Web

Warning Issued on Web Programming Interfaces

(Page 2 of 2)

  • Wednesday, August 5, 2009
  • By Erica Naone

Programmable Web's Musser says that many of the security risks introduced by an API are similar to those found in desktop computers. In both cases, he says, security vulnerabilities exist wherever there is an access point that an attacker might abuse. Any site that builds its API on top of another site's API is relying on someone else's security, and it's not easy to look into what has been built to see how well it has been handled, Musser says. "Part of the fundamental issue is just how new the technology is," he adds.

Jeremiah Grossman, founder and chief technology officer for WhiteHat Security, says that sites that publish APIs can find it hard to discover security flaws in them. He notes that often it's difficult to tell how a third-party site is using an API, and if that site has been compromised by an attacker.

APIs are also harder to test than traditional websites, Grossman says. Though software tools have been developed that can analyze a site's underlying code to pinpoint potential vulnerabilities, those tools won't work for testing APIs. "It's a lot more manual with a lot less automation, and it means, at the end of the day for the business, more expense," he says.

But while experts agree that there's no easy fix for the risks introduced by APIs, they also say the technology isn't going away. "Websites are becoming Web services, and that trend isn't going to stop," Musser says.

Print

Related Articles

Antivirus Protection Gets Social

Can cloud computing and social networking improve security software?

A Browser's View of Your Computer

Researchers reveal how attackers may be able to peer into users' computers over the Web.

Hackers Game a Multiplayer World

Two programmers reveal covert ways to automate characters in an immensely popular game.

To comment, please sign in or register

Forgot my password

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Videos

A Social-Media Decoder

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Groupon

Roche

Amazon.com

Silver Spring Networks

More

Advertisement

Facebook

Advertisement