EPISODE · Jan 3, 2020 · 36 MIN
Erez Yalon — The OWASP API Security Project
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data exposure, mass assignment, resource limits, and forgotten API versions. Erez also discusses the project's plans for practical learning materials and ways the community can contribute. This is a guided introduction to the original API Security Top 10, with concrete explanations of the design assumptions behind common failures.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Erez Yalon:→ LinkedIn→ OWASP API Security projectMentioned in this episode:→ OWASP API Security Top 10 — 2019→ OWASP API Security repository→ OWASP crAPIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:35 What an API is05:50 Why API security differs from web security09:25 Rapid change and the API attack surface11:43 Why OWASP started the API Security project14:52 Broken object-level authorization17:22 Broken authentication19:03 Excessive data exposure20:42 Resource and rate limits21:21 Broken function-level authorization23:16 Mass assignment24:55 Injection26:34 Improper assets management27:59 Logging and monitoring30:05 Learning resources and the project roadmap33:30 Contributing to API security
Embed this episode
What this episode covers
Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data...
Ready to play
Erez Yalon — The OWASP API Security Project
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.