Fix the Flag: Rethinking Secure Code Training with Pedram Hayati episode artwork

EPISODE · Sep 11, 2025 · 39 MIN

Fix the Flag: Rethinking Secure Code Training with Pedram Hayati

from Day One®

Episode SummaryCTFs are fun, but do they actually make developers write more secure code? In this episode of Secured, Cole Cornford is joined by Pedram Hayati (Founder of SecDim & SecTalks) to explore why most developer security training fails, and how SecDim’s “Fix the Flag” approach is changing the game.From contrived WebGoat-style examples to frameworks that quietly eradicate entire bug classes, Cole and Pedram dive deep into the intersection of AppSec and software engineering. They unpack why developer experience is non-negotiable, why security needs to borrow design patterns from engineering, and how real-world incidents (like GitHub’s mass assignment bug or the Optus breach) make concepts stick far better than acronyms like “XSS” or “SSTI.”This is a technical, opinionated episode for anyone who’s ever struggled to get developers engaged with security.Timestamps01:10 – Why Pedram built SecDim, the problem with pen test reports, and why CTFs don’t train developers04:42 – From “Capture the Flag” to “Fix the Flag”: making training realistic and Git-first06:30 – Training inside developer workflows and why contrived examples fail10:28 – Using modern stacks, AI-tailored labs, and real-world incidents to make concepts stick12:35 – Why security names suck (XSS vs. “content injection”) and the Optus hack as a teaching moment17:37 – Secure design patterns vs. vague slogans, and why secure defaults beat secure by design21:15 – Frameworks like React, Rails, and Angular that kill entire bug classes23:23 – Engineering by-products: reproducibility, immutability, and orthogonality in secure coding30:36 – PHP’s bad reputation, language quirks, and what’s actually most popular in security training today33:41 – Why AppSec pros need to build and deploy apps (not just know vulnerability classes)37:44 – Getting started with SecDim and hands-on secure codingMentioned in this episode:Call for FeedbackThis podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrpSpotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/

Episode metadata supplied by the publisher feed · Published Sep 11, 2025

Embed this episode

Ready to play

Fix the Flag: Rethinking Secure Code Training with Pedram Hayati

0:00 39:20

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Day One®?

This episode is 39 minutes long.

When was this Day One® episode published?

This episode was published on September 11, 2025.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Day One® episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!