Главная
Study mode:
on
1
Intro
2
Overview
3
Snapchat
4
HackerOne
5
What is the problem
6
Thirdparty apps
7
Example
8
Risks
9
Spam and Abuse
10
ThirdParty App Abuse
11
Solution 1 Server Side Only
12
Establish a Baseline
13
Press
14
Mobile notifications
15
iOS notifications
16
Serverside analysis
17
Handling abuse
18
Android ID token
19
Android ID token abuse
20
Android Safety Net
21
pitfalls of code obfuscation
22
Current challenge
23
New twist
24
More abuse
25
Hiring
Description:
Explore Snapchat's defensive strategies against unauthorized third-party API access in this 53-minute conference talk from AppSec California 2016. Delve into the challenges faced by Snapchat in protecting user data from potential breaches and account compromises. Learn about the various client-side and server-side defenses implemented by the company in response to determined third-party attempts to reverse-engineer their protocol. Gain insights into the successes, failures, and lessons learned from Snapchat's unique approach to user protection in the social networking space. Discover the ongoing cat-and-mouse game between Snapchat and third-party developers, and understand the complexities of maintaining user security in a landscape of evolving threats. Presented by Jad Boutros, Director of Information Security at Snapchat, this talk covers topics such as establishing baselines, handling abuse, implementing Android ID tokens and Safety Net, and the pitfalls of code obfuscation.

All Our APIs Are Belong to Us

OWASP Foundation
Add to list
0:00 / 0:00