Proceedings 2nd European Workshop on Usable Security 2017
DOI: 10.14722/eurousec.2017.23015
|View full text |Cite
|
Sign up to set email alerts
|

I Do and I Understand. Not Yet True for Security APIs. So Sad

Abstract: Usable security puts the users into the center of cyber security developments. Software developers are a very specific user group in this respect, since their points of contact with security are application programming interfaces (APIs). In contrast to APIs providing functionalities of other domains than security, security APIs are not approachable by habitual means. Learning by doing exploration exercises is not well supported. Reasons for this range from missing documentation, tutorials and examples to lacki… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
10
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
4
3
2

Relationship

1
8

Authors

Journals

citations
Cited by 23 publications
(10 citation statements)
references
References 19 publications
(25 reference statements)
0
10
0
Order By: Relevance
“…SecAPIs broadly fall into two categories, security primitives which required security knowledge to understand and security controls which were found to be a more appropriate abstraction level for developers. Unlike other APIs, SecAPIs do not well support learning-by-doing [70].…”
Section: F Application Programming Interfaces (Apis)mentioning
confidence: 99%
“…SecAPIs broadly fall into two categories, security primitives which required security knowledge to understand and security controls which were found to be a more appropriate abstraction level for developers. Unlike other APIs, SecAPIs do not well support learning-by-doing [70].…”
Section: F Application Programming Interfaces (Apis)mentioning
confidence: 99%
“…Although their focus is on cryptographic APIs, most of their suggested principles apply equally well to other security APIs. Lo Iacono and Gorski (2017) in [28] note that most of the research investigating the APIs' usability of security is related to cryptography. They point out that security APIs include more than cryptographic APIs.…”
Section: Related Workmentioning
confidence: 99%
“…The participants were not primed to expect security tasks, but before accepting them, we made sure that they knew what TLS certificates were. We decided not to limit our sample to security professionals, as it turns out that the majority of developers work with security features from time to time [30]. The whole experiment took about 30 to 40 minutes per participant (pre-task questionnaire, task, post-task interview).…”
Section: Pilot Testing Recruitment and Study Setupmentioning
confidence: 99%