{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:17:24Z","timestamp":1778948244377,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":96,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1145\/3634737.3657012","type":"proceedings-article","created":{"date-parts":[[2024,6,28]],"date-time":"2024-06-28T11:51:38Z","timestamp":1719575498000},"page":"605-620","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Cryptography in the Wild: An Empirical Analysis of Vulnerabilities in Cryptographic Libraries"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-7470-6435","authenticated-orcid":false,"given":"Jenny","family":"Blessing","sequence":"first","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1487-4406","authenticated-orcid":false,"given":"Michael A.","family":"Specter","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, GA, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2368-5300","authenticated-orcid":false,"given":"Daniel J.","family":"Weitzner","sequence":"additional","affiliation":[{"name":"MIT, Cambridge, MA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2014. The Heartbleed Bug. https:\/\/heartbleed.com\/"},{"key":"e_1_3_2_1_2_1","unstructured":"2015. CVE-2015-0204. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-0204"},{"key":"e_1_3_2_1_3_1","unstructured":"OpenBSD 2015. OpenSSL 2015-03-19 Security Advisories: LibreSSL Largely Unaffected. OpenBSD. https:\/\/undeadly.org\/cgi?action=article&sid=20150319145126"},{"key":"e_1_3_2_1_4_1","unstructured":"2017. Some nginx TLS tests started failing with LibreSSL 2.5.3 (but not with 2.4.4). (2017)."},{"key":"e_1_3_2_1_5_1","unstructured":"2020. CVE-2020-13777. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-13777\/"},{"key":"e_1_3_2_1_6_1","unstructured":"2023. BearSSL. https:\/\/bearssl.org\/"},{"key":"e_1_3_2_1_7_1","unstructured":"2023. BoringSSL. https:\/\/boringssl.googlesource.com\/boringssl\/"},{"key":"e_1_3_2_1_8_1","unstructured":"2023. BoringSSL Bug Tracker. https:\/\/bugs.chromium.org\/p\/boringssl\/issues\/list"},{"key":"e_1_3_2_1_9_1","unstructured":"2023. BoringSSL GitHub. https:\/\/github.com\/google\/boringssl"},{"key":"e_1_3_2_1_10_1","unstructured":"2023. Botan. https:\/\/botan.randombit.net\/"},{"key":"e_1_3_2_1_11_1","unstructured":"Legion of the Bouncy Castle 2023. The Bouncy Castle Crypto Package For Java. Legion of the Bouncy Castle. https:\/\/github.com\/bcgit\/bc-java"},{"key":"e_1_3_2_1_12_1","unstructured":"2023. BSAFE. https:\/\/www.dell.com\/support\/kbdoc\/en-uk\/000181945\/dell-bsafe-product-version-life-cycle"},{"key":"e_1_3_2_1_13_1","unstructured":"2023. Censys. https:\/\/censys.io\/"},{"key":"e_1_3_2_1_14_1","unstructured":"Cloudflare 2023. CIRCL (Cloudflare Interoperable Resuable Cryptographic Library). Cloudflare. https:\/\/github.com\/cloudflare\/circl"},{"key":"e_1_3_2_1_15_1","unstructured":"2023. The Cryptix Project. http:\/\/www.cryptix.org\/"},{"key":"e_1_3_2_1_16_1","unstructured":"2023. CryptLib. https:\/\/www.cryptlib.com\/"},{"key":"e_1_3_2_1_17_1","unstructured":"2023. Crypto++. https:\/\/www.cryptopp.com\/"},{"key":"e_1_3_2_1_18_1","unstructured":"2023. Crypto-JS. https:\/\/github.com\/brix\/crypto-js"},{"key":"e_1_3_2_1_19_1","unstructured":"2023. cryptography. https:\/\/pypi.org\/project\/cryptography\/"},{"key":"e_1_3_2_1_20_1","unstructured":"2023. CVE Details. https:\/\/www.cvedetails.com\/"},{"key":"e_1_3_2_1_21_1","volume-title":"National Vulnerability Database. https:\/\/nvd.nist.gov\/general\/FAQ-Sections\/CVE-FAQs#faqLink10","author":"National Vulnerability Database 2023. CVE FAQs.","unstructured":"National Vulnerability Database 2023. CVE FAQs. National Vulnerability Database. https:\/\/nvd.nist.gov\/general\/FAQ-Sections\/CVE-FAQs#faqLink10"},{"key":"e_1_3_2_1_22_1","unstructured":"2023. GnuTLS. https:\/\/www.gnutls.org\/"},{"key":"e_1_3_2_1_23_1","unstructured":"2023. Golang Cryptography. https:\/\/pkg.go.dev\/crypto"},{"key":"e_1_3_2_1_24_1","unstructured":"2023. Java Cryptography Architecture (JCA) Reference Guide. