Social Coding Platforms (SCPs) like GitHub have become central to modern software engineering thanks to their collaborative and version-control features. Like in mainstream Online Social Networks (OSNs) such as Facebook, users of SCPs are subjected to privacy attacks and threats given the high amounts of personal and project-related data available in their profiles and software repositories. However, unlike in OSNs, the privacy concerns and practices of SCP users have not been extensively explored nor documented in the current literature. In this work, we present the preliminary results of an online survey (N=105) addressing developers' concerns and perceptions about privacy threats steaming from SCPs. Our results suggest that, although users express concern about social and organisational privacy threats, they often feel safe sharing personal and project-related information on these platforms. Moreover, attacks targeting the inference of sensitive attributes are considered more likely than those seeking to re-identify source-code contributors. Based on these findings, we propose a set of recommendations for future investigations addressing privacy and identity management in SCPs.
翻译:GitHub等社会编码平台因其协作和版本控制功能而成为现代软件工程的核心。与脸书等主流在线社会网络一样,SCP用户由于其档案和软件库中的个人和项目相关数据数量巨大,往往会受到隐私攻击和威胁。然而,与OSNs不同的是,SCP用户的隐私关切和做法没有在目前的文献中进行广泛探讨和记录。在这项工作中,我们介绍了一项在线调查的初步结果(N=105),其中涉及开发商对SCP对隐私威胁的担忧和看法。我们的结果表明,虽然用户对社会和组织隐私威胁表示关切,但他们往往感到在这些平台上分享个人和项目信息的安全性。此外,针对敏感属性的推断的攻击被认为比那些试图重新识别源代码提供者的攻击更有可能。基于这些调查结果,我们提出了一套关于未来调查SCP隐私和身份管理的建议。</s>