconstruct what its agents did, using around 7,000 GPUs at a reported cost of over $500,000 USD per DAY. 😱 That's an extraordinary amount of incident response work. Talk about #hugops! 2/6
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 03/10/2026
AI is supposed to help us save time and money. But what happens when we don't build security in from the beginning? 1/6
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
5190
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
Who should be responsible when an autonomous agent goes rogue? 🎥 Watch here: twp.ai/9Obi3l #AISecurity #AppSec #AIAgents #SecureCoding 5/5
twp.ai
youtu.be
When Your AI Agent Breaks the Law, Who Is Responsible?
021
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
In my new video, I dig into accountability, containment, least privilege, logging, and why telling an AI agent to behave itself is NOT a security control. We need to stop vibe coding agents and letting them loose without proper security requirements. What do you think? 4/5
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
When your AI agent accesses someone else's systems without authorization, who's responsible? The developer? The company deploying it? The model provider? What if nobody explicitly instructed the agent to do anything wrong? 3/5
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
California's Attorney General has now issued an investigative subpoena to OpenAI concerning cybersecurity incidents and risks involving its AI models. This isn't a criminal charge or a finding of wrongdoing, but it raises VERY interesting questions. 2/5
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
Yesterday, someone commented on my LinkedIn asking when the law was going to get involved with AI agents accessing systems they aren't authorized to access. I said I thought it was only a matter of time. Apparently, that time was about 24 hours. 😳 1/5
Composite thumbnail with a smiling red-haired woman on the left and large headline text reading WHO’S LIABLE? across the top. On the right are a robot at a laptop, a judge’s gavel, and stacked papers labeled INVESTIGATION, ACCOUNTABILITY, and REGULATION?, with a blurred Capitol building in the background.
232
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
Picture it: the feature ships, everyone's thrilled, and then someone says "is the password being logged?" OH NO. Nobody's the villain here! That's the frustrating part. The rule was never written, so nobody broke it. Watch or listen on any podcast platform: twp.ai/9OXtHu #Episode12
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 02/10/2026
If you had to use emojis to summarize Application security as an industry, which ones would you use? #AppSecThursday #talkAppSectome
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
It doesn't get to decide what it's allowed to do.** 🎥 twp.ai/9OblIy 4/4
twp.ai
youtu.be
What Happens When an AI Agent Doesn't Take No for an Answer?
020
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
But what actually STOPS them from doing something we didn't intend? In my new video, I talk about this incident, introduce the concept of an AI agent harness, and explain the security controls we need to put around autonomous agents. Because: **The agent can decide what it wants to do. 3/4
351
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
Good news: there's no indication that government systems were compromised. But this raises a REALLY interesting question: **What happens when an AI agent encounters a security boundary and decides to 'be creative'?** We give agents goals. We give them tools. We give them access to systems. 2/4
250
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
Apparently, AI agents have been trying to hack the Canadian government. Oh, good. That's new. 😬 Researchers at Transluce reported suspicious AI-agent activity targeting Library and Archives Canada, including requests containing attack payloads and SQL injection attempts. 1/4
A smiling red-haired woman points at the viewer beside bold text reading AI AGENTS VS CANADA? WHO STOPS THEM?, with a small robot, code panel, security shield, and a Canadian flag in front of the Library and Archives Canada building.
2107
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
In this video, I explain what application security means, what AppSec teams do, and how AI is changing both. twp.ai/9OaNCU 3/3
twp.ai
youtu.be
What is Application Security?
010
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
It is everything you to do ensure it is safe, rugged, and secure. But AppSec is changing. Developers are using AI coding assistants. Actually, EVERYONE is using AI assistants. We're going faster than ever before. And sometimes it feels like no one is wearing a seat belt. 2/3
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
What is application security? And what does AppSec actually mean in 2026? At its core, application security (AppSec) is about making software more secure throughout its entire lifecycle. From the first idea and design decisions, through development and testing, all the way into production. 1/3
A woman with long brown hair speaks in front of bookshelves, with a purple title box reading “What is Application Security?” Video player controls and a 0:00 / 2:48 time display appear along the bottom.
