World Congress 2022 Jun 15, 2022

Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes

Tino Sokic

Information security expert Tino argues that 90% of breaches stem from human error, not tech. Learn to ditch the 'it works' fallacy and fix your naive coding habits.

Pause
Mute Enter Fullscreen
#1 about 6 min

Prioritizing security and risk over basic functionality

Focusing purely on making code work often causes teams to overlook critical risk management and secure implementation practices.

#2 about 3 min

Understanding the differences between developers and programmers

There is a distinct difference between programmers who specifically write code and developers who manage broader project responsibilities.

#3 about 3 min

Inherent security flaws in legacy internet protocols

Foundational internet protocols like DNS and BGP were originally built for simple network connectivity rather than robust security.

#4 about 4 min

Applying the ninety ten rule to cybersecurity

Effective cybersecurity defense depends only slightly on technical mechanisms and predominantly on human awareness and daily behavior.

#5 about 3 min

Social engineering risks associated with private email usage

Using personal email accounts for professional development communications creates direct vulnerabilities to targeted social engineering and phishing attacks.

#6 about 2 min

Overconfidence and poor secret management in software

Deploying untested code and relying on easily guessable passwords represent fundamental and avoidable failures in modern software development.

#7 about 2 min

Physical security risks and shared development accounts

Shoulder surfing in public spaces and distributing shared access credentials are significantly overlooked physical security hazards for remote teams.

#8 about 1 min

Security vulnerabilities from unnecessary third party libraries

Importing massive external functional libraries for minor programmatic needs carelessly introduces unpatched structural flaws into production applications.

#9 about 1 min

The downsides of promoting engineers to management roles

Promoting top technical programming talent directly into team leadership roles frequently causes serious role misalignment and engineering retention issues.

#10 about 4 min

Balancing business expectations with secure software development

Rigid business expectations and nonnegotiable delivery milestones consistently restrict the realistic implementation of secure application structures.

Matching moments

55 sec

Setting the scene for real-world cybersecurity failures

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

1:34 min

Elevating basic developer security knowledge for rapid wins

Isaac Evans Isaac Evans · WWC 2025

2:05 min

Making security a foundational feature in software development

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

7:16 min

Addressing developer adoption and future software security risks

Anna Fritsch-Weninger · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois