Главная
Study mode:
on
1
Intro
2
A10 Underprotected APIs
3
OVER-EXPOSING API DATA
4
LACK OF PROPER AUTHORIZATION
5
FAILURE TO AUDIT THE AUTHORIZATION POLICY
6
MISHANDLING CLIENT-SIDE SESSION DATA
7
MISTAKING JWTS FOR SESSIONS
8
LACK OF PROPER JWT KEY MANAGEMENT
9
Cookie: ID=42
10
UNDERESTIMATING THE IMPACT OF SESSION TRANSPORT
11
FAILURE TO COMPARTMENTALIZE
Description:
Explore common API security pitfalls and best practices in this 53-minute conference talk by Philippe De Ryck. Delve into the evolution of API landscapes and the challenges of protecting access to REST APIs in JavaScript and mobile applications. Learn about crucial security features, potential vulnerabilities, and actionable advice to address security problems. Discover how to assess API security, implement best practices, and improve future implementations. Cover topics such as underprotected APIs, over-exposed data, authorization failures, client-side session data mishandling, JWT key management issues, and the importance of compartmentalization. Gain valuable insights to enhance the security of your APIs and prevent unauthorized access to user accounts and sensitive data.

Common API Security Pitfalls

NDC Conferences
Add to list
0:00 / 0:00