论文标题
“我们是核心的创业公司”:关于土耳其软件初创公司安全和隐私开发实践的定性访谈研究
"We are a startup to the core": A qualitative interview study on the security and privacy development practices in Turkish software startups
论文作者
论文摘要
在软件开发中通常会忽略安全性和隐私性,而对于开发人员来说,安全性和隐私率很少。这种见解通常基于研究人员和在美国,欧洲和英国生活和工作的开发人员进行的研究。但是,软件的生产是全球性的,重要技术中心中的关键种群没有得到充分的研究。土耳其的软件启动场景具有影响力,与软件安全性和隐私相关的理解,知识和缓解措施仍在研究中。为了缩小这一研究差距,我们对16位在土耳其软件初创公司工作的开发人员进行了半结构化访谈研究。访谈研究的目的是分析开发人员是否以及如何确保其软件安全并保留用户隐私。我们的主要发现是,由于缺乏意识,技能和资源,开发人员很少优先考虑安全和隐私。我们发现法规可以对安全和隐私产生积极影响。基于研究,我们就行业,个人开发人员,研究,教育者和监管机构发出建议。我们的建议可以为软件开发中的安全性和隐私性提供更全球化的方法。
Security and privacy are often neglected in software development, and rarely a priority for developers. This insight is commonly based on research conducted by researchers and on developer populations living and working in the United States, Europe, and the United Kingdom. However, the production of software is global, and crucial populations in important technology hubs are not adequately studied. The software startup scene in Turkey is impactful, and comprehension, knowledge, and mitigations related to software security and privacy remain understudied. To close this research gap, we conducted a semi-structured interview study with 16 developers working in Turkish software startups. The goal of the interview study was to analyze if and how developers ensure that their software is secure and preserves user privacy. Our main finding is that developers rarely prioritize security and privacy, due to a lack of awareness, skills, and resources. We find that regulations can make a positive impact on security and privacy. Based on the study, we issue recommendations for industry, individual developers, research, educators, and regulators. Our recommendations can inform a more globalized approach to security and privacy in software development.