Tino Sokic
Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes
#1about 2 minutes
Why developers make basic cybersecurity mistakes
The talk will cover common security errors made by developers, the importance of correct terminology, and the conflict between functionality and business risk.
#2about 6 minutes
Moving beyond the "it just works" developer mindset
Developers must shift from prioritizing simple functionality to understanding the underlying infrastructure and building secure, robust solutions from the start.
#3about 3 minutes
Differentiating between a developer and a programmer
A developer has a broader range of responsibilities including project management, whereas a programmer is focused on specific coding tasks.
#4about 4 minutes
Understanding the internet's inherent insecurity
Core internet protocols like DNS and BGP were not built for security, and human behavior is a far greater risk than the technology itself.
#5about 3 minutes
A social engineering attack using a personal email
A simple social engineering attack demonstrates how using personal email for business communication creates significant security vulnerabilities.
#6about 6 minutes
Five common cybersecurity mistakes developers make
Developers often exhibit risky behaviors like overconfidence, poor password management, account sharing, and improper use of third-party libraries.
#7about 4 minutes
The clash between business pressure and security reality
Business pressures often force developers to launch products with known bugs or security flaws simply to meet deadlines and get paid.
Related jobs
Jobs that call for the skills explored in this talk.
MARKT-PILOT GmbH
Stuttgart, Germany
Remote
€75-90K
Senior
Java
TypeScript
+1
Matching moments
01:06 MIN
Malware campaigns, cloud latency, and government IT theft
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
05:55 MIN
The security risks of AI-generated code and slopsquatting
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
01:15 MIN
Crypto crime, EU regulation, and working while you sleep
Fake or News: Self-Driving Cars on Subscription, Crypto Attacks Rising and Working While You Sleep - Théodore Lefèvre
11:32 MIN
The industry's focus on frameworks over web fundamentals
WeAreDevelopers LIVE – Frontend Inspirations, Web Standards and more
05:01 MIN
Comparing the security models of browsers and native apps
Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof
03:45 MIN
Preventing exposed API keys in AI-assisted development
Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2
02:48 MIN
Building trust through honest developer advocacy
Devs vs. Marketers, COBOL and Copilot, Make Live Coding Easy and more - The Best of LIVE 2025 - Part 3
07:39 MIN
Prompt injection as an unsolved AI security problem
AI in the Open and in Browsers - Tarek Ziadé
Featured Partners
Related Videos
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Programming secure C#/.NET Applications: Dos & Don'ts
Sebastian Leuer
Security Pitfalls for Software Engineers
Jasmin Azemović
101 Typical Security Pitfalls
Alexander Pirker
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Typed Security: Preventing Vulnerabilities By Design
Michael Koppmann
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Software Security 101: Secure Coding Basics
Thomas Konrad
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.


Secunet
Remote
Python
Grafana
Terraform
Kubernetes
+1


Gmv
Municipality of Madrid, Spain
Remote
Intermediate
API
Java
REST
DevOps
+5

Zertificon Solutions GmbH
Berlin, Germany
Remote
Intermediate
Go
PHP
API
REST
+9

Siemens AG
München, Germany
API
GIT
Ruby
Docker
Ansible
+4

Working Class Heroes
Rotterdam, Netherlands
Remote
DNS
Bash
Linux
Python
+5

