Issue 120: Video doorbells security flaws, intro to JWT attacks, security zines

The Latest API Security News, Vulnerabilities and Best Practices
Issue: #120
Video doorbells security flaws, intro to JWT attacks, security zines

This week, we take a look at the security issues in cheap video doorbells and security cameras, as well as tutorials and webinars on protecting APIs running in Kubernetes, JSON web tokens (JWT), and web and API authentication and authorization.

Oh, and we also have a link to DZone community awards where you can vote for this newsletter!

Vulnerability: Video doorbells and security cameras
 

Research teams from Florida Tech and NCC Group have, independently of each other, looked into the security of inexpensive video doorbells and security cameras. These devices are sold at Walmart, Amazon, Home Depot, Best Buy, to mention but a few.

The researchers concluded that most of the cheap devices on the market come from a handful of Chinese manufacturers (ODMs), using standard generic design and components. This also means that issues found in one model are replicated in others.

The devices they looked at had multiple serious security issues, including built-in backdoors. Some of the found issues were API-related, too:

  • Communications are not encrypted.
  • Backend APIs are not protected with authentication.
  • There are REST APIs on cameras with hard-coded credentials.

You can find a quick summary of both research efforts in the GadgetGuy. For more details, see the full reports (links above).

Webinars: API Threat Protection in a Kubernetes World
 

In the world of microservice-based applications, every component is an API. As such, API security in the Kubernetes world is a lot more relevant than in the world of traditional applications.

Next Thursday, February 18th at 8 AM PST / 11 AM EST, Isabelle Mauny (42Crunch) gives a webinar on this exact topic.

For more details and to register, click here.

webinar-b-021821

 

Videos: Attacking JWT for beginners
 

If you find the world of JSON Web Token (JWT) security hard, check out this quick introductory video by Farah Hawaa:

image (2)

 

Technology 101: Security Zines
 

Security zines by Rohit Sehgal are fun, easy-to-grasp, comics-style explanations of web and API security.

The first one he has published explains some common authentication and authorization concepts:

  • Basic
  • Session-based
  • Token-based
  • JWT
  • OAuth

For example, here he is covering the OAuth Authorization Code grant:

OAuth authorization code grant zine

 

Vote for us!
 

DZone has nominated this newsletter (which they also republished) for their 2020 Contributor Awards.

If you have a minute and want to support us, please cast your vote here. This will help us further spread the word of API security.

14388732-dzone-awards-dmitry

 

 
 
Thanks for reading.

That's it for today. If you have any feedback or stories to share, simply reply to this email.

Please forward the newsletter to your friends and colleagues who might benefit from it.

 
42Crunch Ltd   71-75 Shelton Street  Covent Garden  London  Greater London   WC2H 9JQ   United Kingdom
You received this email because you are subscribed to API Security News from 42Crunch Ltd.

Update your email preferences to choose the types of emails you receive or Unsubscribe from all future emails  
 
 

Older messages

Issue 119: NoxPlayer supply-chain attack through a hacked API 📲

Thursday, February 4, 2021

Hi , today we look at NoxPlayer API attack, Radware state of web sec report, Azure API m APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #119 NoxPlayer supply-

Issue 118: Spring Framework ALPS, OAuth 2.0 attack mindmap, securing JWTs 📜

Thursday, January 28, 2021

Hi, today we look at potential API exposure via Spring ALPS, OAuth 2.0 attacks, JWT and APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #118 Spring Framework ALPS

Issue 116: Facebook and Parler API vulnerabilities, clairvoyance 🔭

Friday, January 15, 2021

Hi , this week we look at a recent Facebook vulnerability, Parler breach, GraphQL recon APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #116 Facebook and Parler

Issue 115: Vulnerabilities in SolarWinds, Ledger, Outlook, new plugin for JetBrains IDEs 🛠️

Thursday, January 7, 2021

Hi, today we look at the API aspects of SolarWinds and Ledger breaches, Outlook JWT... APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #115 Vulnerabilities in

Issue 114: SolarWinds and PickPoint breaches, GitHub Code Scanning review, GraphQL security 〽️

Thursday, December 17, 2020

Hi, this week we look at the API security aspects of two recent breaches, shift-left APIsecurity.io The Latest API Security News, Vulnerabilities and Best Practices Issue: #114 SolarWinds and PickPoint

You Might Also Like

📧 What Rewriting a 40-Year-Old Project Taught Me About Software Development

Saturday, December 28, 2024

​ What Rewriting a 40-Year-Old Project Taught Me About Software Development Read on: m​y website / Read time: 7 minutes The .NET Weekly is brought to you by: As the year wraps up, it's clear API

This Week in Rust #579

Saturday, December 28, 2024

Email isn't displaying correctly? Read this e-mail on the Web This Week in Rust issue 579 — 25 DEC 2024 Hello and welcome to another issue of This Week in Rust! Rust is a programming language

The Calm Voice Of Chaos 🏆

Friday, December 27, 2024

The protest singer whose songs shaped 2024. Here's a version for your browser. Hunting for the end of the long tail • December 27, 2024 The Calm Voice Of Chaos This year's Tedium awards start

JSK Daily for Dec 27, 2024

Friday, December 27, 2024

JSK Daily for Dec 27, 2024 View this email in your browser A community curated daily e-mail of JavaScript news Performance Optimization in React Pivot Table with Data Compression The Syncfusion React

Daily Coding Problem: Problem #1650 [Hard]

Friday, December 27, 2024

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Microsoft. Recall that the minimum spanning tree is the subset of edges of a tree that

🧠 3 Ways Quantum Computing Will Change Our World — How to Transfer Data to Your New iPhone

Friday, December 27, 2024

Also: Great Spotify Features That Apple Music Has Too, and More! How-To Geek Logo December 27, 2024 Did You Know 2004 was the last year that hidden (or "pop-up") headlamps appeared on a mass-

Charted | How U.S. Household Incomes Have Changed (1967-2023) 💰

Friday, December 27, 2024

When looking at inflation adjusted data, US households have definitely gotten a whole lot richer since 1967. View Online | Subscribe | Download Our App FEATURED STORY How US Household Incomes Have

Can Pirates Save Democracy?

Friday, December 27, 2024

Top Tech Content sent at Noon! Boost Your Article on HackerNoon for $159.99! Read this email in your browser How are you, @newsletterest1? 🪐 What's happening in tech today, December 27, 2024? The

The 2025 Predictions You Can't Afford to Miss 🔮

Friday, December 27, 2024

Get a head start on what's to come in the New Year. Join VC+ to gain access to our 2025 Global Forecast Series and other exclusive insights! View email in browser HOW LEADERS STAY AHEAD IN 2025 The

DeveloPassion's Newsletter #182 - 2024 Retrospective

Friday, December 27, 2024

A newsletter discussing Knowledge Management, Knowledge Work, Zen Productivity, Personal Organization, and more! Sébastien Dubois DeveloPassion's Newsletter DeveloPassion's Newsletter #182 -