2016 IEEE Symposium on Security and Privacy (SP) 2016
DOI: 10.1109/sp.2016.25
|View full text |Cite
|
Sign up to set email alerts
|

You Get Where You're Looking for: The Impact of Information Sources on Code Security

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

3
197
2
1

Year Published

2017
2017
2024
2024

Publication Types

Select...
4
2
1

Relationship

1
6

Authors

Journals

citations
Cited by 213 publications
(203 citation statements)
references
References 33 publications
3
197
2
1
Order By: Relevance
“…They concluded that crypto APIs are generally perceived to be too low-level, and developers prefer more task-based solutions [7]. Acar et al manually analyzed the security properties of Stack Overflow posts, which their participants used to resolve pre-defined challenges, and they automatically analyzed 200,000 randomly sampled apps from the Google Play market [10]. They observed that real-world Android developers use Stack Overflow and are unwilling to use official Android API documentation.…”
Section: Related Workmentioning
confidence: 99%
“…They concluded that crypto APIs are generally perceived to be too low-level, and developers prefer more task-based solutions [7]. Acar et al manually analyzed the security properties of Stack Overflow posts, which their participants used to resolve pre-defined challenges, and they automatically analyzed 200,000 randomly sampled apps from the Google Play market [10]. They observed that real-world Android developers use Stack Overflow and are unwilling to use official Android API documentation.…”
Section: Related Workmentioning
confidence: 99%
“…Only six guides referenced external information sources; a lack of such citations potentially undermines a reader's confidence in the guide's accuracy and inhibits further reading and learning. Overall, these results provide evidence of an important guidance gap noted in our prior work [4]: official documents and corporate guidelines do not provide the same level of detail and focus on utility as, for example, Q&A sites.…”
Section: Resultsmentioning
confidence: 60%
“…Our prior work found that "official" guidance (from Google and from books) could promote stronger security outcomes than community-based guidance from Stack Overflow [4]. The results of this survey, however, underscore another conclusion from that work: these "official" documents may not necessarily provide the content and format that developers want or need in practice.…”
Section: Resultsmentioning
confidence: 68%
See 2 more Smart Citations