Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative Survey

R Serafini, SA Horstmann, A Naiakshina - 33rd USENIX Security …, 2024 - usenix.org
Previous research demonstrated that company developers excel compared to freelancers
and computer science students, with the corporate environment significantly influencing …

“Those things are written by lawyers, and programmers are reading that.” Map** the Communication Gap Between Software Developers and Privacy Experts

SA Horstmann, S Domiks, M Gutfleisch… - Proceedings on …, 2024 - petsymposium.org
To ensure data-privacy compliance, it is common for companies to consult privacy experts
for the identification and communication of privacy requirements to software developers …

[HTML][HTML] Addressing combinatorial experiments and scarcity of subjects by provably orthogonal and crossover experimental designs

F Massacci, A Papotti, R Paramitha - Journal of Systems and Software, 2024 - Elsevier
Abstract Context: Experimentation in Software and Security Engineering is a common
research practice, in particular with human subjects. Problem: The combinatorial nature of …

Write, Read, or Fix? Exploring Alternative Methods for Secure Development Studies

KR Fulton, J Lewis, N Malkin, ML Mazurek - Twentieth Symposium on …, 2024 - usenix.org
When studying how software developers perform security tasks, researchers often ask
participants to write code. These studies can be challenging because programming can be …

Redesigning Privacy with User Feedback: The Case of Zoom Attendee Attention Tracking

TW Li, A Arya, H ** - Proceedings of the CHI Conference on Human …, 2024 - dl.acm.org
Software engineers' unawareness of user feedback in earlier stages of design contributes to
privacy issues in many products. Although extensive research exists on gathering and …

NERDS: A Non-invasive Environment for Remote Developer Studies

J Lewis, KR Fulton - Proceedings of the 17th Cyber Security …, 2024 - dl.acm.org
Given the difficulties of secure development, studying software developers remains pivotal.
However, conducting these studies remains a pain point for the security community as …

[PDF][PDF] Towards Bridging the Research-Practice Gap: Understanding Researcher-Practitioner Interactions and Challenges in Human-Centered Cybersecurity

J Haney, C Cunningham, S Furman - practice, 2024 - tsapps.nist.gov
Human-centered cybersecurity (HCC) researchers seek to improve people's experiences
with cybersecurity. However, a disconnect between researchers and practitioners, the …