Anna Oliveira
Security Blindspots and How to Learn About Them - Anna Oliveira
#1about 3 minutes
Creating a terminal game to learn secure coding practices
The project Blindspot was inspired by Rustlings to create a gamified, open-source terminal experience for practicing vulnerability identification in code.
#2about 4 minutes
Gameplay mechanics of the Blindspot security game
Blindspot presents code snippets in the terminal with multiple-choice options to identify vulnerabilities, providing detailed explanations after each correct answer.
#3about 3 minutes
Sourcing security challenges and embracing open source contributions
The game's challenges are sourced from OWASP materials and AI tools, with an open-source model designed to invite community contributions and corrections.
#4about 3 minutes
Contributing security content using simple YAML files
You can contribute new challenges and vulnerability explanations to the project by editing YAML files, without needing any knowledge of Go.
#5about 2 minutes
The personal motivation behind building a learning tool
The project was created out of a personal desire to learn and share, emphasizing the joy of coding over commercial success or viral fame.
#6about 2 minutes
Balancing automated security scanning with manual code review
While automated tools offer efficiency, they often lack application context and produce false positives, making manual code review essential for deep security analysis.
#7about 3 minutes
Navigating the career transition from engineering to security
Transitioning into a security career is challenging due to experience requirements, making internal mobility within your current company the most practical path.
#8about 1 minute
How teaching others solidifies your own technical knowledge
Explaining concepts to others is a powerful learning method because it exposes gaps in your own understanding and forces you to master the subject.
#9about 4 minutes
A call for community contributions and future localization
The project seeks community contributions for new challenges and plans to add localization to make security education accessible to a global audience.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
14:17 MIN
Hands-on security training for developers
How GitHub secures open source
55:17 MIN
Avoiding common security mistakes and giving better feedback
The weekly developer show: Boosting Python with CUDA, CSS Updates & Navigating New Tech Stacks
27:19 MIN
Key takeaways on IDE and developer tool security
You click, you lose: a practical look at VSCode's security
17:39 MIN
Augmenting tests with specialized security tools
Plants vs. Thieves: Automated Tests in the World of Web Security
29:56 MIN
Q&A on speed, team adoption, and common mistakes
DevSecOps: Injecting Security into Mobile CI/CD Pipelines
00:03 MIN
Why developers are a prime target for attackers
You click, you lose: a practical look at VSCode's security
1:39:28 MIN
Key takeaways and resources for continuous security learning
Software Security 101: Secure Coding Basics
01:10 MIN
Making web application security accessible to developers
What The Hack is Web App Sec?
Featured Partners
Related Videos
What The Hack is Web App Sec?
Jackie
Plants vs. Thieves: Automated Tests in the World of Web Security
Ramona Schwering
Coffee with Developers - Cassidy Williams -
Cassidy Williams
Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor
Feross Aboukhadijeh
How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR
Anna Bacher
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Walking into the era of Supply Chain Risks
Vandana Verma
Real-World Security for Busy Developers
Kevin Lewis
From learning to earning
Jobs that call for the skills explored in this talk.

Application Security Engineer
BrainRocket Limited
Municipality of Valencia, Spain
Kubernetes
Amazon Web Services (AWS)

Senior Software Engineer (Go) - Security & Secrets
Jobgether
Remote
Azure
Kubernetes
Microservices
Google Cloud Platform
+1

Senior Software Engineer (Go) - Security & Secrets
Jobgether
Municipality of Madrid, Spain
Remote
Azure
Kubernetes
Microservices
Google Cloud Platform
+1

{"@context":"https://schema.org","@graph":[{"@context":"https://schema.org/","@type":"JobPosting","@id":"#jobPosting","title":"Application Security Engineer
Ninedots
Python
CircleCI
Amazon Web Services (AWS)

DevOps Security Engineer with Golang Development Focus
SAP AG
Sankt Leon-Rot, Germany
Junior
Go
Azure
DevOps
Puppet
Docker
+6

AI Security Content Engineer
TryHackMe
Charing Cross, United Kingdom
Remote
€57K
Intermediate
Bash
Azure
Python
+7

Application Security Engineer
Palantirians
Charing Cross, United Kingdom
Remote
Go
Java
Python
JavaScript
+1

Senior / Fullstack Developer (Go, Golang) Remote
Blackfluo
Municipality of Madrid, Spain
Remote
Senior
Go
XML
HTML
JSON
+2
