Explore the human factors influencing secure code development in this 35-minute LASCON conference talk. Delve into research findings on developer experience, team dynamics, and environmental characteristics affecting software security. Discover how disrupted attention, team size, co-location, communication, work hours, and code rewrites impact the introduction of security weaknesses. Learn about DoD-funded R&D conducted on open-source and proprietary software repositories, as well as academic research on software engineering practices. Gain insights into psychological and environmental factors, research methodologies, and lessons from non-software domains. Examine concepts like the bystander effect, interactive churn, and the "Dirty Dozen" of human factors. Understand the implications for quality versus security in software development and explore opportunities to participate in ongoing research on secure coding practices.
Do Certain Types of Developers or Teams Write More Secure Code?