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/security\/crypto\/CryptoSpec.html"},{"key":"e_1_3_2_1_25_1","unstructured":"2023. Libgcrypt. https:\/\/gnupg.org\/software\/libgcrypt\/index.html"},{"key":"e_1_3_2_1_26_1","unstructured":"2023. LibreSSL. https:\/\/www.libressl.org\/"},{"key":"e_1_3_2_1_27_1","unstructured":"2023. LibreSSL ChangeLog. https:\/\/github.com\/libressl-portable\/portable\/blob\/master\/ChangeLog"},{"key":"e_1_3_2_1_28_1","unstructured":"2023. LibreSSL GitHub. https:\/\/github.com\/libressl-portable\/openbsd"},{"key":"e_1_3_2_1_29_1","unstructured":"2023. LibreSSL Mailing list ARChives. https:\/\/marc.info\/?l=libressl&r=1&w=2"},{"key":"e_1_3_2_1_30_1","unstructured":"2023. LibreSSL Releases. https:\/\/www.libressl.org\/releases.html"},{"key":"e_1_3_2_1_31_1","unstructured":"2023. LibreSSl with Bob Beck. https:\/\/www.youtube.com\/watch?v=GnBbhXBDmwU"},{"key":"e_1_3_2_1_32_1","unstructured":"2023. Libsodium. https:\/\/doc.libsodium.org\/"},{"key":"e_1_3_2_1_33_1","unstructured":"2023. LibTomCrypt. https:\/\/github.com\/libtom\/libtomcrypt"},{"key":"e_1_3_2_1_34_1","unstructured":"2023. MatrixSSL. https:\/\/github.com\/matrixssl\/matrixssl"},{"key":"e_1_3_2_1_35_1","unstructured":"2023. Mbed TLS. https:\/\/github.com\/Mbed-TLS\/mbedtls"},{"key":"e_1_3_2_1_36_1","unstructured":"2023. Microsoft Schannel. https:\/\/docs.microsoft.com\/en-us\/windows-server\/security\/tls\/tls-ssl-schannel-ssp-overview"},{"key":"e_1_3_2_1_37_1","unstructured":"2023. Monocypher. https:\/\/monocypher.org\/"},{"key":"e_1_3_2_1_38_1","unstructured":"2023. Mozilla Network Security Services. https:\/\/developer.mozilla.org\/en-US\/docs\/Mozilla\/Projects\/NSS"},{"key":"e_1_3_2_1_39_1","unstructured":"2023. NaCl. https:\/\/nacl.cr.yp.to\/"},{"key":"e_1_3_2_1_40_1","unstructured":"2023. Nettle. https:\/\/github.com\/gnutls\/nettle"},{"key":"e_1_3_2_1_41_1","unstructured":"2023. OpenSSL. https:\/\/www.openssl.org\/"},{"key":"e_1_3_2_1_42_1","unstructured":"2023. OpenSSL Releases. https:\/\/github.com\/openssl\/openssl\/releases"},{"key":"e_1_3_2_1_43_1","unstructured":"2023. OpenSSL Vulnerabilities. https:\/\/www.openssl.org\/news\/vulnerabilities.html"},{"key":"e_1_3_2_1_44_1","unstructured":"2023. Orion. https:\/\/github.com\/orion-rs\/orion"},{"key":"e_1_3_2_1_45_1","unstructured":"2023. PyCrypto. https:\/\/github.com\/pycrypto\/pycrypto"},{"key":"e_1_3_2_1_46_1","unstructured":"2023. PyCryptodome. https:\/\/pypi.org\/project\/pycryptodome\/"},{"key":"e_1_3_2_1_47_1","unstructured":"2023. Rambus TLS Toolkit 4.0. https:\/\/www.rambus.com\/security\/software-protocols\/secure-communication-toolkits\/tls-toolkit\/"},{"key":"e_1_3_2_1_48_1","unstructured":"2023. Ring. https:\/\/github.com\/briansmith\/ring"},{"key":"e_1_3_2_1_49_1","unstructured":"2023. RustCrypto. https:\/\/github.com\/RustCrypto"},{"key":"e_1_3_2_1_50_1","unstructured":"2023. Rustls. https:\/\/docs.rs\/rustls\/latest\/rustls\/"},{"key":"e_1_3_2_1_51_1","unstructured":"2023. s2n. https:\/\/github.com\/aws\/s2n-tls"},{"key":"e_1_3_2_1_52_1","unstructured":"2023. Sodium