> Markdown version of [/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira?t=1081](https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira?t=1081). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Blindspots and How to Learn About Them - Anna Oliveira Think automated scanners catch every vulnerability? Anna Oliveira built Blind Spot, an open-source CLI game, to help developers manually train their eyes to spot what AI misses. - **Speakers:** Anna Oliveira - **Event:** Coffee With Developers - **Published:** November 10, 2025 - **Duration:** 26:28 - **URL:** https://www.wearedevelopers.com/videos/1754-security-blindspots-and-how-to-learn-about-them-anna-oliveira ## Summary Software engineer Anna Oliveira built "Blind Spot," an open-source, command-line game designed to teach secure coding practices. Inspired by terminal-based learning tools like Rustlings, Blind Spot gamifies the process of identifying vulnerabilities in code snippets. By keeping the experience in the terminal and using a multiple-choice format, the tool lowers the intimidation factor often associated with security training and helps developers "train your eye to identify secure code."<br><br>Written in Go using the Bubble Tea library for its terminal UI, the project emphasizes community collaboration. Users can easily contribute new security challenges to a simple YAML dataset, drawing from OWASP materials or personal experience. Anna points out that teaching others is one of the most effective ways to master a subject, and crowdsourcing these challenges allows developers to collaboratively demystify complex concepts.<br><br>While AI and automated scanning tools are valuable for resource-constrained teams, they often lack contextual awareness and generate false positives, making manual vulnerability spotting a critical software engineering skill. For engineers looking to transition into security, market requirements can be harsh, making cross-training within a current role the most pragmatic stepping stone. Ultimately, Blind Spot highlights the joy of coding for education and the ongoing need to make technical concepts highly accessible. **Keywords:** secure coding practices, command-line gamification, vulnerability identification, software security training, open-source security tools, go programming, bubble tea terminal library, OWASP vulnerabilities, AI security scanning limitations, security career transitions, developer education platforms, YAML dataset contributions, security false positives, manual code review, terminal-based learning ## Chapters 1. **Creating a terminal game for security education** (00:00) — How the challenges of learning secure coding inspired an interactive command-line tool. 1. **Exploring the mechanics of vulnerability spotting** (03:39) — How category filters and multiple-choice questions train developers to identify vulnerabilities. 1. **Sourcing vulnerabilities and encouraging open source collaboration** (07:36) — Using OWASP materials and AI tools to generate security challenges for public contribution. 1. **Contributing data sets without learning Go** (10:21) — How developers can add new security challenges using simple YAML configuration files. 1. **Building terminal user interfaces with Bubble Tea** (12:26) — Leveraging the Bubble Tea library to create visually appealing command-line environments. 1. **Sharing side projects and embracing public feedback** (13:28) — The importance of coding for joy and sharing educational tools despite being a learner. 1. **Balancing automated security scanners with manual reviews** (15:33) — Why understanding application context remains crucial despite the rise of automated scanning platforms. 1. **Transitioning from software engineering to security roles** (18:01) — Navigating career mobility hurdles by introducing security practices within current engineering workflows. 1. **Solidifying engineering concepts by teaching others** (21:24) — How building educational tools and explaining concepts deepens personal technical understanding. 1. **Expanding project accessibility through cultural localization** (24:44) — Plans to translate project content to ensure non-English speakers can access security training. ## Related Moments - [Improving developer education with realistic security training environments](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) (from "How GitHub secures open source") - [Using intentionally vulnerable applications for practical security training](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Exploring pathways to application security careers and research workflows](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Recommended training platforms for developing security mindsets](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) (from "Software Security 101: Secure Coding Basics") - [Identifying non-coding software vulnerabilities and organizational risks](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) (from "Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?") - [Identifying technical blind spots and exploring open source](https://www.wearedevelopers.com/videos/912-coffee-with-developers-cassidy-williams) (from "Coffee with Developers - Cassidy Williams - ") ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 105 - Security First](https://www.wearedevelopers.com/magazine/393-dev-digest-105-security-first) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 112 - The True Crime of AI Development](https://www.wearedevelopers.com/magazine/421-dev-digest-112-the-true-crime-of-ai-development) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Software Engineer II, Security](https://www.wearedevelopers.com/jobs/ext/131510-software-engineer-ii-security) at **GitHub**