3 papers
cs.CR2026
A Multi-Month Study of Git Commit Signing
Abubakar Sadiq Shittu, John Sadik, Scott Ruoti
Git commit signing, introduced in 2012, is one mechanism for establishing commit provenance in software supply chains, yet developer-controlled adoption remains rare and developers…
cs.CR2026
"Setting up TLS authentication was hell": A Usability Study of Client Certificate Authentication
Abubakar Sadiq Shittu, Clay Shubert, John Sadik +1
"Cryptography turns a security problem into a key management problem." Despite decades of research effort towards usable key management, it remains unclear whether key management i…
cs.SE2026
Analysis of Commit Signing on Github
Abubakar Sadiq Shittu, John Sadik, Farzin Gholamrezae +1
Securing the open-source software supply chain requires verifying the provenance of every code contribution. While end-to-end (E2E) cryptographic commit signing is widely promoted…