Главная
Study mode:
on
1
Intro
2
ShipFast Delivery Service
3
Client Complexity Spurs API Growth
4
Ship Raider Shipper's Edge
5
Transport Layer Security
6
Man in the Middle Attack
7
Certificate Pinning
8
Pinning Upkeep
9
Rate Limiting and Load Shedding
10
Behavioral API Security
11
Add Request Signing
12
App Hardening Approaches
13
Calculate Secret at Runtime
14
How They Broke the HMAC
15
OAuth2 Overview
16
Abstract Protocol Flow
17
Outh2 Code Grant Flow
18
OAuth2 Proof of Key Code Exchange (PKCE)
19
Multiple API Services
20
API Proxy Pattern
21
App Integrity Measurement
22
Dynamic Pinning
23
Strengthening OAuth2 Flow
24
Architecture Pattern
25
Conclusion
26
Additional References
Description:
Explore the critical aspects of API security in this 50-minute conference talk from APPSEC Cali 2018. Delve into potential threats arising from undersecured Web APIs and learn techniques to strengthen your API security posture. Gain a clear understanding of user authorization via OAuth2, software authorization using static API keys, and their crucial interplay. Address concerns about mobile API consumers with poorly concealed secrets in statically published code. Discover practical advice and code examples for improving mobile API security, including the implementation of certificate pinning to enhance channel communications. Examine advanced techniques such as app hardening, white box cryptography, and mobile app attestation. Walk away with a comprehensive understanding of the underprotected API problem, immediately applicable tips to enhance your API security, and insights into emerging tools and technologies that enable significant improvements in API protection.

A Tour of API Underprotection

OWASP Foundation
Add to list
0:00 / 0:00