{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T07:59:47Z","timestamp":1780646387930,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,6,27]],"date-time":"2020-06-27T00:00:00Z","timestamp":1593216000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/P011799\/1"],"award-info":[{"award-number":["EP\/P011799\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,6,27]]},"DOI":"10.1145\/3377811.3380394","type":"proceedings-article","created":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T18:25:34Z","timestamp":1601576734000},"page":"149-160","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":32,"title":["Schr\u00f6dinger's security"],"prefix":"10.1145","author":[{"given":"Dirk","family":"van der Linden","sequence":"first","affiliation":[{"name":"University of Bristol"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pauline","family":"Anthonysamy","sequence":"additional","affiliation":[{"name":"Google"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bashar","family":"Nuseibeh","sequence":"additional","affiliation":[{"name":"The Open University Lero and University of Limerick"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thein Than","family":"Tun","sequence":"additional","affiliation":[{"name":"The Open University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marian","family":"Petre","sequence":"additional","affiliation":[{"name":"The Open University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mark","family":"Levine","sequence":"additional","affiliation":[{"name":"Lancaster University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Towse","sequence":"additional","affiliation":[{"name":"Lancaster University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Awais","family":"Rashid","sequence":"additional","affiliation":[{"name":"University of Bristol"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.33"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.52"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_1_4_1","volume-title":"Too: A Survey of Security Advice for Software Developers. In Cybersecurity Development (SecDev)","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Christian Stransky, Dominik Wermke, Charles Weir, Michelle L Mazurek, and Sascha Fahl. 2017. Developers Need Support, Too: A Survey of Security Advice for Software Developers. In Cybersecurity Development (SecDev), 2017 IEEE. IEEE, 22--26."},{"key":"e_1_3_2_1_5_1","volume-title":"Motivations and Amotivations for Software Security - Preliminary Results. In Workshop on Security Information Workers (WSIW)","author":"Assal Hala","year":"2018","unstructured":"Hala Assal and Sonia Chiasson. 2018. Motivations and Amotivations for Software Security - Preliminary Results. In Workshop on Security Information Workers (WSIW) 2018."},{"key":"e_1_3_2_1_6_1","volume-title":"Security in the Software Development Lifecycle. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018","author":"Assal Hala","year":"2018","unstructured":"Hala Assal and Sonia Chiasson. 2018. Security in the Software Development Lifecycle. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018). USENIX Association, Baltimore, MD, 281--296. https:\/\/www.usenix.org\/conference\/soups2018\/presentation\/assal"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3290605.3300519"},{"key":"e_1_3_2_1_8_1","volume-title":"Proc. ARES'11","author":"Andrea","unstructured":"Andrea Atzeni et al. 2011. Here's Johnny: a methodology for developing attacker personas. In Proc. ARES'11. IEEE, 722--727."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978333"},{"key":"e_1_3_2_1_10_1","volume-title":"Igexin advertising network put user privacy at risk. https:\/\/blog.lookout.com\/igexin-malicious-sdk. (2017). Online","author":"Bauer Adam","year":"2018","unstructured":"Adam Bauer and Bauer Hebeisen. 2017. Igexin advertising network put user privacy at risk. https:\/\/blog.lookout.com\/igexin-malicious-sdk. (2017). Online; accessed 20 October 2018."