Issue 220: API flaw in Booking.com, apps leaking sensitive API data, API security testing checklist
Brief
This week, we have news of a vulnerability affecting the OAuth2 implementation on the Booking. com website. We have a report from Approov on their research into financial apps in the Google Play store and another great article from Dana Epp on API security checklists. Finally, we cover an interview with Matias Madou on the need for people-driven security.
Vulnerability: API flaw in Booking.com could affect other sites
Recent research featured in IT Security Guru revealed an API flaw in the Booking. com platform relating to implementing the Open Authorization (OAuth) social-login functionality. Booking. com’s teams immediately investigated the findings, resolved the vulnerability, and thanked the researchers, encouraging others in the global security community to participate in their bug bounty program.
