Issue 251: FCC mandates API security, API vulnerabilities in dating apps and Docker plugins, Life360 API data leak
Brief
This week, we review the API security controls outlined by the FCC to prevent data breaches and examine multiple incidents of API data leaks exposing users’ personal data. We also cover a case of unsafe API consumption in the Docker ecosystem.
Report: FCC weighs in with API security requirements
The U. S. Federal Communications Commission (FCC) has established a list of API security controls as part of a mandatory information security program at Tracfone, a wireless service provider. The company was also fined $16 million in connection with a series of data breaches that exposed its customers’ personal information.
The details of the mandated security program are included in a consent decree issued by the FCC, which specifically emphasizes the paramount importance of API security.
