PaymentsJournal
SUBSCRIBE
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
No Result
View All Result

Just as HTML Enabled Crime, API Platforms Also Jeopardize API Security

Tim Sloane by Tim Sloane
April 5, 2022
in Analysts Coverage, Security
0
Just as HTML Enabled Crime, API Platforms Also Jeopardize Security

Just as HTML Enabled Crime, API Platforms Also Jeopardize Security

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

An API, or application programming interface, is a set of tools and protocols that allow software applications to interact with each other. APIs enable software developers to access the functionality of another application without having to understand the underlying code. This makes it possible to create new applications that build on the functionality of existing ones. For example, the Google Maps API allows developers to add mapping capabilities to their own websites and apps. The Twitter API enables developers to integrate Twitter content into their own applications. And the Amazon API allows third-party sellers to list their products on Amazon.com. By providing APIs, these companies make it possible for others to extend and enhance their services in ways that they may never have thought of themselves. It is imperative to make sure API security has been considered when implementing these tools.

A security firm Mercator worked with on a project scanned a company’s sites for API vulnerabilities. The scan discovered several API portals, and IT was unaware these portals existed. One of them put critical data at risk, and threatened API security. According to the security company, this is not an uncommon experience.

This article indicates that many APIs are unmonitored and ungoverned, which is impossible for me to comprehend. I get that a mistake might be made, but leaving any internet port wide open is an act of insanity: 

“The transformation has been staggering in many regards. Connecting core business systems to external systems has exposed what had been typically tightly guarded within company networks through access, segmentation and layers of security protection. Now, business logic and processes are both visible and available for interaction. Through the conduit of business APIs, data can be scraped or exfiltrated, orders can be placed or changed, discounts applied, shipping destinations altered, funds transferred, payments sent, purchases made and a myriad of other operations arranged or changed. Since every business is unique, the possibility for abuse is only limited by the information transferred on the API.

Of course, the implications are not lost on the more sophisticated cybercriminals. Attackers have demonstrated the tendency to seek the greatest reward for the least effort. Data breaches still have value, but engaging directly in the theft of more valuable assets, including money, has much greater attractiveness.”

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

Tags: APIAPIsCybercrimeCybersecuritySecurity
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Analyst Coverage, Payments Data, and News Delivered Daily

    Sign up for the PaymentsJournal Newsletter to get exclusive insight and data from Mercator Advisory Group analysts and industry professionals.

    Must Reads

    On-Demand Webinar: Solving the Digital Onboarding Challenge​ – Increasing Conversions without Increasing Risk

    On-Demand Webinar: Solving the Digital Onboarding Challenge​ – Increasing Conversions without Increasing Risk

    February 8, 2023
    legacy infrastructure

    How Modernizing IT Can Help Banks Compete With Fintechs

    February 7, 2023
    Buy Now Pay Later BNPL, B2B BNPL

    B2B BNPL Offers a High-Potential New Chapter in Payments

    February 6, 2023
    eCommerce On Social Media, social commerce

    The Rise of Social Commerce and Social Payments

    February 3, 2023
    Electroneum AnyTask; ETN Crypto, sales enablement

    Ethical Financial Selling: The Role of Compliance Technology and Sales Enablement

    February 2, 2023
    direct deposit

    Nacha Launches Campaign to Reach Millennials on the Benefits of Direct Deposit

    February 1, 2023
    Equinix Helps UK-Based Payments Provider Enable Faster, More Reliable Payments Processing

    Equinix Helps UK-Based Payments Provider Enable Faster, More Reliable Payments Processing

    January 31, 2023
    credit card tumbling

    How to Detect, and Prevent, Credit Card Tumbling

    January 30, 2023

    • Advertise With Us
    • About Us
    • Terms of Use
    • Privacy Policy
    • Subscribe
    ADVERTISEMENT
    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Videos
    • Industry Opinions
    • News
    • Resources

    © 2022 PaymentsJournal.com

    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Industry Opinions
    • Faster Payments
    • News
    • Jobs
    • Events
    No Result
    View All Result

      Register to download the Equinix report - Dojo Delivers Fast, Reliable and Secure Card Payments to Businesses on Platform Equinix