Hacking Secure Coding Into Education
Or Sahar (co-founder · Secure From Scratch), Yariv Tal
BSides Las Vegas 2025 · Day 1
Overview
Osar and Yariv Ta argue that software remains insecure in 2025 because education still teaches dangerous patterns—using a real high school “internet programming” assignment as a case study with three serious issues in one example (SQL injection, wildcard LIKE misuse, missing password hashing). Their response is a multi-year advocacy and delivery effort branded “Secure from Scratch,” moving security left to before developers become developers: high schools, universities, YouTube, open workshops (including DEF CON), and an open GitHub repository of workshop materials. They also introduce a mnemonic acronym (VER, inspired by SOLID) to condense secure coding guidance, and a small OWASP-adjacent library project aimed at eliminating path traversal in Python and Java.

Key moments
- 2:00 Speakers introduce backgrounds: long-time developers turned appsec; 2025 still ships SQLi/XSS/path traversal and AI adds pressure.
- 4:00 High school login assignment dissection: SQL injection on username/password, dangerous LIKE wildcards, missing password hashing.
- 8:00 OWASP Global 2022 push for curriculum change reportedly stalled; pivot to direct teacher workshops and national spread.
- 10:00 University semester course born from LinkedIn outreach; syllabus written week-to-week under pressure—not recommended template.
- 14:00 Workshop pedagogy: intentional traps, 11/12 developers fall in, then hack demos with optional participation.
- 16:00 VER acronym introduced (SOLID-inspired); OWASP Trust path-library idea to make path traversal structurally harder.
- 18:00 Open GitHub repo model: paid workshops subsidize public materials; YouTube iteration and English rollout plans.
- 22:00 Live hall-computer demo: cheating attempt hits validation issues; discussion of why naive blocking fails (e.g., names containing 'right').
Hacking Secure Coding Into Education
Speakers: Osar (as introduced; spelling as transcribed), penetration tester and secure-coding consultant; Yariv Ta (as introduced), application security researcher and former long-time developer and educator
Conference: BSides Las Vegas
YouTube: https://www.youtube.com/watch?v=x1lqNZNMbvU
Overview
Osar and Yariv Ta argue that software remains insecure in 2025 because education still teaches dangerous patterns—using a real high school “internet programming” assignment as a case study with three serious issues in one example (SQL injection, wildcard LIKE misuse, missing password hashing). Their response is a multi-year advocacy and delivery effort branded “Secure from Scratch,” moving security left to before developers become developers: high schools, universities, YouTube, open workshops (including DEF CON), and an open GitHub repository of workshop materials. They also introduce a mnemonic acronym (VER, inspired by SOLID) to condense secure coding guidance, and a small OWASP-adjacent library project aimed at eliminating path traversal in Python and Java.
Background
▶ Watch: Speakers introduce backgrounds: long-time developers turned appsec; 2025 stil... (2:00)
The speakers establish credibility through blended careers: Osar as a former developer (many years) who moved into cybersecurity about 10 years ago, now doing pentesting and secure coding workshops in government and private sectors. Yariv describes 40 years of development, university lecturing, bootcamp mentoring, and roughly five years in application security research.
They anchor urgency with familiar incidents: SQL injection discussed since 1998 yet still central to major breaches; MoveIt in 2023 cited with $9 billion loss (speaker figure); a claim that U.S. policy in 2024 will “no longer forgive” SQL injection flaws (as phrased—treat as speaker paraphrase, exact policy text unknown from transcript). Other classes mentioned: XSS, path traversal, insecure file upload, and AI-generated code risks (speakers cite 40–50% vulnerability rate from AI—source not specified in transcript).
They critique the industry tool stack (SAST/DAST/SCA, threat modeling) as largely after code exists.
The speakers also lean on humor and performance to keep the audience engaged—roller coasters and mountains as personal “drugs of choice,” and a running gag about saying AI only twice. The humor matters because the underlying claim is uncomfortable: the industry spends massively on tools while the pedagogical foundation can still teach SQL string concatenation for authentication. If that claim is true, then AppSec is partially a labor arbitrage problem: enterprises pay to remediate what schools could prevent cheaply, at least for common classes.
Key Findings
▶ Watch: OWASP Global 2022 push for curriculum change reportedly stalled; pivot to dir... (8:00)
- Curriculum is an attack surface: The high school login example demonstrates concatenated SQL, unsafe
LIKEpatterns, and cleartext password handling—presented as representative of how students are taught, not as an isolated mistake.
- Advocacy alone stalled: After a 2022 OWASP Global talk arguing coding education must change, the speakers expected universities and high schools to adapt; “nothing happened.”
- Grassroots path through teachers: A friend who is a computer science teacher shared materials across hundreds of teachers nationally; requested changes were slow, so the speakers ran an in-school workshop for students, then leveraged summer teacher gatherings to spread Secure from Scratch.
- University scaling via LinkedIn: A professor contacted Osar after LinkedIn posts; this led to a full-semester course (~13 sessions of 3–4 hours), with the syllabus and lectures written during the semester under time pressure (explicitly not recommended as a model).
- National cyber directorate amplification: After reputational spread, Israel’s national cyber directorate (as described) allegedly offered to share their names with universities/colleges; the speakers accepted broad teaching engagements, then used YouTube reels to scale duplicated effort.
- Pedagogy: trap labs, then hack: Workshops give coding tasks with intentional insecure paths; 11 of 12 developers reportedly fall into traps. After attempts, facilitators demonstrate exploitation; hacking portions are optional for attendees who dislike offensive segments.
- VER acronym: A SOLID-inspired mnemonic condenses preventive guidance; details deferred to YouTube (not expanded in transcript).
