Why Insecure Government Software Is a National Security Problem
When Tanya Janca worked in the Canadian government, she learned the departmental website ranked as the number-one mission-critical asset. When it went down, citizens called 911. With over half of Canada’s 1.3 million tech workers writing software and no security training in universities, insecure government code is a national risk. Software runs tax collection, healthcare, and election infrastructure. Every unpatched vulnerability is a direct attack surface on public services.
Canada’s Guidance Is Vague and Voluntary
The Canadian Centre for Cyber Security’s best public guidance on software security covers four points. Use strong authentication, validate your input, protect sensitive data, and store credentials securely. Each is a sentence with no instructions. A “secure by design” section offers zero examples and zero explanation. A third-party component guide suggests an SBOM but doesn’t require analyzing whether components are safe. None of it is mandatory. There is no government-wide vulnerability disclosure program. Only Alberta, Canada Post, and one five-person team at CDS have anything resembling one.
42 Hidden Breaches and Three Years of Escalation
CBC’s investigative journalists found that the Canada Revenue Agency hid 42 material breaches. CRA holds every Canadian’s financial data. A material breach means significant organizational harm or citizen data compromised. Janca escalated for three years: letters to the prime minister’s office, national media interviews, multiple trips to Ottawa, blog posts on Risky Business. She cornered the CRA chief information officer at a conference after he skipped her talk. He said he’d follow up. He didn’t. CRA’s terms of service disclaim responsibility for user data because “the internet’s not safe.”
A Nine-Page Policy Built to Be Used
After three years of being ignored, Janca wrote the policy herself. Nine pages. Stack-agnostic and language-agnostic, it tells any developer exactly what to do. Based on her book “Alice and Bob Learn Secure Coding,” it’s free with no email signup. She paired it with a template letter for contacting elected officials and a Canadian petition. Collecting 500 signatures behind a parliamentary sponsor triggers a mandatory government hearing. British Columbia’s corrections CISO has already agreed to review adoption across the province.
What Security Professionals Can Do Right Now
Every security professional can do the same in their own country. Contact elected officials and ask whether a mandatory secure coding policy exists. If one does, read it. Janca’s policy works as a template for comparison. Push universities that offer software degrees but no secure coding course. Universities in Canada offer less than a Walmart greeter wage for adjunct professors, which explains the faculty shortage. Her free academy has 11 courses on secure coding, incident response, and building an AppSec program, all ungated.
Q&A
You’ve been at this for years. Are you more hopeful now? Janca said yes, pointing to growing supporter numbers, OWASP Canada chapters joining her campaign, and a House of Commons petition that forces a mandatory government hearing at 500 signatures. ▶ 26:59
Notable Quotes
is risk. It’s national risk. Tanya “SheHacksPurple” Janca · ▶ 3:38
held accountable to, it’s sort of yolo. Tanya “SheHacksPurple” Janca · ▶ 4:10
you should do secure by design with zero examples, Tanya “SheHacksPurple” Janca · ▶ 9:04
Nothing happened. Literally nothing. Tanya “SheHacksPurple” Janca · ▶ 17:05
Key Takeaways
- Canada has no mandatory secure coding policy and no government-wide vulnerability disclosure program.
- CRA hid 42 material breaches; its terms of service disclaim responsibility for user data.
- A free nine-page stack-agnostic secure coding policy, petition, and letter template are available for any citizen to use.
About the Speaker
Tanya “SheHacksPurple” Janca is the bestselling author of “Alice and Bob Learn Secure Coding” and “Alice and Bob Learn Application Security,” with 28 years in IT including 13.5 years inside the Canadian government. She has received the OWASP Lifetime Distinguished Member award and the Hacker of the Year award, led security for the 52nd Canadian general election, and performed counter-terrorism work. She currently works at Semgrep as a Security Advocate and makes her full secure coding academy available free online.