activity
20182020
most citedSecurity Smells in Android

47 citations · 67 across the 3 of their papers we have counts for

collaborators

12 papers

cs.CR2020

Java Cryptography Uses in the Wild

Mohammadreza Hazhirpasand, Mohammad Ghafari, Oscar Nierstrasz

[Background] Previous research has shown that developers commonly misuse cryptography APIs. [Aim] We have conducted an exploratory study to find out how crypto APIs are used in ope…

cs.SE202020 cited

Why Research on Test-Driven Development is Inconclusive?

Mohammad Ghafari, Timm Gross, Davide Fucci +1

[Background] Recent investigations into the effects of Test-Driven Development (TDD) have been contradictory and inconclusive. This hinders development teams to use research result…

cs.CR202047 cited

Security Smells in Android

Mohammad Ghafari, Pascal Gadient, Oscar Nierstrasz

The ubiquity of smartphones, and their very broad capabilities and usage, make the security of these devices tremendously important. Unfortunately, despite all progress in security…

cs.CR2020

Tricking Johnny into Granting Web Permissions

Mohammadreza Hazhirpasand, Mohammad Ghafari, Oscar Nierstrasz

We studied the web permission API dialog box in popular mobile and desktop browsers, and found that it typically lacks measures to protect users from unwittingly granting web permi…

cs.SE2020

Caveats in Eliciting Mobile App Requirements

Nitish Patkar, Mohammad Ghafari, Oscar Nierstrasz +1

Factors such as app stores or platform choices heavily affect functional and non-functional mobile app requirements. We surveyed 45 companies and interviewed ten experts to explore…

cs.SE2020

CryptoExplorer: An Interactive Web Platform Supporting Secure Use of Cryptography APIs

Mohammadreza Hazhirpasand, Mohammad Ghafari, Oscar Nierstrasz

Research has shown that cryptographic APIs are hard to use. Consequently, developers resort to using code examples available in online information sources that are often not secure…