Talking Security: Why Storytelling and Values Outperform Checklists for Developers
2019 IEEE/ACM Joint 7th International Workshop on Conducting Empirical Studies in Industry (CESI) and 6th International Workshop on Software Engineering Research and Industrial Practice (SER&IP)
This paper presents a novel engagement framework called the "Motivating Jenny" project, which uses a reflection and discussion tool based on real-world security stories to involve professional developers in security discourse. The method leverages ethnographic studies and "Value Cards" to bridge the gap between technical security knowledge and daily development practices.
TL;DR
Why do developers ignore security best practices despite knowing the risks? This paper argues that the problem isn't a lack of information, but a lack of motivation. By using real-world security "war stories" and a deck of "Value Cards," the researchers created a workshop format that effectively engages non-security specialists in meaningful security discourse, turning security from a chore into a core professional value.
Problem & Motivation: The Gap Between Knowledge and Action
In the software world, there is a frustrating paradox: we have more security tools and documentation than ever, yet breaches caused by preventable coding errors remain common. The authors of "Talking about Security with Professional Developers" suggest that security is often viewed as "codified knowledge"—something developers feel they should know, but which feels disconnected from their daily reality.
The motivation behind the "Motivating Jenny" project is to treat security not as a technical hurdle, but as a social and cultural practice. For many developers, security feels like an external imposition that slows them down. To fix this, we need to understand the "insider perspective" and shift the narrative from fear and compliance to personal values and professional pride.
Methodology: The Power of Perspective and Play
The core of the research is a 90-minute workshop structured to encourage "naturalistic" interaction. The intervention relies on two key components:
1. The Dual-Perspective Narrative
The workshop uses the HandBrake compromise of 2017 as a case study.
- Part 1 presents the incident through cold, technical media reports.
- Part 2 presents the same incident but through the eyes of a developer at Panic Software who was personally affected.
This shift is crucial. It moves the conversation from "How did the company fail?" to "How would I feel if this happened to me?"
2. Value Cards: Mapping Security to Ethics
To guide the discussion, developers are given "Value Cards" containing terms like Autonomy, Trust, and Accountability.
Fig 1. Physical workshop materials including incident reports and prompting cards.
By asking developers to discuss how these values were impacted by the HandBrake breach, the workshop bypasses the "judgmental" tone often found in security audits. Instead of being told they are doing it wrong, developers explore what they care about as professionals.
Field Results: Turning Silence into "Code Talk"
The researchers tested this at a practitioner conference and an industrial field site. The results were telling:
- Engagement: Developers were highly participatory, noting that the developer-centered story was "close enough to experience to engage, but far enough to not inhibit."
- Information Trading: In the process of debating the stories, developers began naturally sharing "war stories" and technical "hacks," effectively facilitating peer-to-peer security learning.
Fig 2. Developers participating in the collaborative reflection activity.
| Value | Description | Impact on Security |
|---|---|---|
| Trust | Reliability of social interactions. | High: Security breaches destroy user trust. |
| Accountability | Actions can be uniquely traced. | Critical for post-incident forensics. |
| Self-direction | Freedom to cultivate ideas. | Developers want security that doesn't limit creativity. |
Deep Insight: Security as a Quality to be Striven For
The most profound takeaway is that security should be positioned as a quality of craftsmanship. When developers talk about "code talk," they are discussing values. By framing security within the context of Human Welfare or Face (Public Image), it becomes a point of professional honor.
Limitations & Future Work
While the workshop was a success, the authors acknowledge that it is currently a "reflection tool" rather than a quantitative fix. Future work involves refining the "Value Cards" to more specifically match developer motivations (e.g., Stimulation, Achievement) and conducting formal longitudinal evaluations to see if these "talks" actually lead to fewer vulnerabilities in the codebase.
Conclusion
If your team is suffering from "security fatigue," the answer might not be another automated scanner. It might be a 90-minute conversation. By moving the focus from what is broken to who it affects and why it matters, the Motivating Jenny project provides a blueprint for building a more resilient, security-conscious development culture.
