Erez Yalon — The OWASP API Security Project episode artwork

EPISODE · Jan 3, 2020 · 36 MIN

Erez Yalon — The OWASP API Security Project

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data exposure, mass assignment, resource limits, and forgotten API versions. Erez also discusses the project's plans for practical learning materials and ways the community can contribute. This is a guided introduction to the original API Security Top 10, with concrete explanations of the design assumptions behind common failures.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Erez Yalon:→ LinkedIn→ OWASP API Security projectMentioned in this episode:→ OWASP API Security Top 10 — 2019→ OWASP API Security repository→ OWASP crAPIFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction01:35 What an API is05:50 Why API security differs from web security09:25 Rapid change and the API attack surface11:43 Why OWASP started the API Security project14:52 Broken object-level authorization17:22 Broken authentication19:03 Excessive data exposure20:42 Resource and rate limits21:21 Broken function-level authorization23:16 Mass assignment24:55 Injection26:34 Improper assets management27:59 Logging and monitoring30:05 Learning resources and the project roadmap33:30 Contributing to API security

Episode metadata supplied by the publisher feed · Published Jan 3, 2020

Embed this episode

Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Erez Yalon — The OWASP API Security Project

0:00 36:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 3, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!