'Think secure from the beginning': A Survey with Software Developers
Best PaperVulnerabilities persist despite existing software security initiatives and best practices. This paper focuses on the human factors of software security, including human behaviour and motivation. We conducted an online survey to explore the interplay between developers and software security processes, e.g., we looked into how developers influence and are influenced by these processes. Our data included responses from 123 software developers currently employed in North America who work on various types of software applications. Whereas developers are often held responsible for security vulnerabilities, our analysis shows that the real issues frequently stem from a lack of organizational or process support to handle security throughout development tasks. Our participants are self-motivated towards software security, and the majority did not dismiss it but identified obstacles to achieving secure code. Our work highlights the need to look beyond the individual, and take a holistic approach to investigate organizational issues influencing software security.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 83%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 80%
Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking
CHI '19· Privacy by Design & User Control +1
- 80%
On the Usability of HTTPS Deployment
CHI '19· Privacy by Design & User Control +1
- 80%
No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
CHI '25· Privacy by Design & User Control +1
- 71%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 67%
Security During Application Development: an Application Security Expert Perspective
CHI '18· Privacy by Design & User Control +1
- 67%
A Promise Is A Promise: The Effect of Commitment Devices on Computer Security Intentions
CHI '19· Privacy by Design & User Control +2
- 67%
Understanding Privacy-Related Questions on Stack Overflow
CHI '20· Privacy by Design & User Control +1
- 67%
The TaPSI Research Framework - A Systematization of Knowledge on Tangible Privacy and Security Interfaces
CHI '25· Privacy by Design & User Control +2
- 60%
Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection Practices
CHI '20· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)