2018/08/04 by Chamila Wijayarathna, Wijayarathna, Chamila, Nalin Asanka Gamagedara Arachchilage +1 · 1 citation
Computer Science · #Advanced Malware Detection Techniques #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Security and Verification in Computing #User Authentication and Security Systems #cs.CR #cs.CY
paper · pdf · doi:10.48550/arxiv.1808.01481
4, USENIX Symposium on Usable Privacy and Security (SOUPS), August 12 14 Baltimore, MD, USA,2018
arxiv created 2018/08/04 · openalex publication_date 2018/08/04 · arxiv updated 2018/08/07 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Previous research has pointed that software applications should not depend on programmers to provide security for end-users as majority of programmers are not experts of computer security. On the other hand, some studies have revealed that security experts believe programmers have a major role to play in ensuring the end-users' security. However, there has been no investigation on what programmers perceive about their responsibility for the end-users' security of applications they develop. In this work, by conducting a qualitative experimental study with 40 software developers, we attempted to understand the programmer's perception on who is responsible for ensuring end-users' security of the applications they develop. Results revealed majority of programmers perceive that they are responsible for the end-users' security of applications they develop. Furthermore, results showed that even though programmers aware of things they need to do to ensure end-users' security, they do not often follow them. We believe these results would change the current view on the role that different stakeholders of the software development process (i.e. researchers, security experts, programmers and Application Programming Interface (API) developers) have to play in order to ensure the security of software applications.