Explore the critical importance of API design in securing software's future through this insightful conference talk from OWASP AppSec California 2015. Delve into Timothy D. Morgan's examination of why traditional security training methods fall short and discover innovative approaches to prevent vulnerabilities. Learn about the properties of safe development environments and gain valuable insights into guiding principles for API designers. Understand how well-designed APIs can subtly guide developers towards secure implementations, potentially preventing entire classes of vulnerabilities. Examine real-world examples of both problematic and secure API designs, including discussions on LDAP Filter Injection, ColdFusion, and SQL Injection. Consider the role of standardization in convincing vendors to prioritize API security and explore strategies for building better platforms that inherently promote secure coding practices.
Securing Software's Future: Why API Design Matters