Katie Paxton-Fear
speaker
37 appearances
1 recordings
1 series
first heard Oct 2024
last heard Oct 2024
Katie Paxton-Fear’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
So these APIs get exploited all the time. And honestly, it's because it's quite easy. If you don't even know something exists, how on earth are you supposed to secure it? You can talk about things like secure coding, secure software development life cycles, security vulnerabilities in general. But if you don't even know an API exists, how on earth are you supposed to protect it at all?
You don't know what you don't know. And when it comes to security, that is what will get you breached. Certainly, if we think about today as we're recording it, people have done an investigation into the Internet Archive attack from a few weeks ago and found there were just credentials on GitHub that were just valid that nobody had deleted. The problem is that they were up for decades as well.
I think it was up for like 10 years before anybody even noticed. So certainly, if we think about the kind of trend of people leaving companies, most people leave the company after maybe two to three years. Eventually, there'll be nobody left that knows that API exists. And the bad guys are highly motivated to find out it does exist because for them, that is a payday.
That is a way in, not even a backdoor, right? It is just a nice entryway, inviting one in to come and attack you.
I always feel bad for the defenders when I have this conversation with them, because as an attacker, my job is quite easy compared to that, because that is not an easy thing to do. Obviously, you can buy API security solutions like Traceable that have this as part of it, and that can be a great option.
But if you don't have the budget, you don't have the maturity to deal with it, that is where it is really hard. Some advice I've given some of Some of the companies I've worked with has been run an inventory.
If you can try and get as much information as you can, like whether or not that is digging through GitHub commit history, digging through what files are on servers, what cloud environments are running and what they're all running and what you have available, what pods are up, or by just asking a developer, hey, do you know what APIs we have? That is a huge first step taming this beast.
But it's not easy. You can use, there are some really great word lists that you can use like with fuzzing tools. There's the only API word list you will ever need that uses like a lot of historical data from different APIs that they've audited and sharing their knowledge.
Some of the other things you can do is have something like, if you have API management tools, things like Kong or MuleSoft, they can be really great ways of finding APIs. But honestly, if we had a bulletproof solution to that, you would be a millionaire.
Companies like Traceable do a lot there in trying to, again, bring in that intelligence side of things, have continuous monitoring, look for APIs in weird places. But you are simply not going to get them all. And what you need when that happens is a plan on how you're going to react when that inevitably happens.
So some of the most common kind of mistakes that I see are essentially not having a process for decommissioning things. If your process for decommissioning things is switch off, like you are not going to catch everything. You need a way to track what developers have deployed over time, where it's deployed, how it's deployed, and then you can properly decommission it when developers leave.
The other common mistake I see people make is having a really terrible relationship between development teams and security teams. A lot of people will have a weird adversarial relationship with their security team. And the security team is seen as an annoying, really frustrating team to have to deal with rather than it being a partnership.
And when you have that kind of relationship, it's really hard to bring it back. Some of the other common things is simply having no API security tools at all. I'm not even talking just you have free tools, you have nothing. You maybe don't even prioritize API security. That's another common one I see. There's no API incident response plan. There's no API management tools in place.
There's no process for deploying APIs. There's no API inventory in place. That is a really common thing that organizations will fall on. It's really easy to buy a tool that can scan your code and find every vulnerability. That's really tempting. Of course it's tempting. That sounds really easy. In reality, though, security is never quite that easy.
Though there are tools out there that can make it easier and highlighting what you actually need help with, what will make things easier, and then actually implementing that process and certainly having an API incident response plan. Because at the end of the day, these shadow APIs, unknown APIs, undocumented APIs, all of them, they're going to get attacked eventually.
If you start panicking like a headless chicken when something goes wrong, and you don't you can't go into that like focused instant response mode you're just panicking and just what's happening like you will lose control of the situation very quickly
No, I'm really happy to spread the good word about not getting breached by your APIs.
Showing 21–37 of 37 · page 2 of 2
← Previous