Talking Security: Why Storytelling and Values Outperform Checklists for Developers

2019 IEEE/ACM Joint 7th International Workshop on Conducting Empirical Studies in Industry (CESI) and 6th International Workshop on Software Engineering Research and Industrial Practice (SER&IP)

2019-05-01
Summary
Problem
Method
Results
Takeaways
Abstract

This paper presents a novel engagement framework called the "Motivating Jenny" project, which uses a reflection and discussion tool based on real-world security stories to involve professional developers in security discourse. The method leverages ethnographic studies and "Value Cards" to bridge the gap between technical security knowledge and daily development practices.

TL;DR

Why do developers ignore security best practices despite knowing the risks? This paper argues that the problem isn't a lack of information, but a lack of motivation. By using real-world security "war stories" and a deck of "Value Cards," the researchers created a workshop format that effectively engages non-security specialists in meaningful security discourse, turning security from a chore into a core professional value.

Problem & Motivation: The Gap Between Knowledge and Action

In the software world, there is a frustrating paradox: we have more security tools and documentation than ever, yet breaches caused by preventable coding errors remain common. The authors of "Talking about Security with Professional Developers" suggest that security is often viewed as "codified knowledge"—something developers feel they should know, but which feels disconnected from their daily reality.

The motivation behind the "Motivating Jenny" project is to treat security not as a technical hurdle, but as a social and cultural practice. For many developers, security feels like an external imposition that slows them down. To fix this, we need to understand the "insider perspective" and shift the narrative from fear and compliance to personal values and professional pride.

Methodology: The Power of Perspective and Play

The core of the research is a 90-minute workshop structured to encourage "naturalistic" interaction. The intervention relies on two key components:

1. The Dual-Perspective Narrative

The workshop uses the HandBrake compromise of 2017 as a case study.

  • Part 1 presents the incident through cold, technical media reports.
  • Part 2 presents the same incident but through the eyes of a developer at Panic Software who was personally affected.

This shift is crucial. It moves the conversation from "How did the company fail?" to "How would I feel if this happened to me?"

2. Value Cards: Mapping Security to Ethics

To guide the discussion, developers are given "Value Cards" containing terms like Autonomy, Trust, and Accountability.

Stories and Cards Fig 1. Physical workshop materials including incident reports and prompting cards.

By asking developers to discuss how these values were impacted by the HandBrake breach, the workshop bypasses the "judgmental" tone often found in security audits. Instead of being told they are doing it wrong, developers explore what they care about as professionals.

Field Results: Turning Silence into "Code Talk"

The researchers tested this at a practitioner conference and an industrial field site. The results were telling:

  • Engagement: Developers were highly participatory, noting that the developer-centered story was "close enough to experience to engage, but far enough to not inhibit."
  • Information Trading: In the process of debating the stories, developers began naturally sharing "war stories" and technical "hacks," effectively facilitating peer-to-peer security learning.

Group Work Fig 2. Developers participating in the collaborative reflection activity.

ValueDescriptionImpact on Security
TrustReliability of social interactions.High: Security breaches destroy user trust.
AccountabilityActions can be uniquely traced.Critical for post-incident forensics.
Self-directionFreedom to cultivate ideas.Developers want security that doesn't limit creativity.

Deep Insight: Security as a Quality to be Striven For

The most profound takeaway is that security should be positioned as a quality of craftsmanship. When developers talk about "code talk," they are discussing values. By framing security within the context of Human Welfare or Face (Public Image), it becomes a point of professional honor.

Limitations & Future Work

While the workshop was a success, the authors acknowledge that it is currently a "reflection tool" rather than a quantitative fix. Future work involves refining the "Value Cards" to more specifically match developer motivations (e.g., Stimulation, Achievement) and conducting formal longitudinal evaluations to see if these "talks" actually lead to fewer vulnerabilities in the codebase.

Conclusion

If your team is suffering from "security fatigue," the answer might not be another automated scanner. It might be a 90-minute conversation. By moving the focus from what is broken to who it affects and why it matters, the Motivating Jenny project provides a blueprint for building a more resilient, security-conscious development culture.

Find Similar Papers

Try Our Examples

  • Search for recent studies on how developer motivation and organizational culture impact the adoption of DevSecOps practices.
  • What are the seminal papers on Value-Sensitive Design (VSD) in software engineering, and how have they been applied to cybersecurity?
  • Explore longitudinal research that measures the effectiveness of "serious games" versus traditional training for improving long-term secure coding behaviors.
Contents
Talking Security: Why Storytelling and Values Outperform Checklists for Developers
1. TL;DR
2. Problem & Motivation: The Gap Between Knowledge and Action
3. Methodology: The Power of Perspective and Play
3.1. 1. The Dual-Perspective Narrative
3.2. 2. Value Cards: Mapping Security to Ethics
4. Field Results: Turning Silence into "Code Talk"
5. Deep Insight: Security as a Quality to be Striven For
5.1. Limitations & Future Work
6. Conclusion