Oxide. https:\/\/docs.rs\/sodiumoxide\/latest\/sodiumoxide\/"},{"key":"e_1_3_2_1_53_1","unstructured":"2023. Stanford JavaScript Cryptography Library (SJCL). https:\/\/github.com\/bitwiseshiftleft\/sjcl\/"},{"key":"e_1_3_2_1_54_1","unstructured":"2023. WolfSSL. https:\/\/www.wolfssl.com\/"},{"key":"e_1_3_2_1_55_1","volume-title":"A Path Toward Secure and Measurable Software","author":"House The White","year":"2024","unstructured":"The White House February 2024. A Path Toward Secure and Measurable Software. The White House. https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2024\/02\/Final-ONCD-Technical-Report.pdf"},{"key":"e_1_3_2_1_56_1","unstructured":"CISA October 2023. Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design. CISA. https:\/\/www.cisa.gov\/sites\/default\/files\/2023-10\/SecureByDesign_1025_508c.pdf"},{"key":"e_1_3_2_1_57_1","volume-title":"Keys Under Doormats: Mandating Insecurity by Requiring Government Access to All Data and Communications. Journal of Cybersecurity 1.1","author":"Abelson Harold","year":"2015","unstructured":"Harold Abelson, Ross Anderson, Steven M. Bellovin, Josh Benaloh, Matt Blaze, Whitfield Diffie, John Gilmore, Matthew Green, Susan Landau, Peter G. Neumann, Ronald L. Rivest, Jeffrey I. Schiller, Bruce Schneier, Michael Specter, and Daniel Weitzner. 2015. Keys Under Doormats: Mandating Insecurity by Requiring Government Access to All Data and Communications. Journal of Cybersecurity 1.1 (2015), 69--79."},{"key":"e_1_3_2_1_58_1","volume-title":"Comparing the Usability of Cryptographic APIs. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 154--171","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Michael Backes, Sascha Fahl, Simson Garfinkel, Doowon Kim, Michelle L Mazurek, and Christian Stransky. 2017. Comparing the Usability of Cryptographic APIs. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 154--171."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168615"},{"key":"e_1_3_2_1_60_1","volume-title":"Cleaning the NVD: Comprehensive quality assessment, improvements, and analyses","author":"Anwar Afsah","year":"2021","unstructured":"Afsah Anwar, Ahmed Abusnaina, Songqing Chen, Frank Li, and David Mohaisen. 2021. Cleaning the NVD: Comprehensive quality assessment, improvements, and analyses. IEEE Transactions on Dependable and Secure Computing (2021)."},{"key":"e_1_3_2_1_61_1","unstructured":"D. F. Aranha C. P. L. Gouv\u00eaa T. Markmann R. S. Wahby and K. Liao. 2023. RELIC is an Efficient LIbrary for Cryptography. https:\/\/github.com\/relic-toolkit\/relic."},{"key":"e_1_3_2_1_62_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Azad Babak Amin","year":"2019","unstructured":"Babak Amin Azad, Pierre Laperdrix, and Nick Nikiforakis. 2019. Less is More: Quantifying the Security Benefits of Debloating Web Applications. In 28th USENIX Security Symposium (USENIX Security 19). 1697--1714."},{"key":"e_1_3_2_1_63_1","volume-title":"Progress in Cryptology-LATINCRYPT 2012: 2nd International Conference on Cryptology and Information Security in Latin America, Santiago, Chile, October 7--10","author":"Bernstein Daniel J","year":"2012","unstructured":"Daniel J Bernstein, Tanja Lange, and Peter Schwabe. 2012. The security impact of a new cryptographic library. In Progress in Cryptology-LATINCRYPT 2012: 2nd International Conference on Cryptology and Information Security in Latin America, Santiago, Chile, October 7--10, 2012. Proceedings 2. Springer, 159--176."