avatarDr Mehmet Yildiz

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

5721

Abstract

illion-user-profiles-have-been-leaked/"> this article on CPO Magazine </a>pointed out that “Hot on the heels of high-profile data scraping incidents at Facebook and LinkedIn that compromised hundreds of millions of accounts, the personal information of about <b>1.3 million users of social media darling Clubhouse has been found posted to a hacker forum</b>.”</p><p id="858b">According to <a href="https://www.vice.com/en/article/4avy8j/bugs-allowed-hackers-to-dox-all-john-deere-owners">this report on Vice</a>, a security researcher found two bugs that allowed him to find customers who had purchased John Deere tractors or equipment. However, there was no evidence that hackers exploited these flaws. These bugs could have doxed John Deere Tractor Owners</p><p id="3028">There are many more eye-opening examples in the security news. I assume you understand the magnitude of issues at the global scale. What can we do? Understanding risks, vulnerabilities, and issues are critical.</p><h1 id="8398">Understanding API Risks and Vulnerabilities</h1><p id="3a33"><a href="https://owasp.org/">The Open Web Application Security Project</a>® (OWASP) “is a nonprofit foundation that works to improve software security. Through community-led open-source software projects, hundreds of local chapters worldwide, <b>tens of thousands of members,</b> and leading educational and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web.”</p><p id="2218">Here are the top 10 API risks as identified by <a href="https://owasp.org/www-project-api-security/">the OWASP Foundation</a>.</p><blockquote id="2486"><p>Broken Object Level Authorization</p></blockquote><blockquote id="5781"><p>Broken User Authentication</p></blockquote><blockquote id="6a42"><p>Excessive Data Exposure</p></blockquote><blockquote id="1de4"><p>Lack of Resources and Rate Limiting</p></blockquote><blockquote id="bdc9"><p>Broken Function Level Authorization</p></blockquote><blockquote id="5547"><p>Mass Assignment</p></blockquote><blockquote id="7e35"><p>Security Misconfiguration</p></blockquote><blockquote id="f168"><p>Injection</p></blockquote><blockquote id="1b98"><p>Improper Assets Management</p></blockquote><blockquote id="cb31"><p>Insufficient Logging and Monitoring</p></blockquote><p id="291f">You can download this comprehensive and valuable document <a href="https://raw.githubusercontent.com/OWASP/API-Security/master/2019/en/dist/owasp-api-security-top-10.pdf">at this link</a> free of charge. I also highly recommend <a href="https://api.gov.au/standards/national_api_standards/api-security.html">a review of this resource related to API security</a> by the Australian Government. This resource points out that “applying the right level of security will allow your APIs to perform well without compromising on the security risk.”</p><p id="a2d4">In a nutshell, let’s keep in mind that APIs not only expose critical user information but also application data, logic, and more importantly increase attack surfaces for hackers.</p><p id="738d">So, in addition to using <a href="https://owasp.org/www-community/Vulnerability_Scanning_Tools">vulnerability scanning tools </a>(cross-site scripting, SQL injection, command injection, path traversal and insecure server configuration) as pointed out by OWASP, we can also leverage API security gateways. These secure gateways allows us to restrict access to the use of APIs by establishing rules on how data requests must be handled.</p><h1 id="a270">Conclusions</h1><p id="6289">APIs are critical and innovative tools for service providers, consumers, and partners. Without APIs, we cannot enjoy and benefit from the richness of online information. In addition, business organizations depend on APIs to disseminate information timely to their consumers. They also need to use APIs to collaborate with partners.</p><p id="7dea">However, our personally identifiable information is critical for safety, security, and privacy. This type of information is sought after by hackers for various purposes. The key goal is to protect this information with rigor. Technology is a double-edged sword.</p><p id="8e9f">Technical precautions are only one aspect of essential measures. In addition, policies, processes, and procedures by business decisions makers are critical. Cybersecurity is not a joke. I shared my insights about the implications of ransomware on our economy and well-being <a href="https://readmedium.com/lessons-from-fbis-recovery-of-colonial-pipeline-s-darkside-bitcoins-for-ransomware-attacks-eeb950f8ce62">in this article</a>.</p><p id="8c20">For example, privacy governance schemes such as GDPR in Europe, the Cybersecurity 202 in the US, and the Australia Privacy Act are essential for businesses to use in their practice. You can find other countries with GDPR-like data privacy laws <a href="https://insights.comforte.com/13-countries-with-gdpr-like-data-privacy-laws">at this link.</a></p><p id="50a4">With the emergence of <a href="https://readmedium.com/artificial-intelligence-does-not-concern-me-but-artificial-super-intelligence-frightens-me-e5354737d119">artificial super-intelligence systems</a>, we must consider the risks factors posed by APIs for protecting our personally identifiable information. Misuse of deep <a href="https://readmedium.com/time-to-re-examine-deep-fake-technologies-with-firmer-measures-c20747c58f32">fake technologies </a>was a wake-up call for society. <a href="https://readmedium.com/11-emerging-futuristic-technologies-for-global-economy-personal-investment-632e1fc371ba">These eleven emerging technologies </a>make it of paramount importance for considering APIs and protecting our private inf