- OWASP Trust path library: Osar describes a minor OWASP project replacing
pathlibraries in Python and Java so path traversal becomes “impossible” by construction—analogized to parameterized queries for SQLi.
- Open repository sponsorship model: Private customers pay for custom workshops; materials are then open-sourced (customers reportedly agree), funding public artifacts.
- AI implication: Because developers increasingly use AI, students must learn secure coding and how to demand secure output from agents (speaker framing).
Institutional friction (implicit lesson): The teacher-network story is a case study in coordination costs. Even motivated educators sharing materials nationally could not quickly rewrite curricula; workshops became the path of least resistance. That mirrors enterprise behavior: engineering playbooks update slowly because retraining is expensive. The speakers argue for attacking the bottleneck—curriculum authors and professors—rather than only the symptom—CVEs in production.
Technical Deep Dive
▶ Watch: Workshop pedagogy: intentional traps, 11/12 developers fall in, then hack dem... (14:00)
The high school demo (partially live) simulates a hall computer questionnaire: students enter answers; teachers review correctness. The “attack” prompt asks how a student could always appear correct despite wrong answers. The on-stage attempt hits “illegal characters” validation; the speakers note a partially fixed version still has issues, and blocking patterns like right fails because some legitimate last names contain the substring. They intentionally do not fully solve it on stage, pointing viewers to YouTube walkthroughs.
The path library project is described as a safe API wrapping path operations—conceptually similar to canonicalization and chroot-like constraints, though implementation details are not provided in the transcript.
Why the high school cheating scenario is pedagogically clever: It reframes input validation and authorization as a game students already understand—cheating—rather than as abstract security jargon. The failed on-stage exploit is not a flaw of the talk; it demonstrates real developer experience: first fixes are often blacklists that break legitimate inputs and do not stop determined adversaries. The speakers explicitly call out why blocking the substring right fails for some last names, which is a miniature lesson in false positives and internationalization risk.
Demo / Proof of Concept
▶ Watch: VER acronym introduced (SOLID-inspired); OWASP Trust path-library idea to mak... (16:00)
A short interactive demo attempts to show student cheating on a local questionnaire program; the demo encounters validation issues and ends as a teaching moment about incomplete fixes and over-broad blocking.
Defensive Implications
▶ Watch: Live hall-computer demo: cheating attempt hits validation issues; discussion ... (22:00)
- Fix the syllabus, not only corporate AppSec gates: insecure templates in schools propagate for decades.
- Hands-on secure coding must be framed as building, not punishment; optional offensive steps respect developer preferences.
- Prefer APIs that remove bug classes (parameterized queries, safe path APIs) over policy memos alone.
- Treat AI assistance as a multiplier—good or bad—requiring baseline secure patterns first.
- Open workshop repositories reduce duplication across companies and schools, provided legal review aligns with your jurisdiction.
Hiring and internship implications: If university curricula lag, internships become the first encounter with secure coding for many juniors. The speakers’ university engagements are effectively an attempt to shift that first encounter earlier. Organizations that hire aggressively from bootcamps should expect the same gap unless they validate foundational secure patterns in interviews rather than only framework trivia.
Key Takeaways
- Education is a root cause of persistent SQLi/XSS/path traversal classes, not merely tooling gaps.
- Top-down conference talks did not move institutions; bottom-up teacher and professor relationships did.
- Iterative content is acceptable: early YouTube videos were “bad,” then improved—modeling the same growth mindset pushed on students.
- Workshop design matters: traps + hacks create memorable correction loops; 11/12 failure rate shows typical developer defaults.
- Open materials plus paid custom workshops can sustainably fund public goods—if customers consent to release.
- Global scaling is explicitly desired: English content and subtitles in progress at talk time.
What remains unknown from the transcript: The talk references policy shifts and loss figures without citations on-slide; before repeating them in policy memos, verify against primary sources. Likewise, the OWASP Trust library’s guarantees depend on implementation details not shown here—“impossible” is a strong word that should be validated by reading the project’s threat model and tests.
How enterprises can partner without waiting for national curriculum reform: sponsor professors, donate graded lab content with explicit secure defaults, and require internal training to reference the same patterns new hires were taught. The speakers’ model—paid customer workshops that become public artifacts—is one sponsorship pattern; another is simply hiring educators as adjunct reviewers for internal training modules. The key is to stop treating education as someone else’s problem once engineers enter the workforce pipeline.
Condensing guidance for practitioners: The speakers describe OWASP Top 10-style material as oriented toward security professionals (“what not to do”) and other guideline corpora as too long for day-to-day coding. Their response is the VER acronym (details deferred to YouTube in the session). Even without the acronym expansion, the underlying product thesis is familiar: developers need short, memorable rules that attach to everyday coding tasks, not another hundred-page standard skimming read once a year.
About the Speaker(s)
Osar (spelling as transcribed) describes a decade in cybersecurity after many years as a developer, current pentesting and consulting work, and secure coding training in public and private sectors. Yariv Ta describes 40 years in development and teaching, transitioning to application security research about five years prior. Exact employer names (beyond project affiliations mentioned) and full legal name spellings are partially unclear from the transcript; Osar may be Oscar in conventional spelling—unknown with certainty.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Heartfelt education reform pitch with just enough technical sting (bad curricula, trap labs, safe path APIs). It will not teach a new exploit, but it challenges the community to stop pretending tooling alone fixes upstream learning debt.
Heather Calloway (CISO) — STRONG ACCEPT
This is workforce risk at the source: if your pipeline teaches concatenated SQL, your enterprise AppSec tax is permanent. The speakers translate a governance problem—who owns secure curricula—into grassroots action and open artifacts.