},{"key":"e_1_3_2_1_11_1","volume-title":"Longitudinal analysis of android ad library permissions. arXiv preprint arXiv:1303.0857","author":"Book Theodore","year":"2013","unstructured":"Theodore Book, Adam Pridgen, and Dan S Wallach. 2013. Longitudinal analysis of android ad library permissions. arXiv preprint arXiv:1303.0857 (2013)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Jean Braucher. 2006. 12 Principles for Fair Commerce in Mass-Market Software and Other Digital Products. In Arizona Legal Studies Discussion Paper No 06--05. Available at SSRN: https:\/\/ssrn.com\/abstract=730907.","DOI":"10.2139\/ssrn.730907"},{"key":"e_1_3_2_1_13_1","first-page":"95","article-title":"Thematic analysis","volume":"24","author":"Braun Virginia","year":"2014","unstructured":"Virginia Braun, Victoria Clarke, and Gareth Terry. 2014. Thematic analysis. Qual Res Clin Health Psychol 24 (2014), 95--114.","journal-title":"Qual Res Clin Health Psychol"},{"key":"e_1_3_2_1_14_1","volume-title":"Information Security and Contracts","author":"Chandler Jennifer","unstructured":"Jennifer Chandler. 2009. Information Security and Contracts. Contracting Insecurity: Software License Terms That Undermine Information Security. In Harboring Data: Information Security, Law, and the Corporation, Andrea M. Matwyshyn (Ed.). Stanford University Press, Stanford, California."},{"key":"e_1_3_2_1_15_1","volume-title":"Grounded theory research: Procedures, canons, and evaluative criteria. Qualitative sociology 13, 1","author":"Corbin Juliet M","year":"1990","unstructured":"Juliet M Corbin and Anselm Strauss. 1990. Grounded theory research: Procedures, canons, and evaluative criteria. Qualitative sociology 13, 1 (1990), 3--21."},{"key":"e_1_3_2_1_16_1","volume-title":"O'Reilly Media","author":"Cranor Lorrie","unstructured":"Lorrie Cranor and Simson Garfinkel. 2005. Security and Usability. O'Reilly Media, Inc."},{"key":"e_1_3_2_1_17_1","volume-title":"A demographic and business model analysis of today's app developer. GigaOM Pro","author":"Cravens Amy","year":"2012","unstructured":"Amy Cravens. 2012. A demographic and business model analysis of today's app developer. GigaOM Pro (2012)."},{"key":"e_1_3_2_1_18_1","volume-title":"Proc. CHI'16","author":"Cleidson RB","unstructured":"Cleidson RB de Souza et al. 2016. The social side of software platform ecosystems. In Proc. CHI'16. ACM, 3204--3214."},{"key":"e_1_3_2_1_19_1","volume-title":"Proc. SEC'11@USENIX","volume":"2","author":"William","unstructured":"William Enck et al. 2011. A Study of Android Application Security.. In Proc. SEC'11@USENIX, Vol. 2. 2."},{"key":"e_1_3_2_1_20_1","volume-title":"Analyzing Xavier: An Information-Stealing Ad Library on Android. https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/analyzing-xavier-information-stealing-ad-library-android\/.","author":"Mobile Threat Response Ecular Xu","year":"2017","unstructured":"Ecular Xu (Mobile Threat Response Engineer). 2017. Analyzing Xavier: An Information-Stealing Ad Library on Android. https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/analyzing-xavier-information-stealing-ad-library-android\/. (2017). Online; accessed 20 October 2018."},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. CCS'12","author":"Sascha","unstructured":"Sascha Fahl et al. 2012. Why Eve and Mallory love Android: An analysis of Android SSL (in) security. In Proc. CCS'12. ACM, 50--61."},{"key":"e_1_3_2_1_22_1","volume-title":"The Impact of Copy&Paste on Android Application Security. In Symp. S&P'17","author":"Felix","unstructured":"Felix Fischer et al. 2017. Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security. In Symp. S&P'17. IEEE, 121--136."},{"key":"e_1_3_2_1_23_1","volume-title":"Computing inter-rater reliability for observational data: an overview and tutorial. Tutorials in quantitative methods for psychology 8, 1","author":"Hallgren Kevin A","year":"2012","unstructured":"Kevin A Hallgren. 2012. Computing inter-rater reliability for observational data: an overview and tutorial. Tutorials in quantitative methods for psychology 8, 1 (2012), 23."