
Tanya Janca discusses the impact of AI on application security and the challenges it presents.
Kate Holterhoff sits down with Tanya Janca, Secure Coding and AI Trainer at SheHacksPurple, to talk about what AI is doing to application security. Tanya's take: we're driving a car at three times the speed limit after 25 beers. AI writes huge portions of production code, most developers were never taught to review code for security in the first place, and release velocity keeps climbing. The conversation gets into the difference between using AI to help you code and full-on vibe coding, why context collapse trips up LLMs on security decisions, and what's wrong with bolting AI onto legacy AppSec tools instead of building new ones. Tanya also weighs in on Anthropic's Mythos vulnerability-finding model, argues that the bug bounty economy is heading for collapse, discusses supply chain security and the future of the SDLC, and wraps by explaining Canada's Petition E-7115, which Janca helped draft to require secure coding standards across the Canadian federal government. Show notes: https://redmonk.com/videos/tanya-janca/ Chapters 00:00 Introduction to AI and Security 02:58 The Current Security Landscape 05:49 Understanding Context Collapse in AI 09:51 The Role of Vibe Coding 13:50…
Host: Kate Holterhoff
Guest: Tanya Janca
Organizations: SheHacksPurple, Anthropic
Places: Canada
Explore listener stats, chart rankings, contacts and more on the The MonkCast podcast page.