From Bother to Benefit: Engaging Student Developers in Cybersecurity and Privacy Practices
From Bother to Benefit: Engaging Student Developers in Cybersecurity and Privacy Practices
Wednesday, May 21, 2025 | 9:45AM–10:30AM ET | Grand Ballroom Foyer, 3rd Floor
Session Type:
Poster
Delivery Format:
Poster Session
How can we get student developers and higher ed IT on the same page—without buying additional software? How can we address the security concerns of higher ed and still allow students to contribute to the institution’s digital ecosystem? Student developers are eager to build software tools that “fill the gaps” or enhance the usability of official university platforms. The goal is often to ship tools quickly and address privacy and security concerns after launch. That’s why the default choice for institutions is to push back and even shut down student projects. Instead, based on experiences with student developers at Yale University, we propose a framework for students and institutions to collaborate and preserve institutional privacy and security goals. Our framework centers around a real-world scenario: a student-built club directory app was released to the student body via email. The app had security flaws such as well-known OWASP vulnerabilities. The app also scraped several internal platforms and by-default shared this information publicly. Using our approach, students and the institution alike worked to secure the app and reduce information disclosures to an acceptable level. This approach can be translated to other student-built applications without burdening privacy and security teams into full-time app review duty.