},{"key":"e_1_3_2_1_24_1","volume-title":"Fourteenth Symposium on Usable Privacy and Security (SOUPS)","author":"Haney Julie M","year":"2018","unstructured":"Julie M Haney, Mary Theofanos, Yasemin Acar, and Sandra Spickard Prettyman. 2018. \"We make it a big deal in the company\": Security Mindsets in Organizations that Develop Cryptographic Products. In Fourteenth Symposium on Usable Privacy and Security (SOUPS) 2018. 357--373."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPIN.2014.6777033"},{"key":"e_1_3_2_1_26_1","volume-title":"Comparison of release engineering practices in a large mature company and a startup. Empirical Software Engineering","author":"Laukkanen Eero","year":"2018","unstructured":"Eero Laukkanen, Maria Paasivaara, Juha Itkonen, and Casper Lassenius. 2018. Comparison of release engineering practices in a large mature company and a startup. Empirical Software Engineering (2018), 1--43."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Tamara Lopez Thein Tun Arosha Bandara Bashar Nuseibeh Helen Sharp and Mark Levine. 2018. An Investigation of Security Conversations in Stack Overflow: Perceptions of Security and Community Involvement. In First International Workshop on Security Awareness from Design to Deployment (SEAD'18).","DOI":"10.1145\/3194707.3194713"},{"key":"e_1_3_2_1_28_1","volume-title":"International Conference on Games and Learning Alliance. Springer, 221--231","author":"Maarek Manuel","year":"2018","unstructured":"Manuel Maarek, Sandy Louchart, L\u00e9on McGregor, and Ross McMenemy. 2018. Cocreated Design of a Serious Game Investigation into Developer-Centred Security. In International Conference on Games and Learning Alliance. Springer, 221--231."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180201"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2015.123"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134082"},{"key":"e_1_3_2_1_32_1","volume-title":"Flow and the foundations of positive psychology","author":"Nakamura Jeanne","unstructured":"Jeanne Nakamura and Mihaly Csikszentmihalyi. 2014. The concept of flow. In Flow and the foundations of positive psychology. Springer, 239--263."},{"key":"e_1_3_2_1_33_1","volume-title":"API Blindspots: Why Experienced Developers Write Vulnerable Code. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018","author":"Oliveira Daniela Seabra","year":"2018","unstructured":"Daniela Seabra Oliveira, Tian Lin, Muhammad Sajidur Rahman, Rad Akefirad, Donovan Ellis, Eliany Perez, Rahul Bobhate, Lois A. DeLong, Justin Cappos, and Yuriy Brun. 2018. API Blindspots: Why Experienced Developers Write Vulnerable Code. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018). USENIX Association, Baltimore, MD, 315--328. https:\/\/www.usenix.org\/conference\/soups2018\/presentation\/oliveira"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF02296207"},{"key":"e_1_3_2_1_35_1","first-page":"23","article-title":"Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications","volume":"14","author":"Poeplau Sebastian","year":"2014","unstructured":"Sebastian Poeplau, Yanick Fratantonio, Antonio Bianchi, Christopher Kruegel, and Giovanni Vigna. 2014. Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications.. In NDSS, Vol. 14. 23--26.","journal-title":"NDSS"},{"key":"e_1_3_2_1_36_1","volume-title":"Are Free Android App Security Analysis Tools Effective in Detecting Known Vulnerabilities? arXiv preprint arXiv:1806.09059","author":"Ranganath Venkatesh-Prasad","year":"2018","unstructured":"Venkatesh-Prasad Ranganath and Joydeep Mitra. 2018. Are Free Android App Security Analysis Tools Effective in Detecting Known Vulnerabilities? arXiv preprint arXiv:1806.09059 (2018)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2996358"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-015-9379-3"},{"key":"e_1_3_2_1_39_1","volume-title":"What You Need to Know About iOS Malware XcodeGhost. https:\/\/www.macrumors.com\/2015\/09\/20\/xcodeghost-chinese-malware-faq\/. (2015). Online","author":"Rossignol Joe","year":"2018","unstructured":"Joe Rossignol. 