Stack Overflow (SO) is a popular platform among developers seeking advice on various software-related topics, including privacy and security. As for many knowledge-sharing websites, the value of SO depends largely on users' engagement, namely their willingness to answer, comment or post technical questions. Still, many of these questions (including cybersecurity-related ones) remain unanswered, putting the site's relevance and reputation into question. Hence, it is important to understand users' participation in privacy and security discussions to promote engagement and foster the exchange of such expertise. Objective: Based on prior findings on online social networks, this work elaborates on the interplay between users' engagement and their privacy practices in SO. Particularly, it analyses developers' self-disclosure behaviour regarding profile visibility and their involvement in discussions related to privacy and security. Method: We followed a mixed-methods approach by (i) analysing SO data from 1239 cybersecurity-tagged questions along with 7048 user profiles, and (ii) conducting an anonymous online survey (N=64). Results: About 33% of the questions we retrieved had no answer, whereas more than 50% had no accepted answer. We observed that "proactive" users tend to disclose significantly less information in their profiles than "reactive" and "unengaged" ones. However, no correlations were found between these engagement categories and privacy-related constructs such as Perceived Control or General Privacy Concerns. Implications: These findings contribute to (i) a better understanding of developers' engagement towards privacy and security topics, and (ii) to shape strategies promoting the exchange of cybersecurity expertise in SO.
翻译:Stack Overflow (SO) 是开发商寻求有关包括隐私和安全在内的各种软件相关议题的咨询的广受欢迎的平台。对于许多知识共享网站而言,SO的价值在很大程度上取决于用户的参与,即他们是否愿意回答、评论或公布技术问题。然而,其中许多问题(包括网络安全相关问题)仍然没有得到答复,使网站的相关性和声誉受到质疑。因此,必须了解用户参与隐私和安全讨论,以促进参与和促进这种专门知识的交流。目标:根据以前对在线社交网络的研究结果,这项工作详细阐述了用户参与及其在SO的隐私做法之间的相互作用。特别是,SO的价值取决于用户对形象的自我披露行为及其参与与隐私和安全有关的讨论。方法:我们采用混合方法,即(一) 分析来自SO的、与网络安全有关的问题以及7048个用户的概况,(二) 进行匿名在线调查(N=64)。结果:我们检索到的问题中约有33%没有答案,而超过50%的用户的参与及其在SOireireal(我们注意到“积极性”战略往往披露“对安全性和相关性有更好的了解 ” 。我们发现这些关联性,因此“积极性和相关性的用户往往不作好于这些关联性分析”。