Skip to content
Artwork for The Application Security Podcast
The Application Security Podcast · April 30 · 47 min

Tanya Janca - Secure Vibe Coding

If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models confidently reviewing their own insecure output, and developers accepting enormous finding backlogs for code they did not enjoy writing. The discussion also examines whether security tooling will consolidate into AI platforms, how AppSec must be reimagined, and why continuous, embedded guidance matters more than occasional training. Tanya closes by introducing her DevSecStation podcast. Connect with Tanya Janca: → Tanya Janca on LinkedIn → SecureMyVibe → DevSecStation Mentioned in this episode: → SecureMyVibe → OWASP Top 10 → Burp Suite → OWASP ZAP → DevSecStation → Tanya Janca (SheHacksPurple) → ChatGPT → Stack Overflow → The Security Table podcast Follow the Application Security Podcast: ➜ Home ➜ X ➜ LinkedIn ➜ YouTube ➜ Instagram ➜ Facebook Chapters: 00:00 Tanya Janca returns 02:10 What vibe coding actually means 04:03 AI adoption and how developers prompt 05:57 Treating AI like an intern 07:28 Do AI systems need parental controls? 09:34 Security prompts for everyday development 11:47 Models, memory, and protecting sensitive data 14:11 What happens when Claude goes away? 16:02 The most dangerous vibe-coding misconception 18:06 Threat modeling before AI writes the code 22:48 Using AI throughout the development lifecycle 25:32 A reusable secure-prompt framework 29:09 Expose security assumptions and challenge flattery 32:30 Reviewing an AI-generated codebase 36:09 Will AI platforms absorb security tooling? 37:39 Five million findings for code nobody wrote 42:19 The remaining pieces of secure vibe coding 43:52 Reimagining AppSec 45:25 Continuous guidance beats occasional training 46:05 Introducing DevSecStation 47:12 Closing thoughts Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast

0:00-47:57

transcript

No transcript — this publisher did not publish one.

show notes

If AI writes all the code and the developer barely reads it, where does AppSec fit? Tanya Janca returns to define vibe coding and explain why models trained on insecure public code do not understand secure design by default. She and the hosts build a practical secure-vibe-coding framework: explicit requirements, human-led threat modeling, reusable security prompts, iterative review, SAST, and independent testing. Tanya shares hard-earned examples of Claude removing error handling, models confidently reviewing their own insecure output, and developers accepting enormous finding backlogs for code they did not enjoy writing. The discussion also examines whether security tooling will consolidate into AI platforms, how AppSec must be reimagined, and why continuous, embedded guidance matters more than occasional training. Tanya closes by introducing her DevSecStation podcast.

Connect with Tanya Janca:
Tanya Janca on LinkedIn
SecureMyVibe
DevSecStation

Mentioned in this episode:
SecureMyVibe
OWASP Top 10
Burp Suite
OWASP ZAP
DevSecStation
Tanya Janca (SheHacksPurple)
ChatGPT
Stack Overflow
The Security Table podcast

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Tanya Janca returns
02:10 What vibe coding actually means
04:03 AI adoption and how developers prompt
05:57 Treating AI like an intern
07:28 Do AI systems need parental controls?
09:34 Security prompts for everyday development
11:47 Models, memory, and protecting sensitive data
14:11 What happens when Claude goes away?
16:02 The most dangerous vibe-coding misconception
18:06 Threat modeling before AI writes the code
22:48 Using AI throughout the development lifecycle
25:32 A reusable secure-prompt framework
29:09 Expose security assumptions and challenge flattery
32:30 Reviewing an AI-generated codebase
36:09 Will AI platforms absorb security tooling?
37:39 Five million findings for code nobody wrote
42:19 The remaining pieces of secure vibe coding
43:52 Reimagining AppSec
45:25 Continuous guidance beats occasional training
46:05 Introducing DevSecStation
47:12 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

links16