SEVEN things about API security By Philippe De Ryck

Поделиться
HTML-код
  • Опубликовано: 26 авг 2024
  • APIs are everywhere, but API security is a disaster. Stories of API security breaches seem to be just another news cycle away, shining a harsh spotlight on the ease of API abuse and the complexities of robust API security.
    In this session, we use real-world cases to dive into best practices for securing your APIs. We dive into FOUR crucial vulnerabilities highlighted in the OWASP API Security top 10, exposing the areas you need to safeguard against. But we don't stop there. We also bring the threats to life with ONE demo, providing a practical look at how these vulnerabilities can be exploited. Lastly, we'll discuss TWO real-world case studies, where you'll see how even high-profile organizations can fall victim to these weaknesses. At the end of this session, you will have an actionable set of guidelines to assess and improve the security of your own APIs.
    PHILIPPE DE RYCK
    Philippe De Ryck helps developers protect companies through better web security. His Ph.D. in web security from KU Leuven lies at the basis of his exceptional knowledge of the security landscape. As the founder of Pragmatic Web Security, Philippe delivers security training and security consulting to companies worldwide. His online course platform allows anyone to learn complex security topics at their own pace. Philippe is a Google Developer Expert and an Auth0 Ambassador for his community contributions on the security of web applications and APIs.

Комментарии • 4

  • @Riya-zj2mk
    @Riya-zj2mk 3 месяца назад

    Amazing presentation.

  • @lxn7404
    @lxn7404 6 месяцев назад +1

    Outstanding presentation

  • @Tony-dp1rl
    @Tony-dp1rl 10 месяцев назад

    32:20 The section on measuring timing for a valid email address is kinda contrived. Email addresses are not secrets, and most corporations follow simple naming standards for their email accounts.

  • @vrjb100
    @vrjb100 7 месяцев назад +3

    Less than 1000 views, developers are not interested in security, that's the main cause.