"I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIs
Juliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha Fahl
Abstract
Cryptographic libraries are a vital security component of software systems, yet their misuse has caused several incidents. Prior work has established that misuse of cryptographic libraries is common, and developers struggle to use their APIs correctly. However, it is currently unknown how the design and implementation decisions that shape cryptographic library APIs are made. To investigate these decisions and associated challenges in the design and implementation process of cryptographic library APIs, we conducted 21 semi-structured interviews with experienced developers of cryptographic libraries and used thematic analysis to identify overarching topics and challenges they encountered. We find that design decisions span a spectrum of abstraction levels and are heavily influenced by cryptographic standards, other libraries, legacy code, and developers' intuitions. Developers are challenged by the optimal level of abstraction for cryptographic APIs to balance security, usability, and flexibility. They lack systematic knowledge on defining usability and achieving such balance. Consequently, developers rely on usability self-tests, personal experiences, and opinions. Based on our findings, we make detailed recommendations to tailor future research toward better empirically validated support of cryptographic library API design and implementation decisions. Further, we advocate for integrating research-based usability guidance into cryptographic standardization to foster community discussion early on and better support secure, usable, and flexible cryptographic library APIs. identify challenges in the design and decision processes by capturing the developers' perspectives. RQ3. "How can cryptographic library designers and implementers be better supported to improve library security and usability?" Cryptographic libraries face unique security and usability challenges for developers, often complicating their use. We seek to identify opportunities to better support cryptographic library designers and implementers with creating secure, usable APIs to improve overall software security. In this paper, we make the following contributions: Insights from Experienced Cryptographic API Developers. We report insights from 21 semi-structured interviews with experienced developers of cryptographic library APIs, including their opinions on API design and strategies for decision processes. We find that levels of abstraction varied across libraries, and decisions were influenced by standards, other libraries, legacy code, and developers' intuitions. Key Challenges of Cryptographic API Design. We identify critical challenges in the design of cryptographic library APIs, such as limited resources for usability engineering, difficulty determining usability, balancing usability, security, and flexibility, and a lack of specific, empirically validated guidance in research and standards. Recommendations for Usability Research and API Design Guidance in Cryptographic Standards. Based on our findings, we identify open research questions and give detailed recommendations for future work on usable cryptographic APIs. We argue that cryptographic standardization should include API design and usability considerations for multiple levels of misuse resistance and flexibility to help cryptographic library developers make informed decisions. * multiple answers allowed † open-ended answers TABLE 2. PARTICIPANTS' PRIMARY PROJECTS AND ROLES.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3847b9f2-5566-49e6-b66b-6711905ab431Cited by top-tier papers3
- Competing for Attention: An Interview Study with Participants of Cryptography CompetitionsIvana Trummová, Juliane Schmüser, Nicolas Huaman, Sascha FahlCCS 2025
- What Users Ask, Policies Miss: Unveiling the Gap Between Community-Expressed Privacy Concerns and LLM Provider PoliciesZhihuang Liu, Zhen Huang, Ling Hu, Yifan Yang et al.USENIX Security 2026
- "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic CodeAlexander Krause, Harjot Kaur, Jan H. Klemmer, Oliver Wiese et al.USENIX Security 2025
Builds on11
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog et al.CCS 2017 · 146 citations
- "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesHana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou et al.CHI 2020 · 113 citations
- Selecting third-party libraries: the practitioners' perspectiveEnrique Larios Vargas, Maurício Finavaro Aniche, Christoph Treude, Magiel Bruntink et al.FSE 2020 · 81 citations
- "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices OnlineAllison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub et al.USENIX Security 2021 · 75 citations
Related papers
- "You have to read 50 different RFCs that contradict each other": An Interview Study on the Experiences of Implementing Cryptographic StandardsNicolas Huaman, Jacques Suray, Jan H. Klemmer, Marcel Fourné et al.USENIX Security 2024 · 5 citations
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt et al.USENIX Security 2024 · 15 citations
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 39 citations
- The Challenges of Bringing Cryptography from Research Papers to Products: Results from an Interview Study with ExpertsKonstantin Fischer, Ivana Trummová, Phillip Gajland, Yasemin Acar et al.USENIX Security 2024 · 9 citations
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le et al.NDSS 2024
