Peloton powers its web and mobile apps with APIs, like virtually every other app on the Internet. But these APIs had a few critical flaws that exposed the personal information of all 4 million @OnePeloton users. What the Hack happened?!?
🎥 Peloton's 4M User Breach: What the Hack?!? - https://www.youtube.com/watch?v=
In this video Dan Barahona explains how the breach took place and how the open API and lack of authorization controls exposed 4 million Peloton user records.
The user data included the use's age, gender, city, weight, workout statistics, and even birthday. The APIs had access to all this information, even if you marked your Peloton account as private. Even President Joe Biden's records were exposed.
Two key issues caused the exposure: 1) the API was left wide open - no credentials required. And 2) the API allowed users to access records of other users - also known as Broken Object Level Authorization (BOLA) in the @owasp API Top Ten.
👉 Read more about the breach here: https://techcrunch.com/2021/05/05/pel...
👉 Register for APIsec University's free API Security Fundamentals course here: https://www.apisecuniversity.com/cour...
If you're interested in regular news from the API space, including future "What the Hack?!?" episodes, subscribe to "Getting APIs to Work"!
#api #apimanagement #security #apisecurity #owasp #gettingapistowork #digitaltransformation