Options

ormation.</p><p id="3ea1">Thank you for reading my perspectives.</p><div id="c022" class="link-block"> <a href="https://readmedium.com/artificial-intelligence-does-not-concern-me-but-artificial-super-intelligence-frightens-me-e5354737d119"> <div> <div> <h2>Artificial Intelligence Does Not Concern Me, but Artificial Super-Intelligence Frightens Me</h2> <div><h3>Perhaps it is time to move our heads from the desert sands and see the lurking reality in the dark side</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*Ta2aNByRehue7oBDdGqA0g.jpeg)"></div> </div> </div> </a> </div><div id="8cf3" class="link-block"> <a href="https://readmedium.com/11-emerging-futuristic-technologies-for-global-economy-personal-investment-632e1fc371ba"> <div> <div> <h2>Eleven Emerging & Futuristic Technologies for the Global Economy & Personal Investment</h2> <div><h3>Compelling technology values and use cases that positively transform business, the economy, digital intelligence, and…</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*HPqDT2KoysunjN5BnzTxxA.jpeg)"></div> </div> </div> </a> </div><div id="9c17" class="link-block"> <a href="https://readmedium.com/time-to-re-examine-deep-fake-technologies-with-firmer-measures-c20747c58f32"> <div> <div> <h2>Time to Re-Examine Deep Fake Technologies with Firmer Measures</h2> <div><h3>A viewpoint & informed approach to deal with a double-edged sword posing critical risks for individuals & society.</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*ZrnLm4xFESBC4A_V2teo9w.jpeg)"></div> </div> </div> </a> </div><p id="e24a">Here is a valuable and short video shedding lights on API security. The video provides insights from Stan Wisseman, Chief Security Strategist at Micro Focus Fortify.</p> <figure id="4550"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FCpr7oUMLrrM%3Ffeature%3Doembed&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DCpr7oUMLrrM&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FCpr7oUMLrrM%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="854"> </div> </div> </figure></iframe></div></div></figure><h1 id="5ab0">About the Author</h1><p id="cfd5">I am a technologist, postdoctoral researcher, author of several books, editor, and digital marketing strategist with four decades of industry experience.</p><p id="4e5e">I write articles on <a href="https://dr-mehmet-yildiz.medium.com/">Medium</a>, <a href="https://original.newsbreak.com/@digitalintelligence-561548">NewsBreak,</a> and <a href="https://vocal.media/authors/dr-mehmet-yildiz">Vocal Media</a>. On Medium, I established <a href="https://medium.com/illumination">ILLUMINATION</a>, I<a href="https://medium.com/illumination-curated">LLUMINATION-Curated</a>, <a href="https://medium.com/illuminations-mirror">ILLUMINATION’ S MIRROR</a><a href="https://medium.com/technology-hits">,</a> <a href="https://medium.com/illumination-book-chapters">ILLUMINATION Book Chapters</a>, <a href="https://medium.com/technology-hits">Technology Hits</a>, <a href="https://medium.com/technical-excellence">SYNERGY</a>, and <a href="https://medium.com/readers-digests">Readers Hope</a> publications supporting 12,000+ writers on Medium. You can j<a href="https://digitalmehmet.com/contact/">oin my publications requesting access here</a>. You may <a href="https://dr-mehmet-yildiz.medium.com/subscribe">subscribe to my account</a> to be notified when I post on Medium. I share my health and well-being stories on my publication, <a href="https://medium.com/sensible-biohacking-transhumanism">Euphoria.</a></p><p id="43df">If you are new to Medium, you may join <a href="https://dr-mehmet-yildiz.medium.com/membership">by following this link.</a> A small part of your membership fee will not only support my writing but your reading times can support many great writers on this platform. Opportunities for readers and writers are endless on this platform.</p><div id="9405" class="link-block"> <a href="https://readmedium.com/heath-fitness-lifestyle-topics-collected-on-transhumanism-leadership-a22f1d4f7de1"> <div> <div> <h2>Heath, Fitness, & Lifestyle Topics Collected on Euphoria</h2> <div><h3>Eclectic articles addressing interesting and important life matters for individuals and society</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*CvOJVRajvZBcp3-0rXHwcw.jpeg)"></div> </div> </div> </a> </div></article></body>

