Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems 2020
DOI: 10.1145/3313831.3376142
|View full text |Cite
|
Sign up to set email alerts
|

Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
18
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 27 publications
(19 citation statements)
references
References 26 publications
1
18
0
Order By: Relevance
“…One possible explanation of the lack of impact from notifications is that notification elements like presentation, phrasing, organisation, and structure are not well aligned with developer needs. Prior work on the usability of developer-aimed security communications has similarly observed that participants do not find all the information presented in notifications equally useful [39,88]. The results are similar to our observations that participants did not find links to external resources and meta data such as rank and category as useful as sample code (Section 4.3).…”
Section: Discussion and Future Worksupporting
confidence: 87%
See 4 more Smart Citations
“…One possible explanation of the lack of impact from notifications is that notification elements like presentation, phrasing, organisation, and structure are not well aligned with developer needs. Prior work on the usability of developer-aimed security communications has similarly observed that participants do not find all the information presented in notifications equally useful [39,88]. The results are similar to our observations that participants did not find links to external resources and meta data such as rank and category as useful as sample code (Section 4.3).…”
Section: Discussion and Future Worksupporting
confidence: 87%
“…Gorski et al applied Bauer's guidelines to a cryptography API design that included multiple elements such as risk description, secure and insecure actions with examples, and background information. They found that having the API provide a warning with security advice improves code security without changing the perceived usability of the API [40]. In a follow-up participatory design study with developers, researchers highlighted five key elements (message classification, title message, code location, link to detailed external resources, and colour) that participants considered helpful in cryptography API warnings [39].…”
Section: Communicating With Developersmentioning
confidence: 99%
See 3 more Smart Citations