Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects

被引:0
|
作者
Wermke, Dominik [1 ]
Woehler, Noah [1 ]
Klemmer, Jan H. [2 ]
Fourne, Marcel [3 ]
Acar, Yasemin [4 ]
Fahl, Sascha [1 ]
机构
[1] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[2] Leibniz Univ Hannover, Hannover, Germany
[3] Max Planck Inst Secur & Privacy, Bochum, Germany
[4] George Washington Univ, Washington, DC 20052 USA
关键词
D O I
10.1109/SP46214.2022.00143
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Open Source Software plays an important role in many software ecosystems. Whether in operating systems, network stacks, or as low-level system drivers, software we encounter daily is permeated with code contributions from open source projects. Decentralized development and open collaboration in open source projects introduce unique challenges: code submissions from unknown entities, limited personpower for commit or dependency reviews, and bringing new contributors up-to-date in projects' best practices & processes. In 27 in-depth, semi-structured interviews with owners, maintainers, and contributors from a diverse set of open source projects, we investigate their security and trust practices. For this, we explore projects' behind-the-scene processes, provided guidance & policies, as well as incident handling & encountered challenges. We find that our participants' projects are highly diverse both in deployed security measures and trust processes, as well as their underlying motivations. Based on our findings, we discuss implications for the open source software ecosystem and how the research community can better support open source projects in trust and security considerations. Overall, we argue for supporting open source projects in ways that consider their individual strengths and limitations, especially in the case of smaller projects with low contributor numbers and limited access to resources.
引用
收藏
页码:1880 / 1896
页数:17
相关论文
共 50 条
  • [1] Just trust in Open Source software
    Owens, Martin
    [J]. NEW SCIENTIST, 2016, 229 (3058) : 53 - 53
  • [2] TRUST AND DISTRUST IN OPEN SOURCE SOFTWARE DEVELOPMENT
    Ho, Shuk Ying
    Richardson, Alex
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2013, 54 (01) : 84 - 93
  • [3] The Role of Software Trust in Selection of Open-Source and Closed Software
    Hou, Fang
    Jansen, Floris
    de Vries, Arthur
    Jansen, Slinger
    [J]. 2023 IEEE/ACM 11TH INTERNATIONAL WORKSHOP ON SOFTWARE ENGINEERING FOR SYSTEMS-OF-SYSTEMS AND SOFTWARE ECOSYSTEMS, SESOS, 2023, : 30 - 37
  • [4] Open Source and Trust
    Bellovin, Steven M.
    [J]. IEEE SECURITY & PRIVACY, 2022, 20 (02) : 108 - +
  • [5] The Use of Security Tactics in Open Source Software Projects
    Ryoo, Jungwoo
    Malone, Bryan
    Laplante, Phillip A.
    Anand, Priya
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2016, 65 (03) : 1195 - 1204
  • [6] Data on security requirements in open-source software projects
    Wang, Wentao
    Mahakala, Kavya Reddy
    Gupta, Arushi
    Hussein, Nesrin
    Wang, Yinglin
    [J]. DATA IN BRIEF, 2019, 25
  • [7] Decomposing and Measuring Trust in Open-Source Software Supply Chains
    Boughton, Lina
    Miller, Courtney
    Acar, Yasemin
    Wermke, Dominik
    Kastner, Christian
    [J]. 2024 IEEE/ACM 46TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: NEW IDEAS AND EMERGING RESULTS, ICSE-NIER 2024, 2024, : 57 - 61
  • [8] Role of reputation cues in trust formation for a developer's decision to join Open Source Software projects Completed Research
    Tsoy, Mikhail
    Staples, D. Sandy
    [J]. AMCIS 2018 PROCEEDINGS, 2018,
  • [9] Trust Perceptions of Metadata in Open-Source Software: The Role of Performance and Reputation
    Alarcon, Gene M.
    Gibson, Anthony M.
    Walter, Charles
    Gamble, Rose F.
    Ryan, Tyler J.
    Jessup, Sarah A.
    Boyd, Brian E.
    Capiola, August
    [J]. SYSTEMS, 2020, 8 (03): : 1 - 14
  • [10] On the security of open source software
    Payne, C
    [J]. INFORMATION SYSTEMS JOURNAL, 2002, 12 (01) : 61 - 78