USENIX Security2025Top-tier venue
An Industry Interview Study of Software Signing for Supply Chain Security
Kelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias, James C. Davis
Abstract
Many software products are composed of components integrated from other teams or external parties. Each additional link in a software product's supply chain increases the risk of the injection of malicious behavior. To improve supply chain provenance, many cybersecurity frameworks, standards, and regulations recommend the use of software signing. However, recent surveys and measurement studies have found that the adoption rate and quality of software signatures are low. We lack in-depth industry perspectives on the challenges and practices of software signing. To understand software signing in practice, we interviewed 18 experienced security practitioners across 13 organizations. We study the challenges that affect the effective implementation of software signing in practice. We also provide possible impacts of experienced software supply chain failures, security standards, and regulations on software signing adoption. To summarize our findings: (1) We present a refined model of the software supply chain factory model highlighting practitioner's signing practices; (2) We highlight the different challenges-technical, organizational, and human-that hamper software signing implementation; (3) We report that experts disagree on the importance of signing; and (4) We describe how internal and external events affect the adoption of software signing. Our work describes the considerations for adopting software signing as one aspect of the broader goal of improved software supply chain security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0582ad40-5b85-4375-8cbe-bc1334482907Cited by top-tier papers5
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines et al.ICSE 2026 · 5 citations
- Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of SigstoreKelechi G. Kalu, Sofia Okorafor, Tanmay Singla, Sophie Chen et al.USENIX Security 2026 · 3 citations
- A Multi-Month Study of Git Commit SigningAbubakar Sadiq Shittu, John Sadik, Scott RuotiCCS 2026
- Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at ScalePhilipp Beer, Sebastian Roth, Martina Lindorfer, Marco SquarcinaUSENIX Security 2026
- Toward Understanding the Security Implications in Python Configuration FilesXinwei Yu, Zhenkai Zhang, Yuzhe Tang, Xing GaoUSENIX Security 2026
Builds on15
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu et al.ICSE 2023 · 82 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
Related papers
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsTaylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko et al.S&P 2024 · 17 citations
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 35 citations
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the MoonIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2023 · 13 citations
- Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese IndustriesFumihiro Kanei, Ayako Akiyama Hasegawa, Eitaro Shioji, Mitsuaki AkiyamaCHI 2023 · 4 citations
