How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview Study

被引:0
|
作者
Gutfleisch, Marco [1 ]
Klemmer, Jan H. [2 ]
Busch, Niklas [2 ]
Acar, Yasemin [3 ]
Sasse, M. Angela [1 ]
Fahl, Sascha [2 ,4 ]
机构
[1] Ruhr Univ Bochum, Bochum, Germany
[2] Leibniz Univ Hannover, Hannover, Germany
[3] Max Planck Inst Secur & Privacy, Bochum, Germany
[4] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
USABILITY; DEVELOPERS; NEED;
D O I
10.1109/SP46214.2022.00011
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
For software to be secure in practice, users need to be willing and able to appropriately use security features. These features are usually implemented by software professionals during the software development process (SDP), who may be unable to consider the usability of these mechanisms. While research has made progress in supporting developers in creating secure software products, very little attention has been paid to whether and how these security features are made usable. In a semi-structured interview study with 25 software professionals (software developers, designers, architects), we explored how they and other decision-makers encounter and deal with security and usability during the software development process in their companies. Based on 37 hours of interview recordings, we qualitatively analyzed and investigated 23 distinct development contexts in detail. In addition to individual awareness and factors that directly influence the implementation phase, we identify a high impact of contextual factors, such as stakeholder pressure, presence of expertise, and collaboration culture, and the specific implementation of the SDP on usable security in software products. We conclude our work by highlighting important gaps, such as studying and improving contextual factors that contribute to usable security and discussing potential improvements of the status quo.
引用
收藏
页码:893 / 910
页数:18
相关论文
共 50 条
  • [1] How Do Software Startups Approach Experimentation? Empirical Results from a Qualitative Interview Study
    Gutbrod, Matthias
    Munch, Juergen
    Tichy, Matthias
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT (PROFES 2017), 2017, 10611 : 297 - 304
  • [2] On the Recruitment of Company Developers for Security Studies: Results from a Qualitative Interview Study
    Serafini, Raphael
    Gutfleisch, Marco
    Horstmann, Stefan Albert
    Naiakshina, Alena
    PROCEEDINGS OF THE NINETEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, SOUPS 2023, 2023, : 321 - 340
  • [3] Breaking Up Is Hard to Do: A Qualitative Interview Study of How and Why Youth Mentoring Relationships End
    Spencer, Renee
    Basualdo-Delmonico, Antoinette
    Walsh, Jill
    Drew, Alison L.
    YOUTH & SOCIETY, 2017, 49 (04) : 438 - 460
  • [4] "We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups
    Kekulluoglu, Dilara
    Acar, Yasemin
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 2015 - 2031
  • [5] Reasons That Lead People to End Up Buying Fake Medicines on the Internet: Qualitative Interview Study
    Almomani, Hamzeh
    Patel, Nilesh
    Donyai, Parastou
    JMIR FORMATIVE RESEARCH, 2023, 7
  • [6] Core values of genomic citizen science: results from a qualitative interview study
    Christi J. Guerrini
    Meredith Trejo
    Isabel Canfield
    Amy L. McGuire
    BioSocieties, 2022, 17 : 203 - 228
  • [7] Core values of genomic citizen science: results from a qualitative interview study
    Guerrini, Christi J.
    Trejo, Meredith
    Canfield, Isabel
    McGuire, Amy L.
    BIOSOCIETIES, 2022, 17 (02) : 203 - 228
  • [8] Living with Pompe disease: results from a qualitative interview study with children and adolescents and their caregivers
    Truninger, Moritz Ilan
    Werner, Helene
    Landolt, Markus Andreas
    Hahn, Andreas
    Hennermann, Julia B.
    Lagler, Florian B.
    Moeslinger, Dorothea
    Pfrimmer, Charlotte
    Rohrbach, Marianne
    Huemer, Martina
    ORPHANET JOURNAL OF RARE DISEASES, 2024, 19 (01)
  • [9] Patients’ perception of types of errors in palliative care – results from a qualitative interview study
    Isabel Kiesewetter
    Christian Schulz
    Claudia Bausewein
    Rita Fountain
    Andrea Schmitz
    BMC Palliative Care, 15
  • [10] Challenges of general practitioner-oncologist interaction in end-of-life communication: results of a qualitative interview study
    Villalobos, M.
    Unsoeld, L.
    Thomas, M.
    Siegle, A.
    ONCOLOGY RESEARCH AND TREATMENT, 2023, 46 : 121 - 122