activity
20212024
most citedThe best laid plans or lack thereof: Security decision-making of different stakeholder groups

21 citations · 24 across the 5 of their papers we have counts for

collaborators

6 papers

cs.SE2024★ 2 cited

Saltzer & Schroeder for 2030: Security engineering principles in a world of AI

Nikhil Patnaik, Joseph Hallett, Awais Rashid

Writing secure code is challenging and so it is expected that, following the release of code-generative AI tools, such as ChatGPT and GitHub Copilot, developers will use these tool…

cs.CR2023

Decisions & Disruptions 2: Decide Harder

Benjamin Shreeve, Joseph Gardiner, Joseph Hallett +2

Cyber incident response is critical to business continuity -- we describe a new exercise that challenges professionals to play the role of Chief Information Security Officer (CISO)…

cs.CR2022★ 1 cited

How darknet market users learned to worry more and love PGP: Analysis of security advice on darknet marketplaces

Andrew C. Dwyer, Joseph Hallett, Claudia Peersman +3

Darknet marketplaces, accessible through, Tor are where users can buy illicit goods, and learn to hide from law enforcement. We surveyed the advice on these markets and found valid…

cs.CR2021

Don't forget your classics: Systematizing 45 years of Ancestry for Security API Usability Recommendations

Nikhil Patnaik, Andrew C. Dwyer, Joseph Hallett +1

Producing secure software is challenging. The poor usability of security APIs makes this even harder. Many recommendations have been proposed to support developers by improving the…

cs.CR2021★ 21 cited

The best laid plans or lack thereof: Security decision-making of different stakeholder groups

Benjamin Shreeve, Joseph Hallett, Matthew Edwards +3

Cyber security requirements are influenced by the priorities and decisions of a range of stakeholders. Board members and CISOs determine strategic priorities. Managers have respons…

cs.CR2021

"Do this! Do that!, And nothing will happen" Do specifications lead to securely stored passwords?

Joseph Hallett, Nikhil Patnaik, Benjamin Shreeve +1

Does the act of writing a specification (how the code should behave) for a piece of security sensitive code lead to developers producing more secure code? We asked 138 developers t…