"Do this! Do that!, And nothing will happen" Do specifications lead to securely stored passwords?
Joseph Hallett, Nikhil Patnaik, Benjamin Shreeve, Awais Rashid
摘要
Does the act of writing a specification (how the code should behave) for a piece of security sensitive code lead to developers producing more secure code? We asked 138 developers to write a snippet of code to store a password: Half of them were asked to write down a specification of how the code should behave before writing the program, the other half were asked to write the code but without being prompted to write a specification first. We find that explicitly prompting developers to write a specification has a small positive effect on the security of password storage approaches implemented. However, developers often fail to store passwords securely, despite claiming to be confident and knowledgeable in their approaches, and despite considering an appropriate range of threats. We find a need for developer-centered usable mechanisms for telling developers how to store passwords: lists of what they must do are not working.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar 等S&P 2022 · 被引用 51 次
- Recruiting Participants With Programming Skills: A Comparison of Four Crowdsourcing Platforms and a CS Student Mailing ListMohammad Tahaei, Kami VanieaCHI 2022 · 被引用 45 次
- Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative SurveyRaphael Serafini, Stefan Albert Horstmann, Alena NaiakshinaUSENIX Security 2024 · 被引用 7 次
它引用的顶会 Paper6
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog 等CCS 2017 · 被引用 146 次
- On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company DevelopersAlena Naiakshina, Anastasia Danilova, Eva Gerlitz, Matthew SmithCHI 2020 · 被引用 48 次
- Schrödinger's security: opening the box on app developers' security rationaleDirk van der Linden, Pauline Anthonysamy, Bashar Nuseibeh, Thein Than Tun 等ICSE 2020 · 被引用 38 次
- From Needs to Actions to Secure Apps? The Effect of Requirements and Developer Practices on App SecurityCharles Weir, Ben Hermann, Sascha FahlUSENIX Security 2020
相关 Paper
- "The AI tool can't make it any worse." Investigating Developers' Security Behavior with AI Assistants in a Password Storage StudyAsli Yardim, Raphael Serafini, Nadine Jost, Anna-Marie Ortloff 等CHI 2026 · 被引用 1 次
- Exploring the Impact of Intervention Methods on Developers' Security Behavior in a Manipulated ChatGPT StudyRaphael Serafini, Asli Yardim, Alena NaiakshinaCHI 2025 · 被引用 5 次
- Less is More: Supporting Developers in Vulnerability Detection during Code ReviewLarissa Braz, Christian Aeberhard, Gül Çalikli, Alberto BacchelliICSE 2022 · 被引用 26 次
- Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsPeter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha FahlCHI 2020 · 被引用 39 次
- Understanding the How and the Why: Exploring Secure Development Practices through a Course CompetitionKelsey R. Fulton, Daniel Votipka, Desiree Abrokwa, Michelle L. Mazurek 等CCS 2022 · 被引用 7 次
