Hackers vs. Testers: A Comparison of Software Vulnerability Discovery Processes
Daniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu, Michelle L. Mazurek
Abstract
Identifying security vulnerabilities in software is a critical task that requires significant human effort. Currently, vulnerability discovery is often the responsibility of software testers before release and white-hat hackers (often within bug bounty programs) afterward. This arrangement can be ad-hoc and far from ideal; for example, if testers could identify more vulnerabilities, software would be more secure at release time. Thus far, however, the processes used by each group -and how they compare to and interact with each other -have not been well studied. This paper takes a first step toward better understanding, and eventually improving, this ecosystem: we report on a semi-structured interview study (n=25) with both testers and hackers, focusing on how each group finds vulnerabilities, how they develop their skills, and the challenges they face. The results suggest that hackers and testers follow similar processes, but get different results due largely to differing experiences and therefore different underlying knowledge of security concepts. Based on these results, we provide recommendations to support improved security training for testers, better communication between hackers and developers, and smarter bug bounty policies to motivate hacker participation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a1f11649-69d0-4b8e-9b6c-ddc24cf57513Cited by top-tier papers42
- LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and BenchmarksSaad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce et al.S&P 2024 · 167 citations
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu et al.USENIX Security 2018 · 138 citations
- Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and ChallengesMohammad Tahaei, Alisa Frik, Kami VanieaCHI 2021 · 75 citations
- An Inside Look into the Practice of Malware AnalysisMiuyin Yong Wong, Matthew Landen, Manos Antonakakis, Douglas M. Blough et al.CCS 2021 · 58 citations
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
Builds on7
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim et al.S&P 2016 · 325 citations
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog et al.CCS 2017 · 146 citations
- Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User StudyKhaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew SmithS&P 2016 · 128 citations
- A Stitch in Time: Supporting Android Developers in WritingSecure CodeDuc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes et al.CCS 2017 · 125 citations
Related papers
- Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty EcosystemYangheran Piao, Temima Hrle, Daniel W. Woods, Ross AndersonS&P 2025
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
- A Deep Dive into How Open-Source Project Maintainers Review and Resolve Bug Bounty ReportsJessy Ayala, Steven Ngo, Joshua GarciaS&P 2025
- Vulnerability Discovery for All: Experiences of Marginalization in Vulnerability DiscoveryKelsey R. Fulton, Samantha Katcher, Kevin Song, Marshini Chetty et al.S&P 2023
- "I'm trying to learn...and I'm shooting myself in the foot": Beginners' Struggles When Solving Binary Exploitation ExercisesJames Mattei, Christopher Pellegrini, Matthew Soto, Marina Sanusi Bohuk et al.USENIX Security 2025
