Super Bowl API Security Risks with Noname Securitys Karl Mattson
Karl Mattson, field CISO for Noname Security, explains what might go wrong as the application programming interfaces (APIs) relied on to provide a better digital fan experience during the Super Bowl are targeted by cybercriminals.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Carl Matson, who's field CSO for no name security, and we're talking about of all things the Super Bowl, and not just who he's gonna pick to win.
Carl, welcome to the show. Thank you for having me. We have this big event that happens every year and there's lots of physical security at the event.
It's probably one of the safest places you can be on a particular Sunday. But from a cybersecurity perspective, what should we be concerned about here and what impacts are we not thinking through entirely? Well, the Super Bowl is sort of a concentrated dose of of, of what we see happening, uh, across sports and entertainment, which is the, the rapid progress towards an improved fan experience, uh, the, the great fan experience of buying tickets and merchandise and going to the venue and enjoying yourself.
Uh, we want fans to have a great experience, but what that means is, is the API based services now become a part of our fan experience, whether it's, you know, the way, the way that we go through the entire process, uh, is a, is is a sort of composite use case of why APIs are valuable, um, because we can have this, this great fan experience because of the, of the services that APIs provide us. So, well, on the flip side, what that also does is it means that we have sensitive data, things like biometrics for authentication or payments information. Um, um, we're now, we're a part of, of going to a game.
And, and so, uh, we're, we're putting data out there into the world. Um, and it's, it's easy to forget sometimes that the, um, the, the, the best fan experience or the best customer digital experience that that can be offered also means that there's data trafficking, um, at a, at an increasing rate. And that, and that data needs to be protected.
And a lot of that data is, doesn't even involve being at the game, right? There's all these gambling apps and all kinds of experiences on mobile phones that involve APIs. So, do we need to really think this through more holistically?
'cause I'm sure the bad guys are. Oh, absolutely. I think, you know, whether it's the, the, the QR code that pops up in the commercial with the ask is to, for the, the viewer to scan that QR code and go to the website, um, or it's by buying merchandise, uh, from, from a, from a fan store.
Um, all of those experiences typically utilize, um, API based services for payments and, and, um, uh, information sharing, uh, that, that customers, um, need to be aware of. com website and, and we order a, a hoodie and a hat, um, um, that, that favorite sports team that you're buying from. It's actually a third party service that's running behind the scenes that does inventory management, that does, um, payments information, those kinds of things.
And so we have to be very diligent about, about the, the, the institution who offers these services needs to have their due diligence on providing these API based services, um, so that their platform and has integrity and so that their customers can, can trust their platforms. So what are the odds that there'll be some sort of incident? I mean, I imagine there's, it's almost certain that only question at this point is how big it might be.
Well, I think what we saw a few years ago, uh, I think it was January, 2022, right square in the middle of the Super Bowl, um, there was a, a major vulnerability disclosed in a, in a Coinbase API, uh, and that, that vulnerability was really identified because the, the, the organization had advertised itself and, and was directing con, you know, consumers to a Coinbase website. Well, guess who else gets redirected there as security researchers and attackers? And that immediately discovered that that website or that API was vulnerable to compromise.
And so it was literally during the course of the Super Bowl that Twitter was, you know, coming alive, uh, and foreign this, this API vulnerability that that, uh, thankfully was resolved before it turned into a major breach. Um, but really what the, what the Super Bowl does is it places just this absolutely intense, you know, spotlight of, of attention from consumers, but potentially from attackers as well, uh, on that service or product that we're advertising. And so, um, uh, there's, there's definitely a, a, a careful what you wish for, uh, opportunity here, uh, for, for organizations who are putting themselves out there during the Super Bowl for marketing purposes or otherwise, um, um, and are they ready?
Have they prepared themselves for the scrutiny of what they're offering the world? Why doesn't API security get the level of attention it deserves, especially for these big types of events? Because you would think the folks building APIs are conscious of the fact that that's an end point that somebody's trying to compromise.
Yeah, I think that the, uh, the momentum has definitely shifted. I think that from, from three to four years ago with the company's founding, I think API security, um, was a bit of an edge case for most security teams. Maybe 10% or 20% of organizations thought of API security as a, as a primary mission or a, a top objective.
