A Password-Storage Field Study with Freelance Developers [pdf]
net.cs.uni-bonn.de
net.cs.uni-bonn.de
> Researchers asked 43 freelance developers to code the user registration for a web app and assessed how they implemented password storage. 26 devs initially chose to leave passwords as plaintext.
> Those devs were then asked to rewrite their code to 'store passwords securely.' Overall here are the methods of password storage chosen by the developers: > 10 - MD5 > 8 - Base64 > 7 - Bcrypt > 5 - SHA-256 > 5 - PBKDF2 > 3 - AES > 3 - 3DES > 1 - SHA-1 > 1 - HMAC/SHA1
> only 3 of 17 participants, who used other hash algorithms, implemented salting. One of them generated a random salt, one made use of the username, and one hard-coded a static salt
As an industry, we (developers) have a long way to go.
Their conclusion states as much (hiring more expensive devs on freelancer.com got them more secure solutions):
"In addition, we found a significant effect in the freelancers’ acceptance rate between the €100 and €200 conditions for the prompted task and examined the effect of different payment levels on secure coding behavior. We saw more secure solutions in the €200 conditions, although the difference was not statistically significant. However, this result might be due to the small sample size and we believe this is worth following up in future work."
(Although I agree that seems likely because of the sample size)
Fiver and freelancer.com has the worst kind of freelancers in my experience.
It's also interesting because 6 used an encryption algorithm, 10 used MD5 which is as good as plaintext nowadays IMO, and 8 used Base64, so even though 24 people thought they "secured it" the passwords are trivial to recover.
Base64... is actually plaintext; that's much, much worse.
I have to wonder how they sourced their developers. I don't think researchers would be motivated to do much more then post a low bidding ad on craigslist, meaning the quality of the developers will be commiserate.
They used 2 tier of payment to see if the payment had an effect on the security of the code.
> Final Study For the final study we recruited freelancers via direct messages. We searched for all freelancers and filtered for the skill “Java.” Unfortunately, Freelancer.com’s search function also returns JavaScript developers or developers where we saw no connection to Java, so we manually pruned out developers whose profile did not include Java skills. Based on our experience in the pre-studies we added two payment levels to our study design (EUR100 and EUR200). We only accepted freelancers’ submissions if they were functional
Literally bcrypt and you're done (for now).
Emphasis added.
If you assume it takes....
- 1hr to apply, negotiate, and accept job
- 1hr to do job
- 1hr to submit and aid in support & integration of code
Then at $200 you're making $66/hr. I'd classify myself as an average developer and most contract work people spam me me with on LinkedIn is in the $150/hr + benefits range.I wonder what kind of quality they'd get with a larger project priced at that range. Something with 15hr of work @ $150 might bring in higher quality freelancers that are closer to the industry average.