Founder's Corner: Episode 3
12:13
Founder's Corner: Episode 2
12:32
Founder's Corner: Episode 1
20:04
2 ай бұрын
A New Strategy for Reducing API Risk
57:55
API Security in Healthcare
3:55
Жыл бұрын
Understanding API Attacks
4:11
Жыл бұрын
Salt: Securing your innovation
1:39
Fireside Chat with Amway
52:39
Жыл бұрын
How Aon Approaches API Security
3:16
Salt: Securing your innovation video
1:32
Пікірлер
@ΣτέλλαΜιχαηλίδου-φ3χ
@ΣτέλλαΜιχαηλίδου-φ3χ Ай бұрын
Ράδιο αμορε
@JoshuaJOnuh
@JoshuaJOnuh 9 ай бұрын
Hi, I would like to have a demo session to review your product. I booked from your site some couple of days back and I am still yet to get a response
@SaltSecurity
@SaltSecurity 9 ай бұрын
Hi! Thank you for reaching out and for your patience! You should be hearing from our team shortly :)
@JoshuaJOnuh
@JoshuaJOnuh 9 ай бұрын
Okay, thank you @@SaltSecurity. I look forward to your response.
@JoshuaJOnuh
@JoshuaJOnuh 9 ай бұрын
Hello I am yet to hear from your team. Why is it taking this long? I have tried calling the number attached to your contact but it never goes through from my location. I sent a couple of mails to [email protected] and yet no response. I am really keen on partnering with you on API security issues as our company business model has a lot to do around that. Kindly reach out please, thank you.@@SaltSecurity
@saidchaida5431
@saidchaida5431 11 ай бұрын
Thanks for explaining the concept in a simple way
@MRPOLY_237
@MRPOLY_237 Жыл бұрын
Thank you ! I missed an interview yesterday because I couldn’t recall these latest OWASP API Vulnerabilities 😅
@kev48
@kev48 Жыл бұрын
Great job 👌👍
@brutsecurity
@brutsecurity Жыл бұрын
how you created the animation ?
@AsdfghjklMnop677
@AsdfghjklMnop677 Жыл бұрын
Salt Labs researchers
@hox7125
@hox7125 2 жыл бұрын
Am kinda amazed its 22 and still not enough resources on yt for api security.
@SaltSecurity
@SaltSecurity 2 жыл бұрын
Yes, there’s a gap in understanding in the broader community. Along with this channel, other good education materials can be found here: salt.security/resources and here: salt.security/blog-tags/salt-labs
@SaltSecurity
@SaltSecurity 2 жыл бұрын
Thanks! We make this attack info available only to signed customers at this time but we appreciate understanding that this info could help the broader community and are looking at more ways to share our API attack insights. We do have additional info here: salt.security/blog-authors/salt-labs
@oudi1987
@oudi1987 2 жыл бұрын
can you share the postman collection?? Please!🙏🙏
@oudi1987
@oudi1987 2 жыл бұрын
?????
@janibashamd
@janibashamd 2 жыл бұрын
can you share the postman collection if possible..
@rikherlaar
@rikherlaar 2 жыл бұрын
Great presentation - just trying to get my head around how API flows might disclose business logic flaws in a TLS (1.2 or 1.3) session - I understand most state is kept at client side but still...
@antribera2138
@antribera2138 2 жыл бұрын
😂 ᴘʀᴏᴍᴏsᴍ
@hosangi.t.2508
@hosangi.t.2508 2 жыл бұрын
Appreciate the video.. interesting. I believe the title should of been API Attacks - Cloudflare WAF vs Salt Security since some WAFs are way more powerful, for example the AWAF by F5 is much more capable then the free version of cloudflare but thats my opinion only. Curious if there is somewhere I can download the Postman scripts you have so I can do some evaluation of our own. We recently purchased SALT Security (not implemented yet) and would like to do some of the same evaluations. Thanks again for the video
@SN-zr3rf
@SN-zr3rf 2 жыл бұрын
The below are my observations from this video.| 1) API is developed with consist of set of business functionalities. Each business functionality is described (insert/update/delete) operation or (viewing the single record operation) or (viewing list of records operation). 2) Each API should be privileged to access by User Groups. Each functional operation of API should also be authorized to access by user groups. The few list of attackers Vulnerabilities ---------------------------------------------------- 1) if user who does not have privileges and is trying to access the API their request API call should be blocked by API. 2) If attackers is trying to hijack user sessions and trying to access API , they API should reject those requests. 3) For each API call , the Session Authentication and API Operation authorization should be validated.. 4) If attackers are trying to modify/alter the data which was sent by user as part of API call, then API should validate and block those requests.
@mikepallcynac3865
@mikepallcynac3865 3 жыл бұрын
Great information. The foundations of cybersecurity are very rapidly changing. Would Salt Security's API protect small tax preparation offices that fully depend on external cloud-based services such as Intuit's ProConnect tax, Intuit Link for file sharing and Google Workspace office apps? OR Is Salt Security more directed at companies like Intuit itself to help Intuit secure its APIs. Another question: If we are using Google's AppSheet no-code system to create new API-based apps, are those apps automatically fully secured against all of the threats mentioned in your video? Should we / can we integrate Salt's API security into our AppSheet created programs for full spectrum API security? Can Salt's API security system even be integrated into these no-code, click-n-build app programs?
@SaltSecurity
@SaltSecurity 3 жыл бұрын
Salt would not be a good fit for the small tax preparation office use case to secure 3rd party cloud services. That's probably a better fit for a CASB solution. As you mentioned, Salt is directed at companies like Intuit and others who build apps/APIs to help them secure the APIs that they provide to customers/employees/partners. AppSheet apps are not automatically secured against the threats mentioned in the video. For security, AppSheet only provides authentication and authorization which leaves a lot of room for some of the top API threats like BOLA. Yes you can integrate Salt into AppSheet and other no-code apps to improve protection. Please reach out if you'd like to talk more about your apps and how we can help at Salt.
@mikepallcynac3865
@mikepallcynac3865 3 жыл бұрын
@@SaltSecurity Thank you for the helpful response. Appreciate it. It would be interesting to provide an overview of the API security vulnerabilities as well as other issues (shadow APIs) of no-code development platforms like AppSheet or Microsoft's Power Automate in a short video or discussion on your website. Both programs indicate, in their overview documentation, that secure apps can be made by anyone using these platforms. An increasing number of companies are engaging any interested staff to quickly make new apps for companies using these platforms.
@ProtikPC_pro_indigo
@ProtikPC_pro_indigo 4 жыл бұрын
kzbin.info/www/bejne/fISTeaCdr7uWl6s A discussion and a high level overview of things.