4 papers
A Multi-Month Study of Git Commit Signing
Abubakar Sadiq Shittu, John Sadik, Scott Ruoti
Git commit signing, introduced in 2012, is one mechanism for establishing commit provenance in software supply chains, yet developer-controlled adoption remains rare and developers…
"Setting up TLS authentication was hell": A Usability Study of Client Certificate Authentication
Abubakar Sadiq Shittu, Clay Shubert, John Sadik +1
"Cryptography turns a security problem into a key management problem." Despite decades of research effort towards usable key management, it remains unclear whether key management i…
Analysis of Commit Signing on Github
Abubakar Sadiq Shittu, John Sadik, Farzin Gholamrezae +1
Securing the open-source software supply chain requires verifying the provenance of every code contribution. While end-to-end (E2E) cryptographic commit signing is widely promoted…
A Large-Scale Survey of Password Entry Practices on Non-Desktop Devices
John Sadik, Scott Ruoti
Password managers encourage users to generate passwords to improve their security. However, research has shown that users avoid generating passwords, often giving the rationale tha…