Security and privacy are often neglected in software development, and rarely a priority for developers. This insight is commonly based on research conducted by researchers and on developer populations living and working in the United States, Europe, and the United Kingdom. However, the production of software is global, and crucial populations in important technology hubs are not adequately studied. The software startup scene in Turkey is impactful, and comprehension, knowledge, and mitigations related to software security and privacy remain understudied. To close this research gap, we conducted a semi-structured interview study with 16 developers working in Turkish software startups. The goal of the interview study was to analyze if and how developers ensure that their software is secure and preserves user privacy. Our main finding is that developers rarely prioritize security and privacy, due to a lack of awareness, skills, and resources. We find that regulations can make a positive impact on security and privacy. Based on the study, we issue recommendations for industry, individual developers, research, educators, and regulators. Our recommendations can inform a more globalized approach to security and privacy in software development.
翻译:在软件开发中,安全和隐私往往被忽视,而且很少成为开发商的优先事项。这种洞察力通常以研究人员的研究以及在美国、欧洲和联合王国生活和工作的开发商人口为基础。然而,软件的生产是全球性的,重要技术枢纽中的关键人口没有得到充分的研究。土耳其的软件启动场景影响深远,与软件安全和隐私有关的理解、知识和缓解问题仍然研究不足。为了缩小这一研究差距,我们与在土耳其软件启动阶段工作的16个开发商进行了半结构化的访谈研究。访谈研究的目的是分析开发商是否以及如何确保其软件安全并保护用户隐私。我们的主要发现是,由于缺乏认识、技能和资源,开发商很少优先考虑安全和隐私。我们发现,监管能够对安全和隐私产生积极影响。根据研究,我们向工业界、个人开发商、研究、教育工作者和监管者提出建议。我们的建议可以为软件开发中更加全球化的安全和隐私方法提供信息。