Alice and Bob Learn Application Security cover
Pages
288
Year
2020
Level
beginner
Read time
8h
Tanya Janca · Wiley · 2020
Reviewed by Ashish Sheth · Updated August 2026

Alice and Bob Learn Application Security

4.7 / 5
AMAZON · 225 RATINGS
security
SUBJECTS
Check Price on Amazon →
What you'll come away with
01.
A mental model for security that spans the full software lifecycle
02.
How to bake security into design instead of bolting it on at the end
03.
The practices that turn secure coding into a team habit, not a heroic act
04.
How to talk to security teams and read their findings without fear
05.
A starting map for a DevSecOps or application-security career
Strengths
+Friendly, encouraging tone that lowers the barrier to a hard topic
+Covers the whole lifecycle, not just a list of vulnerabilities
+Practical checklists and exercises at the end of each chapter
+Strong on the people and process side of security, not only the code
Caveats
Breadth over depth; each topic is an introduction rather than a deep dive
Language-agnostic, so few copy-paste code examples for your stack
Experienced security engineers may find the early chapters too basic
★ 4.7 FROM 225 READERS ON AMAZON
Check Price on Amazon →
Read this if
Developers who want a structured, lifecycle-wide view of AppSec
Engineers stepping into a security champion or DevSecOps role
Teams that want a shared vocabulary for secure development
Skip this if
Seasoned security professionals looking for advanced technique
Readers who only want hands-on exploitation practice
Anyone needing deep, stack-specific secure-coding recipes
Head-to-head comparisons
Alice and Bob Learn Application Security vs Web Security for Developers Alice and Bob Learn Application Security vs Threat Modeling
MORE SOFTWARE SECURITY BOOKS
Frequently asked
Is Alice and Bob Learn Application Security good for beginners?
Yes, that is exactly who it is written for. Tanya Janca assumes little security background and builds up fundamentals, secure design, and coding practices in a warm, encouraging voice. About 130 Goodreads readers rate it around 4.3. Experienced security engineers may find the early chapters slow, but newcomers get a clear map.
How is this book different from Web Security for Developers?
Web Security for Developers focuses tightly on web attacks and their fixes. Alice and Bob Learn Application Security is broader, covering the whole software lifecycle, from secure design and threat modeling to testing, culture, and building a security program. Read the first for web specifics and this one for the wider AppSec picture.
Does the book teach a specific programming language?
No. Tanya Janca keeps the advice language-agnostic so it applies whether you write in Java, Python, JavaScript, or C#. That makes the principles portable across teams, but it also means you will find few ready-to-paste code snippets. Pair it with stack-specific guidance when you implement the practices in your own project.
Read this next
2 alternatives
Web Security for Developers cover
Malcolm McDonald
Web Security for Developers
★ 4.6 · 108 RATINGS
Threat Modeling cover
Adam Shostack
Threat Modeling
★ 4.5 · 339 RATINGS
Ready?
Check Price on Amazon →