Security is Key: The Vulnerabilities of API Security

No ratings

Presented at Bsides London 2023 by

APIs are one of the most popular development tools used today, so it is no surprise they have become a significant target for threat actors. Supported by API development tools and platforms, developers can now easily make and share APIs with others in the community. This talk will explore the core security issues facing the API security landscape, including how, through common vulnerabilities, APIs can be misused. I will also show how not only are traditional vulnerabilities an issue, but also the attitude towards security of APIs. This will be explored through my personal experience, having found a series of exposed keys on a global API development platform. I will discuss how I found these leaked API keys, and how through communication with the company themselves, extra protection measures were put in place to ensure the security of the API development community.