YoVDO

Common API Security Pitfalls

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Web Security Courses Encryption Courses API Security Courses Input Validation Courses Key Management Courses

Course Description

Overview

Explore common API security pitfalls and best practices in this 31-minute conference talk from OWASP Global AppSec Tel Aviv. Delve into the evolving landscape of API-driven applications, focusing on REST APIs for JavaScript and mobile platforms. Learn to identify critical security features, assess potential vulnerabilities, and implement robust protection measures for your APIs. Discover how to prevent unauthorized access, secure user accounts, and safeguard sensitive data. Gain actionable insights on evaluating API security, addressing root causes of vulnerabilities, and adopting forward-thinking security practices. Benefit from the expertise of Philippe De Ryck, founder of Pragmatic Web Security and Google Developer Expert, as he covers topics including stateless APIs, JSON Web Tokens, encryption, HMAC, asymmetric signatures, key management, cookies vs. tokens, cross-origin requests, and the limitations of input validation.

Syllabus

Intro
Overview
About Philip
API Security Baseline
Stateless API
JSON Web Tokens
Encryption
HMAC
Asymmetric signature
Key management
Cookies vs tokens
Crossorigin requests
Input validation
Dont rely on input validation


Taught by

OWASP Foundation

Related Courses

Internet History, Technology, and Security
University of Michigan via Coursera
Client-Server Communication
Google via Udacity
HTTP & Web Servers
Udacity
Network Security
Georgia Institute of Technology via Udacity
Web Security Fundamentals
KU Leuven University via edX