130
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/10/2026
Nobody gets excited about "requirements." Yet here I am, all fired up, because the ones nobody writes down are the reason things blow up later. Sorry, I don't make the rules. But that's the point. Somebody has to. Watch or listen on any podcast platform: twp.ai/9OXtHf #Episode12
030
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
I made a short video about this after Spain's data protection authority received its first breach notification involving an attack reportedly carried out by an AI agent: 🎥 twp.ai/9Oa8cK 4/4
twp.ai
youtu.be
What If an AI Agent Attacks Your Application?
021
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
Rate limits. Logging. Monitoring. Alerting. FastER detection and response. AI agents may make attackers faster and more adaptable. But they don't make good application security obsolete. **They make it more important than ever before.** 3/4
120
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
Does it matter whether there's a person sitting behind a keyboard? A script? A bot? An AI agent? From the application's perspective, hostile behaviour is hostile behaviour. And that makes the answer surprisingly boring: Authentication. Authorization. Least privilege. Input validation. 2/4
110
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
I think we're all coming back to this question: **Does your application care WHO is attacking it?** Imagine someTHING is: → trying credentials → probing your APIs → accessing things it shouldn't → exploiting a vulnerability → changing its approach when something doesn't work 1/4
A woman with long brown hair speaks into a fuzzy microphone in front of a white bookshelf filled with books and awards. Large on-screen text reads, What If Someone Else's AI Agent Attacks You?
161
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
I talk more about agent escapes and the controls we can put around them here: twp.ai/9Oa8e0 4/4
twp.ai
youtu.be
Your AI Agent Escaped. Would You Know?
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
If an action is especially dangerous, require approval outside the agent. Prompts can help guide behaviour. **Security controls should limit what happens when the behaviour isn't what we expected.** That's how we make an AI agent doing something weird a lot less exciting. :-) 3/4
100
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
If the agent should not be able to access something, restrict its permissions. If it should not be able to communicate somewhere, restrict its network access. If it should not be able to call a particular tool, don't give it that tool. 2/4
210
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 30/09/2026
One of my biggest rules for AI agent security: **Don't make the AI responsible for enforcing the security boundary that contains the AI.** If your security control is: "Dear AI, please don't do this dangerous thing." ...that's a prompt. A suggestion really. It is not a security boundary. 1/4
A smiling woman with long dark red hair sits in front of white bookshelves, with a microphone visible at the bottom and books and awards behind her. A purple text box at the upper left reads, “Your agent escaped. Would you know?”
261
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
It built and published the attacker's code. Provenance is GOOD. We should use it! We just need other security layers too. 🎥 I explain what happened here: twp.ai/9OaPzH 3/3
twp.ai
youtu.be
This Malicious npm Package Had Valid Provenance. How?!!?!?!
000
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
In the recent GHAPPIER software supply chain attack, a malicious npm package had valid provenance. The provenance wasn't broken. The attackers had compromised the source repository. So the legitimate build and publishing infrastructure did exactly what it was supposed to do. 2/3
210
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
What does software provenance actually tell you? It can tell you things like: → Where an artifact was built → How it was built → What source and build process produced it What it does NOT tell you: **"This code is safe."** That's a really important distinction. 1/3
A woman with long dark red hair sits in front of white shelves filled with books and security-related decor, speaking into a microphone. On-screen text reads, “This Malicious npm Package Had Valid Provenance. How?!?!” and a subtitle at the bottom says, “necessarily.”
151
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 29/09/2026
Someone ordered 100 signed copies of Alice and Bob Learn Secure Coding, and it's taken longer to sign them than planned. I can only imagine what younger Tanya would think of how amazing my life has turned out. Thank you to every single person who has bought one of my books. 💜 #gratitude
Smiling woman with dark hair sits on a couch and points to stacks of yellow books beside her. The book cover reads Alice & Bob learn SECURE CODING, by Tanya Janca, with WILEY at the bottom.
040