> Markdown version of [/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes Information security expert Tino argues that 90% of breaches stem from human error, not tech. Learn to ditch the 'it works' fallacy and fix your naive coding habits. - **Speakers:** Tino Sokic - **Event:** World Congress 2022 - **Published:** June 15, 2022 - **Duration:** 28:01 - **URL:** https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes ## Summary **Core Narrative** Information security professional Tino explores the foundational cybersecurity mistakes developers make, arguing that human behavior—not technology—is the primary weak link. Establishing the "90/10 conceptual rule," he emphasizes that 90% of security relies on user awareness and actions, whereas only 10% depends on the technical implementation of systems operating on aging internet infrastructure. **Key Ideas & Vulnerabilities** The core problem frequently stems from the "it works" fallacy, where aggressive business milestones compel developers to ship functional but insecure code. The narrative highlights actionable developer pitfalls, including poor secret management, risky public behaviours like shoulder-surfing exposure, account sharing during debugging, and the blind importation of massive third-party libraries that introduce unvetted software vulnerabilities. Additionally, the presentation critically examines the common organizational misstep of promoting top coders into management roles, which can negatively impact both team morale and holistic project oversight. **Takeaways & Application** Through a real-world social engineering anecdote—compromising a lead developer simply by mimicking a personal email address—the talk reinforces that basic operational awareness is just as critical as writing secure code. Ultimately, technical teams must transition away from risky conveniences, enforce strict credential policies, and rigorously vet external dependencies to prevent fundamental breaches. **Keywords:** cybersecurity awareness, secure coding practices, 90/10 security rule, secret management vulnerabilities, legacy internet protocols, third-party library risks, software supply chain security, social engineering attacks, account sharing debugging, shoulder surfing prevention, software delivery milestones, developer security behaviors, credential management mechanisms, phishing attack simulations, organizational compliance standards ## Chapters 1. **Prioritizing security and risk over basic functionality** (02:49) — Focusing purely on making code work often causes teams to overlook critical risk management and secure implementation practices. 1. **Understanding the differences between developers and programmers** (08:43) — There is a distinct difference between programmers who specifically write code and developers who manage broader project responsibilities. 1. **Inherent security flaws in legacy internet protocols** (11:36) — Foundational internet protocols like DNS and BGP were originally built for simple network connectivity rather than robust security. 1. **Applying the ninety ten rule to cybersecurity** (13:46) — Effective cybersecurity defense depends only slightly on technical mechanisms and predominantly on human awareness and daily behavior. 1. **Social engineering risks associated with private email usage** (16:58) — Using personal email accounts for professional development communications creates direct vulnerabilities to targeted social engineering and phishing attacks. 1. **Overconfidence and poor secret management in software** (19:51) — Deploying untested code and relying on easily guessable passwords represent fundamental and avoidable failures in modern software development. 1. **Physical security risks and shared development accounts** (21:40) — Shoulder surfing in public spaces and distributing shared access credentials are significantly overlooked physical security hazards for remote teams. 1. **Security vulnerabilities from unnecessary third party libraries** (22:47) — Importing massive external functional libraries for minor programmatic needs carelessly introduces unpatched structural flaws into production applications. 1. **The downsides of promoting engineers to management roles** (23:40) — Promoting top technical programming talent directly into team leadership roles frequently causes serious role misalignment and engineering retention issues. 1. **Balancing business expectations with secure software development** (24:31) — Rigid business expectations and nonnegotiable delivery milestones consistently restrict the realistic implementation of secure application structures. ## Related Moments - [Setting the scene for real-world cybersecurity failures](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) (from "Checkmate: 5 Real Incidents That Can End a Software Company") - [Identifying non-coding software vulnerabilities and organizational risks](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) (from "Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?") - [Bridging the gap between developers and security tools](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Elevating basic developer security knowledge for rapid wins](https://www.wearedevelopers.com/videos/1560-simple-steps-to-kill-devsec-without-giving-up-on-security) (from "Simple Steps to Kill DevSec without Giving Up on Security") - [Making security a foundational feature in software development](https://www.wearedevelopers.com/videos/100358-always-on-the-right-track-with-rails-with-eileen-uchitelle-senior-system-engineer-at-github) (from "Always on the Right Track with Rails with Eileen Uchitelle, Senior System Engineer at GitHub") - [Addressing developer adoption and future software security risks](https://www.wearedevelopers.com/videos/900-from-syntax-to-singularity-ai-s-impact-on-developer-roles) (from "From Syntax to Singularity: AI’s Impact on Developer Roles") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Software Engineer II, Security](https://www.wearedevelopers.com/jobs/ext/131510-software-engineer-ii-security) at **GitHub** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio**