Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
Fuente:
arXiv
Salvato in:
| Autori principali: | Kalu, Kelechi G., Okorafor, Sofia, Singla, Tanmay, Chen, Sophie, Torres-Arias, Santiago, Davis, James C. |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
di: Davis, James C, et al.
Pubblicazione: (2025)
di: Davis, James C, et al.
Pubblicazione: (2025)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Towards a Benchmark for Dependency Decision-Making
di: Singla, Tanmay, et al.
Pubblicazione: (2026)
di: Singla, Tanmay, et al.
Pubblicazione: (2026)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
RiskHarvester: A Risk-based Tool to Prioritize Secret Removal Efforts in Software Artifacts
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
di: Basak, Setu Kumar, et al.
Pubblicazione: (2025)
Usability as a Weapon: Attacking the Safety of LLM-Based Code Generation via Usability Requirements
di: Li, Yue, et al.
Pubblicazione: (2026)
di: Li, Yue, et al.
Pubblicazione: (2026)
Rust for Embedded Systems: Current State, Challenges and Open Problems (Extended Report)
di: Sharma, Ayushi, et al.
Pubblicazione: (2023)
di: Sharma, Ayushi, et al.
Pubblicazione: (2023)
Dirty-Waters: Detecting Software Supply Chain Smells
di: Liu, Raphina, et al.
Pubblicazione: (2024)
di: Liu, Raphina, et al.
Pubblicazione: (2024)
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
di: Dang, Wenjing, et al.
Pubblicazione: (2025)
di: Dang, Wenjing, et al.
Pubblicazione: (2025)
When Security Meets Usability: An Empirical Investigation of Post-Quantum Cryptography APIs
di: Toruan, Marthin, et al.
Pubblicazione: (2026)
di: Toruan, Marthin, et al.
Pubblicazione: (2026)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
Enterprise Identity Integration for AI-Assisted Developer Services: Architecture, Implementation, and Case Study
di: Chinthareddy, Manideep Reddy
Pubblicazione: (2026)
di: Chinthareddy, Manideep Reddy
Pubblicazione: (2026)
Analysis of Commit Signing on Github
di: Shittu, Abubakar Sadiq, et al.
Pubblicazione: (2026)
di: Shittu, Abubakar Sadiq, et al.
Pubblicazione: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency
di: Joshi, Siddhant S., et al.
Pubblicazione: (2024)
di: Joshi, Siddhant S., et al.
Pubblicazione: (2024)
Evaluating Software Supply Chain Security in Research Software
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
A Study of Malware Prevention in Linux Distributions
di: Vu, Duc-Ly, et al.
Pubblicazione: (2024)
di: Vu, Duc-Ly, et al.
Pubblicazione: (2024)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
di: Maxam III, William P., et al.
Pubblicazione: (2024)
di: Maxam III, William P., et al.
Pubblicazione: (2024)
Towards the Systematic Testing of Regular Expression Engines
di: Çakar, Berk, et al.
Pubblicazione: (2026)
di: Çakar, Berk, et al.
Pubblicazione: (2026)
Software Security in Software-Defined Networking: A Systematic Literature Review
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
An Introduction to Adaptive Software Security
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
TREBLE: Fast Software Updates by Creating an Equilibrium in an Active Software Ecosystem of Globally Distributed Stakeholders
di: Yim, Keun Soo, et al.
Pubblicazione: (2024)
di: Yim, Keun Soo, et al.
Pubblicazione: (2024)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
di: Sharma, Anupam, et al.
Pubblicazione: (2025)
di: Sharma, Anupam, et al.
Pubblicazione: (2025)
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
di: Jiang, Wenxin, et al.
Pubblicazione: (2025)
di: Jiang, Wenxin, et al.
Pubblicazione: (2025)
Identity Control Plane: The Unifying Layer for Zero Trust Infrastructure
di: Avirneni, Surya Teja
Pubblicazione: (2025)
di: Avirneni, Surya Teja
Pubblicazione: (2025)
Visualisation for the CIS benchmark scanning results
di: Zhao, Zhenshuo, et al.
Pubblicazione: (2025)
di: Zhao, Zhenshuo, et al.
Pubblicazione: (2025)
Software Supply Chain Security of Web3
di: Monperrus, Martin
Pubblicazione: (2025)
di: Monperrus, Martin
Pubblicazione: (2025)
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
Documenti analoghi
-
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026) -
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024) -
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025) -
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024) -
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)