2015. What You Need to Know About iOS Malware XcodeGhost. https:\/\/www.macrumors.com\/2015\/09\/20\/xcodeghost-chinese-malware-faq\/. (2015). Online; accessed 20 October 2018."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2016.2615307"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2002.1067735"},{"key":"e_1_3_2_1_42_1","volume-title":"Developer Economics: State of the Developer Nation Q1","author":"Developer Economics SlashData","year":"2016","unstructured":"SlashData Developer Economics. 2016. Developer Economics: State of the Developer Nation Q1 2016. https:\/\/www.developereconomics.com\/reports\/developer-economics-state-of-developer-nation-q1-2016. (2016). Online; accessed 18 September 2017."},{"key":"e_1_3_2_1_43_1","volume-title":"Developer Economics: State of the Developer Nation. https:\/\/www.developereconomics.com\/reports.","author":"Developer Economics SlashData","year":"2017","unstructured":"SlashData Developer Economics. 2017. Developer Economics: State of the Developer Nation. https:\/\/www.developereconomics.com\/reports. (2017). Online; accessed 20 October 2017."},{"key":"e_1_3_2_1_44_1","volume-title":"Workshop on Mobile Security Technologies (MoST)","volume":"10","author":"Stevens Ryan","year":"2012","unstructured":"Ryan Stevens, Clint Gibler, Jon Crussell, Jeremy Erickson, and Hao Chen. 2012. Investigating user privacy in android ad libraries. In Workshop on Mobile Security Technologies (MoST), Vol. 10."},{"key":"e_1_3_2_1_45_1","volume-title":"Dirk and others","year":"2020","unstructured":"van der Linden, Dirk and others. 2020. Schr\u00f6dinger's Security (ICSE 2020) Appendices. http:\/\/hdl.handle.net\/1983\/f43803de-4ade-488f-be1a-a2e8ba30c201. (2020). Online; accessed 8 January 2020."},{"key":"e_1_3_2_1_46_1","volume-title":"Workshop on Security Information Workers (WSIW).","author":"Votipka Daniel","year":"2018","unstructured":"Daniel Votipka, Michelle L Mazurek, Hongyi Hu, and Bryan Eastes. 2018. Toward a Field Study on the Impact of Hacking Competitions on Secure Development. In Workshop on Security Information Workers (WSIW)."},{"key":"e_1_3_2_1_47_1","volume-title":"Proc. SOUPS@USENIX'16","author":"Charles","unstructured":"Charles Weir et al. 2016. How should mobile app programmers learn security? Comparing and contrasting expert views. In Proc. SOUPS@USENIX'16."},{"key":"e_1_3_2_1_48_1","volume-title":"Am I Responsible for End-User's Security? A Programmer's Perspective. arXiv preprint arXiv:1808.01481","author":"Wijayarathna Chamila","year":"2018","unstructured":"Chamila Wijayarathna and Nalin Asanka Gamagedara Arachchilage. 2018. Am I Responsible for End-User's Security? A Programmer's Perspective. arXiv preprint arXiv:1808.01481 (2018)."},{"key":"e_1_3_2_1_49_1","volume-title":"Symp. VL\/HCC","author":"Xie J.","year":"2011","unstructured":"J. Xie, H. R. Lipford, and B. Chu. 2011. Why do programmers make security errors?. In Symp. VL\/HCC 2011. IEEE, 161--164."}],"event":{"name":"ICSE '20: 42nd International Conference on Software Engineering","location":"Seoul South Korea","acronym":"ICSE '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","KIISE Korean Institute of Information Scientists and Engineers","IEEE CS"]},"container-title":["Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380394","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3377811.3380394","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:39Z","timestamp":1750200099000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3377811.3380394"}},"subtitle":["opening the box on app developers' security rationale"],"short-title":[],"issued":{"date-parts":[[2020,6,27]]},"references-count":49,"alternative-id":["10.1145\/3377811.3380394","10.1145\/3377811"],"URL":"https:\/\/doi.org\/10.1145\/3377811.3380394","relation":{},"subject":[],"published":{"date-parts":[[2020,6,27]]},"assertion":[{"value":"2020-10-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}