Pages
288
Year
2020
Level
beginner
Read time
8h
Tanya Janca · Wiley · 2020
Reviewed by Ashish Sheth · Updated August 2026
Alice and Bob Learn Application Security
4.7 / 5
AMAZON · 225 RATINGS
security
SUBJECTS
What you'll come away with
01.
A mental model for security that spans the full software lifecycle
02.
How to bake security into design instead of bolting it on at the end
03.
The practices that turn secure coding into a team habit, not a heroic act
04.
How to talk to security teams and read their findings without fear
05.
A starting map for a DevSecOps or application-security career
Strengths
+Friendly, encouraging tone that lowers the barrier to a hard topic
+Covers the whole lifecycle, not just a list of vulnerabilities
+Practical checklists and exercises at the end of each chapter
+Strong on the people and process side of security, not only the code
Caveats
−Breadth over depth; each topic is an introduction rather than a deep dive
−Language-agnostic, so few copy-paste code examples for your stack
−Experienced security engineers may find the early chapters too basic
★ 4.7 FROM 225 READERS ON AMAZON
Check Price on Amazon →
Read this if
→Developers who want a structured, lifecycle-wide view of AppSec
→Engineers stepping into a security champion or DevSecOps role
→Teams that want a shared vocabulary for secure development
Skip this if
—Seasoned security professionals looking for advanced technique
—Readers who only want hands-on exploitation practice
—Anyone needing deep, stack-specific secure-coding recipes
Head-to-head comparisons
Alice and Bob Learn Application Security vs Web Security for Developers → Alice and Bob Learn Application Security vs Threat Modeling → Frequently asked
Is Alice and Bob Learn Application Security good for beginners?
Yes, that is exactly who it is written for. Tanya Janca assumes little security background and builds up fundamentals, secure design, and coding practices in a warm, encouraging voice. About 130 Goodreads readers rate it around 4.3. Experienced security engineers may find the early chapters slow, but newcomers get a clear map.
How is this book different from Web Security for Developers?
Web Security for Developers focuses tightly on web attacks and their fixes. Alice and Bob Learn Application Security is broader, covering the whole software lifecycle, from secure design and threat modeling to testing, culture, and building a security program. Read the first for web specifics and this one for the wider AppSec picture.
Does the book teach a specific programming language?
No. Tanya Janca keeps the advice language-agnostic so it applies whether you write in Java, Python, JavaScript, or C#. That makes the principles portable across teams, but it also means you will find few ready-to-paste code snippets. Pair it with stack-specific guidance when you implement the practices in your own project.
Read this next
2 alternatives
Ready?
Check Price on Amazon →