},{"key":"e_1_3_2_1_64_1","volume-title":"Written Testimony before the Committee on Science. Space and Technology","author":"Chang Frederik","year":"2013","unstructured":"Frederik Chang. 2013. Is Your Data on the Healthcare. gov Website Secure?, Written Testimony before the Committee on Science. Space and Technology, US House of Representatives, November (2013)."},{"key":"e_1_3_2_1_65_1","unstructured":"MITRE Corporation. [n. d.].. CWE: Common Weakness Enumeration."},{"key":"e_1_3_2_1_66_1","unstructured":"MITRE Corporation. 2023. Common Vulnerabilities and Exposures. https:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_1_67_1","unstructured":"Al Danial. 2023. cloc: Count Lines of Code. https:\/\/github.com\/AlDanial\/cloc"},{"key":"e_1_3_2_1_68_1","volume-title":"Fireside Chat: The State of Memory Safety.","author":"Dhalla Amira","year":"2023","unstructured":"Amira Dhalla, Yael Grauer, Alex Gaynor, and Josh Aas. 2023. Fireside Chat: The State of Memory Safety. (2023)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_3_2_1_70_1","unstructured":"Alex Gaynor. 2021. Quantifying memory unsafety and reactions to it. (2021)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720291"},{"key":"e_1_3_2_1_72_1","volume-title":"Fourteenth Symposium on Usable Privacy and Security ({SOUPS}","author":"Haney Julie M","year":"2018","unstructured":"Julie M Haney, Mary Theofanos, Yasemin Acar, and Sandra Spickard Prettyman. 2018. \"We make it a big deal in the company\": Security Mindsets in Organizations that Develop Cryptographic Products. In Fourteenth Symposium on Usable Privacy and Security ({SOUPS} 2018). 357--373."},{"key":"e_1_3_2_1_73_1","volume-title":"Cognicrypt: Supporting Developers in Using Cryptography. In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 931--936","author":"Kr\u00fcger Stefan","year":"2017","unstructured":"Stefan Kr\u00fcger, Sarah Nadi, Michael Reif, Karim Ali, Mira Mezini, Eric Bodden, Florian G\u00f6pfert, Felix G\u00fcnther, Christian Weinert, Daniel Demmler, et al. 2017. Cognicrypt: Supporting Developers in Using Cryptography. In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 931--936."},{"key":"e_1_3_2_1_74_1","unstructured":"Adam Langley. 2015. BoringSSL. https:\/\/www.imperialviolet.org\/2015\/10\/17\/boringssl.html"},{"key":"e_1_3_2_1_75_1","volume-title":"Proceedings of 5th Asia-Pacific Workshop on Systems. 1--7.","author":"Lazar David","year":"2014","unstructured":"David Lazar, Haogang Chen, Xi Wang, and Nickolai Zeldovich. 2014. Why Does Cryptographic Software Fail? A Case Study and Open Problems. In Proceedings of 5th Asia-Pacific Workshop on Systems. 1--7."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1976.233837"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134082"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"crossref","unstructured":"NVD. [n. d.].. CVE-2018-12433.","DOI":"10.5465\/AMBPP.2018.12433abstract"},{"key":"e_1_3_2_1_81_1","unstructured":"U.S. National Institute of Standards and Technology. 2020.. National Vulnerability Database. https:\/\/nvd.nist.gov\/home.cfm\/"},{"key":"e_1_3_2_1_82_1","unstructured":"U.S. National Institute of Standards and Technology. 2023. CVSS Information. https:\/\/nvd.nist.gov\/cvss.cfm\/"},{"key":"e_1_3_2_1_83_1","volume-title":"Fourteenth Symposium on Usable Privacy and Security ({SOUPS}","author":"Oliveira Daniela Seabra","year":"2018","unstructured":"Daniela Seabra Oliveira, Tian Lin, Muhammad Sajidur Rahman, Rad Akefirad, Donovan Ellis, Eliany Perez, Rahul Bobhate, Lois A DeLong, Justin Cappos, and Yuriy Brun. 2018. {API} Blindspots: Why Experienced Developers Write Vulnerable Code. In Fourteenth Symposium on Usable Privacy and Security ({SOUPS} 2018). 