"I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIs
Juliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha Fahl
摘要
Cryptographic libraries are a vital security component of software systems, yet their misuse has caused several incidents. Prior work has established that misuse of cryptographic libraries is common, and developers struggle to use their APIs correctly. However, it is currently unknown how the design and implementation decisions that shape cryptographic library APIs are made. To investigate these decisions and associated challenges in the design and implementation process of cryptographic library APIs, we conducted 21 semi-structured interviews with experienced developers of cryptographic libraries and used thematic analysis to identify overarching topics and challenges they encountered. We find that design decisions span a spectrum of abstraction levels and are heavily influenced by cryptographic standards, other libraries, legacy code, and developers' intuitions. Developers are challenged by the optimal level of abstraction for cryptographic APIs to balance security, usability, and flexibility. They lack systematic knowledge on defining usability and achieving such balance. Consequently, developers rely on usability self-tests, personal experiences, and opinions. Based on our findings, we make detailed recommendations to tailor future research toward better empirically validated support of cryptographic library API design and implementation decisions. Further, we advocate for integrating research-based usability guidance into cryptographic standardization to foster community discussion early on and better support secure, usable, and flexible cryptographic library APIs. identify challenges in the design and decision processes by capturing the developers' perspectives. RQ3. "How can cryptographic library designers and implementers be better supported to improve library security and usability?" Cryptographic libraries face unique security and usability challenges for developers, often complicating their use. We seek to identify opportunities to better support cryptographic library designers and implementers with creating secure, usable APIs to improve overall software security. In this paper, we make the following contributions: Insights from Experienced Cryptographic API Developers. We report insights from 21 semi-structured interviews with experienced developers of cryptographic library APIs, including their opinions on API design and strategies for decision processes. We find that levels of abstraction varied across libraries, and decisions were influenced by standards, other libraries, legacy code, and developers' intuitions. Key Challenges of Cryptographic API Design. We identify critical challenges in the design of cryptographic library APIs, such as limited resources for usability engineering, difficulty determining usability, balancing usability, security, and flexibility, and a lack of specific, empirically validated guidance in research and standards. Recommendations for Usability Research and API Design Guidance in Cryptographic Standards. Based on our findings, we identify open research questions and give detailed recommendations for future work on usable cryptographic APIs. We argue that cryptographic standardization should include API design and usability considerations for multiple levels of misuse resistance and flexibility to help cryptographic library developers make informed decisions. * multiple answers allowed † open-ended answers TABLE 2. PARTICIPANTS' PRIMARY PROJECTS AND ROLES.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Competing for Attention: An Interview Study with Participants of Cryptography CompetitionsIvana Trummová, Juliane Schmüser, Nicolas Huaman, Sascha FahlCCS 2025
- What Users Ask, Policies Miss: Unveiling the Gap Between Community-Expressed Privacy Concerns and LLM Provider PoliciesZhihuang Liu, Zhen Huang, Ling Hu, Yifan Yang 等USENIX Security 2026
- "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic CodeAlexander Krause, Harjot Kaur, Jan H. Klemmer, Oliver Wiese 等USENIX Security 2025
它引用的顶会 Paper11
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog 等CCS 2017 · 被引用 146 次
- "It's a scavenger hunt": Usability of Websites' Opt-Out and Data Deletion ChoicesHana Habib, Sarah Pearman, Jiamin Wang, Yixin Zou 等CHI 2020 · 被引用 113 次
- Selecting third-party libraries: the practitioners' perspectiveEnrique Larios Vargas, Maurício Finavaro Aniche, Christoph Treude, Magiel Bruntink 等FSE 2020 · 被引用 81 次
- "It's stressful having all these phones": Investigating Sex Workers' Safety Goals, Risks, and Practices OnlineAllison McDonald, Catherine Barwulor, Michelle L. Mazurek, Florian Schaub 等USENIX Security 2021 · 被引用 75 次
相关 Paper
- "You have to read 50 different RFCs that contradict each other": An Interview Study on the Experiences of Implementing Cryptographic StandardsNicolas Huaman, Jacques Suray, Jan H. Klemmer, Marcel Fourné 等USENIX Security 2024 · 被引用 5 次
- "These results must be false": A usability evaluation of constant-time analysis toolsMarcel Fourné, Daniel De Almeida Braga, Jan Jancar, Mohamed Sabt 等USENIX Security 2024 · 被引用 15 次
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 被引用 39 次
- The Challenges of Bringing Cryptography from Research Papers to Products: Results from an Interview Study with ExpertsKonstantin Fischer, Ivana Trummová, Phillip Gajland, Yasemin Acar 等USENIX Security 2024 · 被引用 9 次
- Towards Precise Reporting of Cryptographic MisusesYikang Chen, Yibo Liu, Ka Lok Wu, Duc Viet Le 等NDSS 2024
