VLDB 2026 Research / reviewers in the wild / expert
Charles Weir
dblp:09/7865
· DBLP profile ↗
7ranked-venue papers
6as first author
3since 2021 · last 2025
0000-0003-3051-4195ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 first-author · 2 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The human factor: Addressing computing risks for critical national infrastructure towards 2040abstractThe authors conducted a UK-based future study employing the Delphi method to explore the impact of emerging computing technologies on Critical National Infrastructure (CNI). The study engaged 22 domain experts specializing in software, cybersecurity , and CNI, whose roles all include forecasting technological trends and challenges. The findings propose making Internet Services a CNI sector, and suggested the weightiest concern to be human-centric challenges around the recovery from software disasters and cyberattacks. Other major concerns also related to human factors, such as attacks via operators, and errors stemming from poorly designed human-computer interfaces. The suggested mitigation strategies therefore concentrate on human-centred approaches. Key recommendations include promoting human-focused cyber resilience , and using legislation, regulation and standards to help establish it in CNI organizations. Charles Weir, Cecilia Loureiro-Koechlin, Lucy Hunt, Louise A. Dennis |
Comput. Secur. | 1 |
| 2023 | Incorporating software security: using developer workshops to engage product managersabstractAbstract Evidence from data breach reports shows that many competent software development teams still do not implement secure, privacy-preserving software, even though techniques to do so are now well-known. A major factor causing this is simply a lack of priority and resources for security, as decided by product managers. So, how can we help developers and product managers to work together to achieve appropriate decisions on security and privacy issues? This paper explores using structured workshops to support teams of developers in engaging product managers with software security and privacy, even in the absence of security professionals. The research used the Design Based Research methodology. This paper describes and justifies our workshop design and implementation, and describes our thematic coding of both participant interviews and workshop discussions to quantify and explore the workshops’ effectiveness. Based on trials in eight organizations, involving 88 developers, we found the workshops effective in helping development teams to identify, promote, and prioritize security issues with product managers. Comparisons between organizations suggested that such workshops are most effective with groups with limited security expertise, and when led by the development team leaders. We also found workshop participants needed minimal guidance to identify security threats, and a wide range of ways to promote possible security improvements. Empowering developers and product managers in this way offers a powerful grassroots approach to improve software security worldwide. Charles Weir, Ingolf Becker, Lynne Blair |
Empir. Softw. Eng. | 1 |
| 2021 | Infiltrating security into development: exploring the world's largest software security studyabstractRecent years have seen rapid increases in cybercrime. The use of effective software security activities plays an important part in preventing the harm involved. Objective research on industry use of software security practices is needed to help development teams, academic researchers, and educators to focus their activities. Charles Weir, Samuel Migues, Mike Ware, Laurie A. Williams |
ESEC/SIGSOFT FSE | 1 |
| 2020 | From Needs to Actions to Secure Apps? The Effect of Requirements and Developer Practices on App Security
Charles Weir, Ben Hermann, Sascha Fahl |
USENIX Security Symposium | 1 |
| 2020 | Interventions for long-term software security: Creating a lightweight program of assurance techniques for developersabstractSummary Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and awareness of assurance techniques, changing its security culture even when no security experts are involved. The interventions were developed after an Appreciative Inquiry and Grounded Theory survey of security professionals to find out what approaches work best. We tested the interventions in a participatory action research field study where we delivered the workshops to three software development organizations and evaluated their effectiveness through interviews beforehand, immediately afterwards, and after twelve months. We found that the interventions can be effective with teams with limited or no security experience and that improvement is long‐lasting. This approach and the learning points arising from the work here have the potential to be applied in many development teams, improving the security of software worldwide. Charles Weir, Ingolf Becker, James Noble 0001, Lynne Blair, M. Angela Sasse, Awais Rashid |
Softw. Pract. Exp. | 1 |
| 2017 | A Stitch in Time: Supporting Android Developers in WritingSecure CodeabstractDespite security advice in the official documentation and an extensive body of security research about vulnerabilities and exploits, many developers still fail to write secure Android applications. Frequently, Android developers fail to adhere to security best practices, leaving applications vulnerable to a multitude of attacks. We point out the advantage of a low-time-cost tool both to teach better secure coding and to improve app security. Using the FixDroid IDE plug-in, we show that professional and hobby app developers can work with and learn from an in-environment tool without it impacting their normal work; and by performing studies with both students and professional developers, we identify key UI requirements and demonstrate that code delivered with such a tool by developers previously inexperienced in security contains significantly less security problems. Perfecting and adding such tools to the Android development environment is an essential step in getting both security and privacy for the next generation of apps. Duc Cuong Nguyen 0001, Dominik Wermke, Yasemin Acar, Michael Backes 0001, Charles Weir, Sascha Fahl |
CCS | 5 |
| 2016 | Reaching the masses: a new subdiscipline of app programmer educationabstractProgrammers’ lack of knowledge and interest in secure development threatens everyone who uses mobile apps. The rise of apps has engaged millions of independent app developers, who rarely encounter any but low level security techniques. But what if software security were presented as a game, or a story, or a discussion? What if learning app security techniques could be fun as well as empowering? Only by introducing the powerful motivating techniques developed for other disciplines can we hope to upskill independent app developers, and achieve the security that we’ll need in 2025 to safeguard our identities and our data. Charles Weir, Awais Rashid, James Noble 0001 |
SIGSOFT FSE | 1 |