Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs

Dark Patterns RecognitionSoftware Engineers & DevelopersCybersecurity Engineers

The positive effect of security information communicated to developers through API warnings has been established. However, current prototypical designs are based on security warnings for end-users. To improve security feedback for developers, we conducted a participatory design study with 25 professional software developers in focus groups. We identify which security information is considered helpful in avoiding insecure cryptographic API use during development. Concerning console messages, participants suggested five core elements, namely message classification, title message, code location, link to detailed external resources, and color. Design guidelines for end-user warnings are only partially suitable in this context. Participants emphasized the importance of tailoring the detail and content of security information to the context. Console warnings call for concise communication; further information needs to be linked externally. Therefore, security feedback should transcend tools and should be adjustable by software developers across development tools, considering the work context and developer needs.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/32468/2020

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3313831.3376142
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2020
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Dark Patterns Recognition
work
Professions
Software Engineers & Developers, Cybersecurity Engineers
article
Content Status
Abstract only
hub
Related Papers
0 related papers