CHCon 2023

Securing REST API Endpoints (or, How to avoid another Optus)
11-24, 09:45–10:15 (Pacific/Auckland), Ngaio Marsh Theatre

Optus and its customers had a very bad time in 2022, with a massive data breach resulting in PII being released into the wild. This apparently happened because a REST API was not properly secured. We’ll talk about practical steps you and your organisation can take to prevent this from happening to you.

James Cooper holds a Ph.D. in Computer Science and works as a Security Developer at Cosive New Zealand. There, he spends most of his time working on Web applications such as Phishfeeder, with occasional side-lines in other tasks like developing third-party MISP integrations with customers' products or debating the merits of various programming languages and paradigms. He also spends too much time in the InfoSecNZ Discord and making Simpsons references.