Cybersecurity, Privacy, and APIs

Mitigating Security Risks of APIs for Business Organizations

Our personally identifiable information matters and cybersecurity is not a joke.

Photo by Tima Miroshnichenko from Pexels

Introduction

APIs are fantastic, critical, and innovative tools for service providers, consumers, and partners. They are a vital part of mobile, Cloud, IoT, and web applications enriching internal applications, consumer-facing, and partner-facing services. Without APIs, we cannot produce and scale innovative solutions rapidly.

However, according to a recent investigation, 44% of enterprises face security risks related to the use of APIs (Application Programming Interfaces). This is a significant issue. APIs are critical for digital transformation, participating in digital ecosystems, and the global economy.

In this post, I introduce APIs and what we can do to reduce security risks without compromising functionality. Performance and security go hand in hand. We need both to survive and thrive in our businesses. The key issue with APIs relates to the concept of Personally Identifiable Information (PII). This type of information is the bread and butter of hackers.

The State of API Economy 2021 report (in a downloadable e-book format) by Google “explains why APIs are central to organizations’ needs and digital transformation efforts. This report is based on Google Cloud’s Apigee API Management Platform usage data, customer case studies, and analysis of several third-party surveys conducted with technology leaders from enterprises with 1,500 or more employees across the United States, United Kingdom, Germany, France, South Korea, Indonesia, Australia, and New Zealand.”

According to this Google report, 58% of global enterprise IT decision-makers found APIs expedited new application development. Additionally, 53% of respondents found APIs vital to building more effective products and creating digital experiences.

Common Security Concerns Related to APIs

There is much disappointing news related to the misuse of APIs and their consequences on consumers. Probably you read this news piece published last April titled Experian API Exposed Credit Scores of Most Americans.

As mentioned in the report, “Big-three consumer credit bureau Experian just fixed a weakness with a partner website that let anyone look up the credit score of tens of millions of Americans just by supplying their name and mailing address, KrebsOnSecurity has learned. Experian says it has plugged the data leak, but the researcher who reported the finding says he fears the same weakness may be present at countless other lending websites that work with the credit bureau.”

As this report titled “Experian’s Credit Freeze Security is Still a Joke” mentions “Dune Thomas is a software engineer from Sacramento, who put a freeze on his credit files last year at Experian, Equifax and TransUnion after thieves tried to open multiple new payment accounts in his name using an address in Washington state that was tied to a vacant home for sale.”

Another example that we heard in the news earlier this year was related to Facebook APIs. Bot Lets Hackers Easily Look Up Facebook Users’ Phone Numbers: The person selling access to the service claims it has data on 500 million Facebook users. This breach involved the use of an API that the developers did not intend. The vulnerability was exploited by hackers feeding phone numbers into the API.

This news on the Security Magazine informed us that “Peloton’s leaky API has allowed any hacker to obtain any user’s account data — even if that user had set their profile to private. The vulnerability, which security research firm Pen Test Partners discovered, allowed requests to go through for Peloton user account data without checking to make sure the request was authenticated. As a result, the exposed API could let anyone access any Peloton user’s age, gender, city, weight, workout stats, and birthday.”