And I'd say that we're, we're well past half now of organizations. Uh, it does depend a little bit to the degree that that organization has adopted API centric application design, uh, activities. And so there are some, some industry verticals that are, that are still just starting to make a journey towards an API first approach.
And there's other verticals like FinTech that were API first from the day that they, you know, open the business. Um, those, those organizations, um, uh, internalized API security is a priority very early, and that, that, that curve, I think we're definitely getting over that curve now, uh, with the, with the overall practitioner understanding that APIs are a unique asset class and they're, they're worthy of a very specific focus. Who's in charge of API Secur?
Is it the developers or is it the cybersecurity team? Um, it's a great question. Uh, the, the answer to that is really every organization has to, has to start with governance, which is who's, who's the accountable party?
Who's responsible. And there are companies that are, um, are choosing to make API security a, a, uh, like a mobile or a digital product owner's responsibility. And if they do so and they design their processes of API security around a product owner with accountabilities, huge recipe for success, another organization designing its roles and responsibilities, making the CISO or the security operations team the, like the primary accountable party, um, and then they can design policies and processes around that structure.
Um, I, so I think the answer is not which party. Um, the answer is an organization needs to pick somebody or pick a, pick a function. And once they pick that function and they organize themselves around supporting and, and governing in a way that that is consistent, that's a recipe for success.
Even though different organizations may choose a different function, it's just that there are organizations that have not maybe had the, had the, the gut check to pick a, pick that function and, and really commit to that being the accountable party. Hmm, of course, these days you can't walk down the street without somebody talking to you about their new AI thing. Are the bad guys gonna use AI to start compromising APIs?
What are you seeing? Um, great question. I think we just saw yesterday, a, an now a $25 million fraud event where a, um, a impersonation of somebody over zoom, a video deepfake actually led to a $25 million loss.
So, um, so I think, I think the obvious answer is, is yes, because I think what we're gonna see is, is a sophistication of human-like impersonation, um, that that human-like impersonation is gonna come in every conceivable shape and size that we could probably whiteboard off 20 ERs right here. Um, but adversaries are gonna come up with a new one me that, that you and I had not contemplated. Um, so what we, what we really have to rely on then is, is really rock solid principles of things like authentication and, uh, that, that deep fake example is one where you and I may be visual, visually fooled by a, an threat actor over Zoom 'cause it was a great video.
Um, but did they, did they, um, did they pass a biometric? Um, that's statistically significant? Did they, did they do a voice authentication?
Those kinds of things. Um, we're gonna have to consider about how we improve authentication so that it can be as much as possible impervious to some sort of sophisticated impersonation attempts. Great question though.
Great time to be in security because we're watching this sort of emerging, um, um, it's emerging risk category right before our eyes take shape. All right. Well, I'm pretty certain that I'm real, and I'm almost certain that you're real, but the question I have for you is what's your advice to folks about how to go and address these issues?
Because to your point, they are gonna become more pressing and not sure everybody's thought it through yet. Well, the, um, um, you know, what's old is always new again. Um, as, as cyber threats change, which is the, the first, um, uh, principle of essentially any cybersecurity discipline is, is know thyself.
It's an inventory. Um, it's, it's do, do we know what all these API endpoint assets are that are in our organization's remit and sort of the discovery of, of an inventory because that discovery then tells us what our next steps are and the next, the next step to secure, the next step for secure development, the next step for anomaly detection. Um, and so that, that very simple question of inventory, um, will always need to be answered first.
Um, because until we answer that question with sort of concrete, what is, what is my, um, uh, what is my responsibility for coverage? When we can answer that, then we can start answering more sophisticated questions. And so organizations always need to start there.
And once they have a comfort level in their, um, their universe of, of, of assets, uh, then we move on to vulnerability, identification and, and testing. And then the more sophisticated runtime detection type kind of conversations. All right, folks, well, you heard it here.
Regardless of who you might be rooting for, there are bad guys out there that have an entirely different interest in the outcome of this game, and hopefully they come up short. But hey Carl, thanks for being on the show. My pleasure.
Thanks for having me. And back to you guys in the studio.