Skipping the Security Side Quests: A Qualitative Study on Security Practices and Challenges in Game Development
Philip Klostermeyer, Sabrina Amft, Sandra Höltervennhoff, Alexander Krause, Niklas Busch, Sascha Fahl
Abstract
The video game market is one of the biggest for software products. Video game development has progressed in the last decades to complex and multifaceted endeavors. Games-as-a-Service significantly impacted distribution and gameplay, requiring providers and developers to consider factors beyond game functionality, including security and privacy. New security challenges emerged, including authentication, payment security, and user data or asset protection. However, the security community lacks in-depth insights into the security experiences, challenges, and practices of modern video game development. This paper aims to address this gap in research and highlights the criticality of considering security in the process.
Therefore, we conducted 20 qualitative, semi-structured interviews with various roles of professional and skilled video game development experts, investigating awareness, priorities, knowledge, and practices regarding security in the industry through their first-hand experiences. We find that stakeholders are aware of the urgency of security and related issues. However, they often face obstacles, including a lack of money, time, and knowledge, which force them to put security issues lower in priority. We conclude our work by recommending how the game industry can incorporate security into its development processes while balancing other resources and priorities and illustrating ideas for future research.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b0c13ef0-abeb-4da2-a073-363504005065Cited by top-tier papers3
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- SoK: Another Arms Race -- 20 Years of (Anti-)Cheating in Video GamesPhilip Klostermeyer, Jan-Ulrich Holtgrave, Jacques Suray, Anne Vonderheide et al.USENIX Security 2026
- "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic CodeAlexander Krause, Harjot Kaur, Jan H. Klemmer, Oliver Wiese et al.USENIX Security 2025
Builds on8
- LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and BenchmarksSaad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce et al.S&P 2024 · 167 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- "In Eighty Percent of the Cases, I Select the Password for Them": Security and Privacy Challenges, Advice, and Opportunities at Cybercafes in KenyaCollins W. Munyendo, Yasemin Acar, Adam J. AvivS&P 2023
Related papers
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
- Women Security Experts Are Not The Enemy: A Qualitative Study on Gender-Related Communication ChallengesAsli Yardim, Stefan Albert Horstmann, Raphael Serafini, Joshua Gabriel Speckels et al.CHI 2025 · 3 citations
- "We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startupsDilara Keküllüoglu, Yasemin AcarS&P 2023
- "False negative - that one is going to kill you": Understanding Industry Perspectives of Static Analysis based Security TestingAmit Seal Ami, Kevin Moran, Denys Poshyvanyk, Adwait NadkarniS&P 2024 · 40 citations
- Relationship Status: "It's Complicated" Developer-Security Expert Dynamics in ScrumHouda Naji, Marco Gutfleisch, Alena NaiakshinaICSE 2025 · 2 citations
