Conference paper

Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs


Authors listGorski, Peter Leo; Acar, Yasemin; Lo Iacono, Luigi; Fahl, Sascha

Appeared inCHI'20, Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems

Editor listBernhaupt, Regina

Publication year2020

ISBN978-1-4503-6708-0

DOI Linkhttps://doi.org/10.1145/3313831.3376142

Conference2020 CHI Conference on Human Factors in Computing Systems (CHI '20)


Abstract

The positive effect of security information communicated to developers through API warnings has been established. However, current prototypical designs are based on security warnings for end-users. To improve security feedback for developers, we conducted a participatory design study with 25 professional software developers in focus groups. We identify which security information is considered helpful in avoiding insecure cryptographic API use during development. Concerning console messages, participants suggested five core elements, namely message classification, title message, code location, link to detailed external resources, and color. Design guidelines for end-user warnings are only partially suitable in this context. Participants emphasized the importance of tailoring the detail and content of security information to the context. Console warnings call for concise communication; further information needs to be linked externally. Therefore, security feedback should transcend tools and should be adjustable by software developers across development tools, considering the work context and developer needs.




Citation Styles

Harvard Citation styleGorski, P., Acar, Y., Lo Iacono, L. and Fahl, S. (2020) Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs, in Bernhaupt, R. (ed.) CHI'20, Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems. New York, NY: Association for Computing Machinery. https://doi.org/10.1145/3313831.3376142

APA Citation styleGorski, P., Acar, Y., Lo Iacono, L., & Fahl, S. (2020). Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIs. In Bernhaupt, R. (Ed.), CHI'20, Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems. Association for Computing Machinery. https://doi.org/10.1145/3313831.3376142


Last updated on 2025-05-08 at 13:32