• English
  • Deutsch
  • Log In
    Password Login
    or
  • Research Outputs
  • Projects
  • Researchers
  • Institutes
  • Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Code reviewing as methodology for online security studies with developers - A case study with freelancers on password storage
 
  • Details
  • Full
Options
2021
Conference Paper
Titel

Code reviewing as methodology for online security studies with developers - A case study with freelancers on password storage

Abstract
While ample experience with end-user studies exists, only little is known about studies with software developers in a security context. In past research investigating the security behavior of software developers, participants often had to complete programming tasks. However, programming tasks require a large amount of participants' time and effort, which often results in high costs and small sample sizes. We therefore tested a new methodology for security developer studies. In an online study, we asked freelance developers to write code reviews for password-storage code snippets. Since developers often tend to focus on functionality first and security later, similar to end users, we prompted half the participants for security. Although the freelancers indicated that they feel responsible for security, our results showed that they did not focus on security in their code reviews, even in a security-critical task such as password-storage. Almost half the participants wante d to release the insecure code snippets. However, we found that security prompting had a significant effect on the security awareness. To provide further insight into this line of work, we compared our results with similar password-storage studies containing programming tasks, and discussed code reviewing as a new methodology for future security research with developers.
Author(s)
Danilova, A.
Naiakshina, A.
Rasgauski, A.
Smith, M.
Hauptwerk
17th Symposium on Usable Privacy and Security, SOUPS 2021. Proceedings
Konferenz
Symposium on Usable Privacy and Security (SOUPS) 2021
Thumbnail Image
Externer Link
Externer Link
Language
English
google-scholar
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Send Feedback
© 2022