CRSep 29, 2021

Worrisome Patterns in Developers: A Survey in Cryptography

arXiv:2109.14363v29 citationsHas Code
Originality Synthesis-oriented
AI Analysis

This identifies security risks in developer practices for cryptography, which is incremental as it builds on existing surveys but highlights specific gaps.

The study surveyed 97 developers using cryptography in open-source projects to assess security practices, finding that high-knowledge developers had more experience and used more security tools, but all groups showed concerning patterns like reliance on unreliable sources and low security tool usage.

We surveyed 97 developers who had used cryptography in open-source projects, in the hope of identifying developer security and cryptography practices. We asked them about individual and company-level practices, and divided respondents into three groups (i.e., high, medium, and low) based on their level of knowledge. We found differences between the high-profile developers and the other two groups. For instance, high-profile developers have more years of experience in programming, have attended more security and cryptography courses, have more background in security, are highly concerned about security, and tend to use security tools more than the other two groups. Nevertheless, we observed worrisome patterns among all participants such as the high usage of unreliable sources like Stack Overflow, and the low rate of security tool usage.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes