Listen to this episode

Navigating the Complexities of API Protection and Compliance

0:0053:25

Recorded March 2024. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig and Blake of Petronella Technology Group welcome Jeremy Snyder, co-founder of the API security company Firetail, to discuss how APIs work, the threats they face, and the state of API compliance. Jeremy explains that Firetail provides inline code libraries that check API traffic against specifications, along with discovery and monitoring tools for APIs running on cloud platforms.

He describes how attackers probe new internet-facing services within minutes, hunt for tokens and secrets, and abuse broken authorization to extract data directly, bypassing mobile apps. The conversation covers APIs that return excessive personal information and the lack of dedicated API mandates in standards like NIST, HIPAA, and ISO at the time of recording, with PCI DSS 4.0 offering only a lightweight introduction. Jeremy recounts the Move it file transfer incident, where ransomware was delivered through an exposed API to thousands of organizations, and concludes that a Gartner prediction naming APIs the top attack surface was probably right. The episode closes with Jeremy's advice to inventory APIs automatically, document them technically, and strengthen authentication, authorization, and data return controls.

Worth remembering

Key takeaways

  1. Jeremy warns that any internet-facing service is discovered and probed by automated attackers within minutes, so organizations should assume continuous scanning rather than one-time drive-by probes.
    “Anything you put online will get probed within a very, very short period of time.”
  2. Jeremy explains that broken authorization is the most common API flaw, and that hackers bypass mobile apps to attack APIs directly and circumvent backend controls.
    “But this abuse of flaws and authorization categorically that's the number one category of flaws that we see on APIs.”
  3. Jeremy notes that many APIs return more personal data than needed because developers find broad queries easier, a common problem his customers seek to solve.
    “identifying these APIs that are returning PII beyond what is expected is definitely a very common use case and scenario that we've seen customers looking to solve.”
  4. Jeremy observes that, at the time of recording, NIST, HIPAA, and ISO lack specific API controls, while PCI DSS 4.0 only begins to address APIs lightly.
    “The most recent PCI, dss 4.0, started to introduce APIs as being in scope, but with a very, very, very lightweight set of requirements around them.”
  5. Jeremy cites the Move it breach, where ransomware was delivered through an exposed API, as a warning that third-party software can make companies unknowing API providers.
    “So all of these organizations bought this third party piece of software and didn't realize that all of a sudden they were now API providers, exposing APIs out to the internet by virtue of using this software.”
  6. Craig and Jeremy agree that security starts with visibility: learn which APIs you run, monitor their usage, and block unused third-party API functions at the network layer.
    “If you don't know about it, you don't know the risks that it poses to your organization.”
  7. Jeremy recommends automating API inventory because APIs change too frequently to track with a manual spreadsheet, and says all APIs need technical documentation.
    “Apis are one of these things that gets created and modified so frequently by the developers that you can't rely on a manual Excel spreadsheet exercise to maintain that inventory.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Unlock the secrets to ironclad API security with Jeremy Snyder of Firetail as we navigate the often treacherous terrain of digital safety. Peering into the murky depths of API exploitation, Jeremy brings clarity to how Firetail's cutting-edge tools not only bolster developers' efforts in constructing impenetrable APIs but also stand guard, thwarting real-time threats. Our digital lives, intertwined with these invisible gateways - be it a simple food order or an endless scroll on social media - demand such vigilance. Alongside relatable anecdotes, we examine the insidious nature of API breaches, from impersonation to lax authorization, and how Firetail's innovations are reshaping the landscape of cybersecurity.

As digital fortresses become more complex, we probe the battlefield of API security threats and compliance, where Firetail emerges as an ally. Attuned to the silent war against automated attacks that exploit API vulnerabilities, we reveal how disabling network telemetry in the name of cost-saving can be a false economy, leaving businesses exposed. The conversation branches out to encompass the intricate dance of compliance, with a spotlight on the necessity for airline industry-like regulations in tech. This nuanced discussion lays bare the urgency of a comprehensive security posture management system, capable of unmasking covert APIs before they fall prey to cyber predators.

Concluding our expedition through the digital thicket, we shine a beacon on the opaque world of API visibility and the pivotal role of security awareness within organizations. Jeremy illustrates how Firetail's sophisticated software unveils hidden APIs, transforming the nebulous into the known. The dialogue turns to the art of log analysis and pattern recognition as we dissect the intricacies of keeping personal data under lock and key. Penetration testing and proactive security assessments rise as the clarion call for CIOs and CISOs, now standing at the vanguard of accountability for breaches. All paths lead to one destination: the imperative need for investment in technology, sharpened knowledge, and rigorous training to cultivate a fortress of security awareness that spans every level of the corporate hierarchy.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.