Security During Application Development: an Application Security Expert Perspective
Authors
Many of the security problems that people face today, such as security breaches and data theft, are caused by security vulnerabilities in application source code. Thus, there is a need to understand and improve the experiences of those who can prevent such vulnerabilities in the first place - software developers as well as application security experts. Several studies have examined developers' perceptions and behaviors regarding security vulnerabilities, demonstrating the challenges they face in performing secure programming and utilizing tools for vulnerability detection. We expand upon this work by focusing on those primarily responsible for application security - security auditors. In an interview study of 32 application security experts, we examine their views on application security processes, their workflows, and their interactions with developers in order to further inform the design of tools and processes to improve application security.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 83%
"Pretty Close to a Must-Have:" Balancing Usability Desire and Security Concern in Biometric Adoption
CHI '19· Privacy by Design & User Control +2
- 83%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 80%
Leveraging Semantic Transformation to Investigate Password Habits and Their Causes
CHI '18· Privacy by Design & User Control +1
- 80%
Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking
CHI '19· Privacy by Design & User Control +1
- 80%
I Don't Even Have to Bother Them!: Using Social Media to Automate the Authentication Ceremony in Secure Messaging
CHI '19· Privacy by Design & User Control +1
- 71%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 67%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 67%
'Think secure from the beginning': A Survey with Software Developers
CHI '19· Privacy by Design & User Control +2
- 67%
I Was Told to Install the Antivirus App, but I'm Not Sure I Need It: Understanding Smartphone Antivirus Software Adoption and User Perceptions
CHI '25· Privacy by Design & User Control +1
- 67%
The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
CHI '25· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)