Anil Yuksel (@anilyukk) 's Twitter Profile
Anil Yuksel

@anilyukk

Cyber Security Professional

ID: 1094229410398568448

calendar_today09-02-2019 13:39:56

76 Tweet

280 Followers

165 Following

Nikki Siapno (@nikkisiapno) 's Twitter Profile Photo

How do we design secure and safe APIs? The rise in API-related security breaches highlights the necessity for robust API security. Let’s look at 12 essential tips for improving API security: 𝗥𝗮𝘁𝗲 𝗹𝗶𝗺𝗶𝘁𝗶𝗻𝗴 𝗮𝗻𝗱 𝘁𝗵𝗿𝗼𝘁𝘁𝗹𝗶𝗻𝗴 ↳ Throttling and rate limiting

How do we design secure and safe APIs?

The rise in API-related security breaches highlights the necessity for robust API security.

Let’s look at 12 essential tips for improving API security:

𝗥𝗮𝘁𝗲 𝗹𝗶𝗺𝗶𝘁𝗶𝗻𝗴 𝗮𝗻𝗱 𝘁𝗵𝗿𝗼𝘁𝘁𝗹𝗶𝗻𝗴
↳ Throttling and rate limiting
Nikki Siapno (@nikkisiapno) 's Twitter Profile Photo

If I had to load balance traffic, here are 6 algorithms I'd consider: 1) Round robin 2) Weighted round robin 3) Least connections 4) IP hash 5) Random 6) Least response time There's no one-size-fits-all solution. When choosing, consider these key factors: ↳ Workload

If I had to load balance traffic,
here are 6 algorithms I'd consider:

1) Round robin
2) Weighted round robin
3) Least connections
4) IP hash
5) Random
6) Least response time

There's no one-size-fits-all solution. 

When choosing, consider these key factors:

↳ Workload
Hammed Oyedele (@devhammed) 's Twitter Profile Photo

Password 1: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa1 Password 2: aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa2 These two users can login to each other's accounts because brcypt caps hashing to the first 72 bytes.

Anil Yuksel (@anilyukk) 's Twitter Profile Photo

Most API breaches don’t come from bugs. They come from valid requests doing things they shouldn’t. API security is about behavior, not just endpoints.

Anil Yuksel (@anilyukk) 's Twitter Profile Photo

Reflected payload in an API response? Don’t report that XSS just yet! The secret is in the Content-Type: ✅application/json = Just data (Safe) ❌text/html = Rendered as a page At ApyGuard, we prioritize accuracy by distinguishing between data reflection and actual risk.

Baha Gökce (@bahagkc) 's Twitter Profile Photo

24.000 sahte hesap. 16 milyon konuşma. Tek bir amaç için. Anthropic bugün bombasını patlattı. DeepSeek ve birkaç Çinli yapay zeka şirketi, Claudeu sistematik şekilde sömürmüş. Sahte hesaplarla modeli sorguya çekip kendi sistemlerini beslemeye çalışmışlar. Bunu bir düşünün.