Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects
Dominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné, Yasemin Acar, Sascha Fahl
Abstract
Open Source Software plays an important role in many software ecosystems. Whether in operating systems, network stacks, or as low-level system drivers, software we encounter daily is permeated with code contributions from open source projects. Decentralized development and open collaboration in open source projects introduce unique challenges: code submissions from unknown entities, limited personpower for commit or dependency reviews, and bringing new contributors up-to-date in projects’ best practices & processes.In 27 in-depth, semi-structured interviews with owners, maintainers, and contributors from a diverse set of open source projects, we investigate their security and trust practices. For this, we explore projects’ behind-the-scene processes, provided guidance & policies, as well as incident handling & encountered challenges. We find that our participants’ projects are highly diverse both in deployed security measures and trust processes, as well as their underlying motivations. Based on our findings, we discuss implications for the open source software ecosystem and how the research community can better support open source projects in trust and security considerations. Overall, we argue for supporting open source projects in ways that consider their individual strengths and limitations, especially in the case of smaller projects with low contributor numbers and limited access to resources.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers23
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- Understanding Parents' Perceptions and Practices Toward Children's Security and Privacy in Virtual RealityJiaxun Cao, Abhinaya S. B., Anupam Das, Pardis Emami NaeiniS&P 2024 · 19 citations
- "There are rabbit holes I want to go down that I'm not allowed to go down": An Investigation of Security Expert Threat Modeling Practices for Medical DevicesRonald E. Thompson III, Madeline McLaughlin, Carson Powers, Daniel VotipkaUSENIX Security 2024 · 15 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- Unhelpful Assumptions in Software Security ResearchIta Ryan, Utz Roedig, Klaas-Jan StolCCS 2023 · 9 citations
Builds on8
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- "Did You Miss My Comment or What?" Understanding Toxicity in Open Source DiscussionsCourtney Miller, Sophie Cohen, Daniel Klug, Bogdan Vasilescu et al.ICSE 2022 · 54 citations
- When the Weakest Link is Strong: Secure Collaboration in the Case of the Panama PapersSusan E. McGregor, Elizabeth Anne Watkins, Mahdi Nasrullah Al-Ameen, Kelly Caine et al.USENIX Security 2017 · 52 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Code of Conduct Conversations in Open Source Software Projects on GithubRenee Li, Pavitthra Pandurangan, Hana Frluckaj, Laura DabbishCSCW 2021 · 49 citations
Related papers
- "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply ChainDominik Wermke, Jan H. Klemmer, Noah Wöhler, Juliane Schmüser et al.S&P 2023
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- Mining Pull Requests to Detect Process Anomalies in Open Source Software DevelopmentBohan Liu, He Zhang, Weigang Ma, Hongyu Kuang et al.ICSE 2024 · 2 citations
- The Long Road Ahead: Ongoing Challenges in Contributing to Large OSS Organizations and What to DoMariam Guizani, Amreeta Chatterjee, Bianca Trinkenreich, Mary Evelyn May et al.CSCW 2021 · 42 citations
