Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
Kelechi G. Kalu, Sofia Okorafor, Tanmay Singla, Sophie Chen, Santiago Torres-Arias, James C. Davis
摘要
Software signing is the most robust method for ensuring the integrity and authenticity of components in a software supply chain. Legacy key-managed signing tools (e.g., OpenPGP) burdened practitioners with key management and signer identification, creating both usability challenges and security risks. A new class of identity-based signing tools automate many of these concerns, but little is known about their usability and its effect on their adoption and effectiveness in practice. A usability evaluation can clarify the extent to which identity-based designs succeed and highlight priorities for improvement. To fill this gap, we conducted the first usability study of Sigstore, a pioneering and widely adopted exemplar of identitybased signing. Through interviews with 17 industry experts, we examined (1) the problems and advantages associated with practitioners' tooling choices, (2) how and why their signingtool usage has evolved over time, and (3) the contexts that cause usability concerns. Our findings illuminate the usability factors of identity-based signing tools and yield recommendations for toolmakers, adopting organizations, and the research community. Notably, components of identity-based tooling exhibit different levels of maturity and readiness for adoption, and integration flexibility is a common pain point but potentially mitigable through plugins and APIs. Our results will help identity-based signing toolmakers further strengthen software supply chain security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper9
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu 等ICSE 2023 · 被引用 82 次
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 被引用 35 次
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsTaylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko 等S&P 2024 · 被引用 17 次
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 被引用 14 次
相关 Paper
- An Industry Interview Study of Software Signing for Supply Chain SecurityKelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias 等USENIX Security 2025
- 27 Years and 81 Million Opportunities Later: Investigating the Use of Email Encryption for an Entire UniversityChristian Stransky, Oliver Wiese, Volker Roth, Yasemin Acar 等S&P 2022 · 被引用 27 次
- A Qualitative Analysis of Fuzzer Usability and ChallengesYunze Zhao, Wentao Guo, Harrison Goldstein, Daniel Votipka 等CCS 2025
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres 等CCS 2019 · 被引用 46 次
- They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesNicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar 等S&P 2021 · 被引用 37 次
