The security attitudes and approaches of software developers have a large impact on the software they produce, yet we know very little about how and when these views are constructed. This paper investigates the security and privacy (S&P) perceptions, experiences, and practices of current Computer Science students at the graduate and undergraduate level using semi-structured interviews. We find that the attitudes of students already match many of those that have been observed in professional level developers. Students have a range of hacker and attack mindsets, lack of experience with security APIs, a mixed view of who is in charge of S&P in the software life cycle, and a tendency to trust other peoples' code as a convenient approach to rapidly build software. We discuss the impact of our results on both curriculum development and support for professional developers.
翻译:软件开发者的安全态度和方法对他们制作的软件产生了很大影响,但我们对这些观点是如何和何时构建的知之甚少,本文调查了研究生和本科生目前的计算机科学学生使用半结构化访谈的安全和隐私观念、经验和做法。我们发现,学生的态度已经与专业水平开发者所观察到的许多态度相匹配。学生有着一系列黑客和攻击性心态,缺乏安全API的经验,对谁在软件生命周期中负责S&P的观念不一,以及相信他人代码作为快速建立软件的方便方法的趋势。我们讨论了我们的成果对课程开发以及对专业开发者的支持的影响。