Several platforms were affected by web-scraping making APIs vulnerable. For example, this article on CPO Magazine pointed out that “Hot on the heels of high-profile data scraping incidents at Facebook and LinkedIn that compromised hundreds of millions of accounts, the personal information of about 1.3 million users of social media darling Clubhouse has been found posted to a hacker forum.”

According to this report on Vice, a security researcher found two bugs that allowed him to find customers who had purchased John Deere tractors or equipment. However, there was no evidence that hackers exploited these flaws. These bugs could have doxed John Deere Tractor Owners

There are many more eye-opening examples in the security news. I assume you understand the magnitude of issues at the global scale. What can we do? Understanding risks, vulnerabilities, and issues are critical.

Understanding API Risks and Vulnerabilities

The Open Web Application Security Project® (OWASP) “is a nonprofit foundation that works to improve software security. Through community-led open-source software projects, hundreds of local chapters worldwide, tens of thousands of members, and leading educational and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web.”

Here are the top 10 API risks as identified by the OWASP Foundation.

Broken Object Level Authorization

Broken User Authentication

Excessive Data Exposure

Lack of Resources and Rate Limiting

Broken Function Level Authorization

Mass Assignment

Security Misconfiguration

Injection

Improper Assets Management

Insufficient Logging and Monitoring

You can download this comprehensive and valuable document at this link free of charge. I also highly recommend a review of this resource related to API security by the Australian Government. This resource points out that “applying the right level of security will allow your APIs to perform well without compromising on the security risk.”

In a nutshell, let’s keep in mind that APIs not only expose critical user information but also application data, logic, and more importantly increase attack surfaces for hackers.

So, in addition to using vulnerability scanning tools (cross-site scripting, SQL injection, command injection, path traversal and insecure server configuration) as pointed out by OWASP, we can also leverage API security gateways. These secure gateways allows us to restrict access to the use of APIs by establishing rules on how data requests must be handled.

Conclusions

APIs are critical and innovative tools for service providers, consumers, and partners. Without APIs, we cannot enjoy and benefit from the richness of online information. In addition, business organizations depend on APIs to disseminate information timely to their consumers. They also need to use APIs to collaborate with partners.

However, our personally identifiable information is critical for safety, security, and privacy. This type of information is sought after by hackers for various purposes. The key goal is to protect this information with rigor. Technology is a double-edged sword.

Technical precautions are only one aspect of essential measures. In addition, policies, processes, and procedures by business decisions makers are critical. Cybersecurity is not a joke. I shared my insights about the implications of ransomware on our economy and well-being in this article.

For example, privacy governance schemes such as GDPR in Europe, the Cybersecurity 202 in the US, and the Australia Privacy Act are essential for businesses to use in their practice. You can find other countries with GDPR-like data privacy laws at this link.

With the emergence of artificial super-intelligence systems, we must consider the risks factors posed by APIs for protecting our personally identifiable information. Misuse of deep fake technologies was a wake-up call for society. These eleven emerging technologies make it of paramount importance for considering APIs and protecting our private information.

Thank you for reading my perspectives.

Here is a valuable and short video shedding lights on API security. The video provides insights from Stan Wisseman, Chief Security Strategist at Micro Focus Fortify.

About the Author

I am a technologist, postdoctoral researcher, author of several books, editor, and digital marketing strategist with four decades of industry experience.

I write articles on Medium, NewsBreak, and Vocal Media. On Medium, I established ILLUMINATION, ILLUMINATION-Curated, ILLUMINATION’ S MIRROR, ILLUMINATION Book Chapters, Technology Hits, SYNERGY, and Readers Hope publications supporting 12,000+ writers on Medium. You can join my publications requesting access here. You may subscribe to my account to be notified when I post on Medium. I share my health and well-being stories on my publication, Euphoria.

If you are new to Medium, you may join by following this link. A small part of your membership fee will not only support my writing but your reading times can support many great writers on this platform. Opportunities for readers and writers are endless on this platform.

Cybersecurity
Artificial Intelligence
Software Development
API
Technology
Recommended from ReadMedium