ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The missing ingredient in software security: grassroots education

security training for software developers
security training for software developers

David A. Wheeler at The Linux Foundation outlines what all software developers should know about open source software security

 

I was recently asked, “what’s the role of grassroots education in developing secure software and securing software supply chains?” My answer is “none, because we lack grass.”

 

“Grassroots education” implies ordinary practitioners teaching their peers, like grass spreading from its roots across an area once it has grown in one part of the area. Grassroots education can be effective when information is widely but not universally known.

 

There’s just one problem: we lack grass. Relatively few software developers know how to develop secure software, or how to secure their software supply chains. That’s because we don’t teach developers what they need to know.

 

A 2019 Forrester report titled “Show, Don’t Tell, Your Developers How to Write Secure Code” found that none of the top 40 US schools or top 5 non-US Computer Science schools required students to learn how to implement secure software (sometimes called “secure coding”).

 

In 2022, of U.S. News’ top 24 Computer Science schools, only one (University of California San Diego) requires security for undergraduates. Ponemon Institute’s Application Security in the DevOps Environment says 53% of developers’ organizations don’t require any training on securing coding (never mind secure software development more generally).

 

One study seemingly contradicts this but actually proves the point. The State of Developer-Driven Security Survey by Secure Code Warrior in 2022 said 89% of developers report they’ve received “sufficient training” in secure coding.

 

That’s misleading. The survey also shows most were unfamiliar with common software vulnerabilities, how to avoid them, and how they can be exploited. Nearly all said they needed more training on security frameworks, and over 80% said they are still knowingly shipping vulnerabilities in code and find it challenging to “practice secure coding” (their term).

 

This is not “sufficiently trained” at all! Developers have been taught so little that they now have unreasonably low expectations, surrounded by others who know equally little. The relatively rare knowledge of secure software development makes its spread slow.

 

Worse, knowledgeable developers leave the field, leaving behind less knowledgeable developers, resulting in ineffective peer education.

 

This is a problem. Our society depends on software – software that hostile actors now repeatedly attack. But since most software developers don’t know how to develop secure software, let alone protect supply chains, the result is an endless series of security problems.

 

What should software developers learn? Here are examples of what all software developers should know:

 

  1. Typical security requirements, what they mean, and how to identify them.
  2. Key secure design principles, such as least privilege, and how to apply them. Many secure design principles were identified by Saltzer and Schroeder in the 1970s, yet software developers are often still unaware of them.
  3. Methods for analysing designs for security (threat modeling / attack modeling)
  4. How to use acceptlists (and not denylists) to constrain untrusted inputs, as these techniques significantly constrain attacks.
  5. The most common kinds of vulnerabilities (at least those identified by the “CWE Top 25” and “OWASP top 10”), including exactly what they are, how to recognize them, and practical general techniques to broadly prevent each one.
  6. Hardening methods so bugs (which are inevitable) are less likely to become vulnerabilities or will tend to have a lower impact.
  7. Different kinds of tools to detect vulnerabilities, their pros and cons, how they can be used, and how to add tools to their continuous integration (CI) pipeline. These include static source code analysers, fuzzers, web application scanners, and software composition analysis (SCA) tools. Modern software is too complex to depend solely on manual approaches, but developers won’t apply tools if they don’t know what they are.
  8. Material specific to evaluating potential reusable components, including open source software (OSS). Today applications are on average 70-90% OSS components; wisely selecting OSS is key for modern software development.
  9. The importance of having an automated test suite and applying negative testing. Many developers, including those who apply Test Driven Development (TDD), only create tests to verify that functionality that should occur does occur. That’s a mistake. Most security requirements are negative requirements, specifying something that should not occur. An adequate automated test suite must test that some prohibited behaviour (e.g. allowing users to change data without authorisation) does not occur.
  10. How to properly handle secrets, including how to correctly apply cryptography, store secrets in general (as opposed to storing them in inappropriate places like source code repositories), store passwords (using iterated salted cryptographic hash algorithms like argon2id), and properly erase secrets.
  11. How to secure the supply chains going into them and going out of them.

 

Ignorance permeates the entire software industry. It’s not an open source software (OSS) problem, nor is it a closed source software problem. Indeed, many developers develop both.

 

That said, today’s applications are 70-90% OSS components once you look inside them, so all developers must know how to select and reuse OSS. OSS gives potential evaluators a lot more information, but using that information effectively requires knowing how. And while OSS has a potential security advantage, since anyone can review it, reviews don’t matter if the reviewers also can’t develop secure software.

 

We should expect software developers to know how to develop secure software, how to select secure reused components, and how to secure their supply chains (both inbound and outbound). Since this can’t happen just through grassroots efforts, we need our educational system – including colleges, universities, and software development bootcamps – to do their part in teaching software developers this as a mandatory part of their education.

 

The Linux Foundation, specifically its Open Source Security Foundation (OpenSSF), has been taking steps to improve education in developing secure software and securing software supply chains. It has developed some courses in developing secure software, and its Open Source Software Security Mobilization Plan discusses its intended steps to improve education.

 

Unfortunately, it’s going to take a while for these newer developers to pervade the field, so organizations will also need to get their software developers into courses that teach them how to do this. The OpenSSF’s Secure Software Development Fundamentals Courses are a good place to start, and they cost nothing.


As more and more developers do have the necessary knowledge, they can begin to help their peers who haven’t learned yet. At some point, we’ll finally have enough grass.

 


 

David A. Wheeler is Director of Open Source Supply Chain Security, The Linux Foundation

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543