IyaSec Blog

Notes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.

Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated User

  • Application Security
  • Authentication
  • Authorization

Authentication is one of the most fundamental concepts in application security. Most developers spend considerable time designing how authenticated users are represented, authorized, and managed. Surprisingly, much less attention is given to the opposite state of users who have not authenticated at…

Read article: Understanding Unauthenticated Traffic: How Applications and APIs Represent The Unauthenticated User

Data Loss Prevention (DLP): Keeping Your Organization’s Secrets from Walking Out the Door

  • Authorization
  • Data Security
  • Data Loss Prevention

For decades, organizations have focused on keeping attackers out. Firewalls, antivirus software, intrusion detection systems, IAM solutions, and the like all serve a common purpose to prevent unauthorized access. However, many security incidents do not begin with an external attacker breaking in.…

Read article: Data Loss Prevention (DLP): Keeping Your Organization’s Secrets from Walking Out the Door

Looking for something specific? Browse all 124 topics.