On Conducting Security Developer Studies with CS Students: Examining a Password-Storage Study with CS Students, Freelancers, and Company Developers

Passwords & AuthenticationUser Research Methods (Interviews, Surveys, Observation)Software Engineers & DevelopersUI/UX DesignersHCI Researchers

Ecological validity is a major concern in usable security studies with developers. Many studies are conducted with computer science (CS) students out of convenience, since recruiting professional software developers in sufficient numbers is very challenging. In a password-storage study, Naiakshina et al. (CHI'19) showed that CS students behave similarly to freelance developers recruited online. While this is a promising result for conducting developer studies with students, an open question remains: Do professional developers employed in companies behave similarly as well? To provide more insight into the ecological validity of recruiting students for security developer studies, we replicated the study of Naiakshina et al. with developers from diverse companies in Germany. We found that developers employed in companies performed better than students and freelancers in a direct comparison. However, treatment effects were found to be significant in all groups; the treatment effects on CS students also held for company developers.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/31863/2020

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3313831.3376791
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2020
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Passwords & Authentication, User Research Methods (Interviews, Surveys, Observation)
work
Professions
Software Engineers & Developers, UI/UX Designers, HCI Researchers
article
Content Status
Abstract only
hub
Related Papers
2 related papers