Software Security for Developers • Laur Spilca & Thomas Vitale • GOTO 2026

Software Security for Developers • Laur Spilca & Thomas Vitale • GOTO 2026

🎙 GOTO Conferences 👥 1.1M 📅 March 5, 2026 ⏱ 29 min 👁 2K 📄 expert opinion 🧭 2026-08-02
Available in: English (current) Français

Keywords

securitycryptographyhashingencryptionPKI

Summary

In this GOTO Book Club interview, Thomas Vitale hosts Laurentiu Spilca to discuss his book ‘Software Security for Developers’, co-authored with Adib Saikali. Spilca explains the motivation behind the book: making security accessible to all developers by avoiding complex mathematics and focusing on practical knowledge. They address common confusions between encoding, hashing, and encryption, emphasizing that developers often misunderstand these concepts, leading to security vulnerabilities. The conversation highlights the danger of reinventing established security standards like OAuth 2 and JWT, advocating for the use of well-tested implementations. They also discuss the growing risk of AI-generated code, which may introduce security flaws if developers lack foundational security knowledge. The importance of understanding PKI and certificates is stressed, especially for protecting sensitive credentials. The book provides hands-on examples in Java and Spring but is applicable across languages. The interview concludes with information on book availability and resources.

145 words

Critical Evaluation

The interview provides a valuable overview of software security from a developer’s perspective, emphasizing practical knowledge over theoretical depth. The speakers, both experienced authors and practitioners, communicate clearly and effectively, making complex topics accessible. The discussion is well-structured, covering key areas such as cryptography fundamentals, common misconceptions, the importance of using established standards, and the emerging challenges posed by AI-generated code. The argumentation is solid, grounded in real-world experience and industry best practices. However, the content is largely conversational and lacks formal citations or references to specific research, which limits its academic rigor. The focus on Java and Spring might not fully represent the diversity of development environments, but the principles discussed are language-agnostic. The interview successfully fulfills its goal of demystifying security for developers and encouraging a proactive approach. The adéquation between title and content is strong, as the discussion directly addresses the book’s themes. Overall, the interview is informative and insightful, though it serves more as an introduction than a comprehensive guide.

164 words

Title / Content Match

The title accurately reflects the content: a discussion on software security for developers, covering key topics like cryptography, standards, and AI risks.

Quality & Reliability

8/10

The discussion is led by recognized experts (Java Champion, book authors) and focuses on established security standards and best practices. The content is consistent with industry knowledge, though it is an interview without formal citations or peer review.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top Ten — Aligns with the interview's emphasis on common security pitfalls and best practices.
  • RFC 7519 - JSON Web Token (JWT) — Provides the official specification for JWT, supporting the discussion on JWT misconceptions.

External References

Contribution & Novelties

The interview offers a clear, accessible introduction to software security for developers, emphasizing the importance of understanding foundational concepts like hashing, encryption, and PKI. It highlights the dangers of reinventing standards and the growing risks of AI-generated code. The discussion provides practical advice for developers to improve their security awareness.

Pour aller plus loin :

103 words

Radar Profile

The radar profile shows high scores in quality and reliability, reflecting the expertise of the speakers and the consistency of the information. The quantity of information is moderate, as the interview is relatively short, and the technical level is accessible, making it suitable for a broad developer audience.

Reliability 8/10