315--328."},{"key":"e_1_3_2_1_84_1","volume-title":"USENIX Security Symposium","volume":"6","author":"Ozment Andy","year":"2006","unstructured":"Andy Ozment and Stuart E Schechter. 2006. Milk or Wine: Does Software Security Improve with Age?. In USENIX Security Symposium, Vol. 6."},{"key":"e_1_3_2_1_85_1","volume-title":"Sixteenth Symposium on Usable Privacy and Security ({SOUPS}","author":"Palombo Hernan","year":"2020","unstructured":"Hernan Palombo, Armin Ziaie Tabari, Daniel Lende, Jay Ligatti, and Xinming Ou. 2020. An ethnographic understanding of software (in) security and a co-creation model to improve secure software development. In Sixteenth Symposium on Usable Privacy and Security ({SOUPS} 2020). 205--220."},{"key":"e_1_3_2_1_86_1","volume-title":"Fifteenth Symposium on Usable Privacy and Security (SOUPS","author":"Patnaik Nikhil","year":"2019","unstructured":"Nikhil Patnaik, Joseph Hallett, and Awais Rashid. 2019. Usability Smells: An Analysis of {Developers'} Struggle With Crypto Libraries. In Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). 245--257."},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.17"},{"key":"e_1_3_2_1_88_1","unstructured":"Bruce Schneier. 1999. A Plea for Simplicity: You Can't Secure What You Don't Understand. Schneier on Security."},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227141"},{"key":"e_1_3_2_1_90_1","volume-title":"Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities","author":"Shin Yonghee","year":"2010","unstructured":"Yonghee Shin, Andrew Meneely, Laurie Williams, and Jason A Osborne. 2010. Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities. IEEE transactions on software engineering 37, 6 (2010), 772--787."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_2_1_92_1","unstructured":"Ted Unangst. [n. d.]. LibreSSL: More Than 30 Days Later. https:\/\/www.openbsd.org\/papers\/eurobsdcon2014-libressl.html"},{"key":"e_1_3_2_1_93_1","volume-title":"29th {USENIX} Security Symposium ({USENIX} Security 20). 109--126.","author":"Votipka Daniel","unstructured":"Daniel Votipka, Kelsey R Fulton, James Parker, Matthew Hou, Michelle L Mazurek, and Michael Hicks. 2020. Understanding security mistakes developers make: Qualitative analysis from build it, break it, fix it. In 29th {USENIX} Security Symposium ({USENIX} Security 20). 109--126."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387465"},{"key":"e_1_3_2_1_95_1","unstructured":"Terry Yin. 2023.. Lizard. https:\/\/github.com\/terryyin\/lizard"},{"key":"e_1_3_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2010.32"}],"event":{"name":"ASIA CCS '24: 19th ACM Asia Conference on Computer and Communications Security","location":"Singapore Singapore","acronym":"ASIA CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 19th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3657012","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:44:07Z","timestamp":1750290247000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3657012"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":96,"alternative-id":["10.1145\/3634737.3657012","10.1145\/3634737"],"URL":"https:\/\/doi.org\/10.1145\/3634737.3657012","relation":{},"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"2024-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}