"We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups
Dilara Keküllüoglu, Yasemin Acar
Abstract
Security and privacy are often neglected in software development, and rarely a priority for developers. This insight is commonly based on research conducted by researchers and on developer populations living and working in the United States, Europe, and the United Kingdom. However, the production of software is global, and crucial populations in important technology hubs are not adequately studied. The software startup scene in Turkey is impactful, and comprehension, knowledge, and mitigations related to software security and privacy remain understudied. To close this research gap, we conducted a semi-structured interview study with 16 developers working in Turkish software startups. The goal of the interview study was to analyze if and how developers ensure that their software is secure and preserves user privacy. Our main finding is that developers rarely prioritize security and privacy, due to a lack of awareness, skills, and resources. We find that regulations can make a positive impact on security and privacy. Based on the study, we issue recommendations for industry, individual developers, research, educators, and regulators. Our recommendations can inform a more globalized approach to security and privacy in software development.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8cf2e7cc-bda1-4f57-bc06-d46372065e9aCited by top-tier papers6
- SoK: Technical Implementation and Human Impact of Internet Privacy RegulationsEleanor Birrell, Jay Rodolitz, Angel Ding, Jenna Lee et al.S&P 2024 · 11 citations
- Mithridates: Auditing and Boosting Backdoor Resistance of Machine Learning PipelinesEugene Bagdasarian, Vitaly ShmatikovCCS 2024 · 3 citations
- PrivacyAkinator: Articulating Key Privacy Design Decisions by Answering LLM-Generated Multiple-choice QuestionsQiyu Li, Yuen Sum Wong, Yuen Kei Wong, Longxuan Yu et al.CHI 2026 · 1 citation
- Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-Based Healthcare ConsultationZhihuang Liu, Ling Hu, Tongqing Zhou, Yonghao Tang et al.S&P 2025
- "Sorry for Bugging you so much." Exploring Developers' Behavior Towards Privacy-Compliant ImplementationStefan Albert Horstmann, Sandy Hong, David Klein, Raphael Serafini et al.S&P 2025
Builds on3
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
Related papers
- Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game DevelopmentPhilip Klostermeyer, Sabrina Amft, Sandra Höltervennhoff, Alexander Krause et al.CCS 2024 · 4 citations
- Security and Privacy Software Creators' Perspectives on Unintended ConsequencesHarshini Sri Ramulu, Helen Schmitt, Dominik Wermke, Yasemin AcarUSENIX Security 2024 · 4 citations
- “I need to learn better searching tactics for privacy policy laws.” Investigating Software Developers’ Behavior When Using Sources on Privacy IssuesStefan Albert Horstmann, Sandy Hong, Maziar Niazian, Cristiana Santos et al.ICSE 2026 · 1 citation
- "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic CodeAlexander Krause, Harjot Kaur, Jan H. Klemmer, Oliver Wiese et al.USENIX Security 2025
- A Mixed-Methods Study of Security Practices of Smart Contract DevelopersTanusree Sharma, Kyrie Zhixuan Zhou, Andrew Miller, Yang WangUSENIX Security 2023
