Coffee With Developers • Nov 10, 2025

Security Blindspots and How to Learn About Them - Anna Oliveira

Anna Oliveira

Think automated scanners catch every vulnerability? Anna Oliveira built Blind Spot, an open-source CLI game, to help developers manually train their eyes to spot what AI misses.

Pause
Mute Enter Fullscreen
#1 about 4 min

Creating a terminal game for security education

How the challenges of learning secure coding inspired an interactive command-line tool.

#2 about 4 min

Exploring the mechanics of vulnerability spotting

How category filters and multiple-choice questions train developers to identify vulnerabilities.

#3 about 3 min

Sourcing vulnerabilities and encouraging open source collaboration

Using OWASP materials and AI tools to generate security challenges for public contribution.

#4 about 3 min

Contributing data sets without learning Go

How developers can add new security challenges using simple YAML configuration files.

#5 about 2 min

Building terminal user interfaces with Bubble Tea

Leveraging the Bubble Tea library to create visually appealing command-line environments.

#6 about 3 min

Sharing side projects and embracing public feedback

The importance of coding for joy and sharing educational tools despite being a learner.

#7 about 3 min

Balancing automated security scanners with manual reviews

Why understanding application context remains crucial despite the rise of automated scanning platforms.

#8 about 4 min

Transitioning from software engineering to security roles

Navigating career mobility hurdles by introducing security practices within current engineering workflows.

#9 about 4 min

Solidifying engineering concepts by teaching others

How building educational tools and explaining concepts deepens personal technical understanding.

#10 about 2 min

Expanding project accessibility through cultural localization

Plans to translate project content to ensure non-English speakers can access security training.

Matching moments

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

6:12 min

Recommended training platforms for developing security mindsets

Thomas Konrad · World Congress 2021

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

30 sec

Identifying technical blind spots and exploring open source

Cassidy Williams Cassidy Williams · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 5

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

September 25, 2026 · 14:50–15:20

Stage 8

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Stage 1

The Era of Machine-Driven Defense is Here: Headless Security

Loris Degioanni

Founder & CTO of Sysdig

Loris Degioanni
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois