
Erez Yalon — The OWASP API Security Project
Om avsnittet
Why did APIs need a security Top 10 of their own? Erez Yalon joins Chris and Robert to explain the gaps that led to the OWASP API Security project and walk through its original 2019 list. He contrasts traditional web applications with APIs serving many kinds of clients, where authorization decisions and exposed data can become especially difficult to control. The conversation distinguishes broken object-level authorization from broken function-level authorization, then examines excessive data exposure, mass assignment, resource limits, and forgotten API versions. Erez also discusses the project's plans for practical learning materials and ways the community can contribute. This is a guided introduction to the original API Security Top 10, with concrete explanations of the design assumptions behind common failures.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Erez Yalon:
→ LinkedIn
→ OWASP API Security project
Mentioned in this episode:
→ OWASP API Security Top 10 — 2019
→ OWASP API Security repository
→ OWASP crAPI
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Introduction
01:35 What an API is
05:50 Why API security differs from web security
09:25 Rapid change and the API attack surface
11:43 Why OWASP started the API Security project
14:52 Broken object-level authorization
17:22 Broken authentication
19:03 Excessive data exposure
20:42 Resource and rate limits
21:21 Broken function-level authorization
23:16 Mass assignment
24:55 Injection
26:34 Improper assets management
27:59 Logging and monitoring
30:05 Learning resources and the project roadmap
33:30 Contributing to API security
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.