Bitcoin Forum
May 17, 2024, 12:40:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Oauth2 // API : security issues  (Read 139 times)
dragons_are_secure (OP)
Jr. Member
*
Offline Offline

Activity: 42
Merit: 2


View Profile
October 14, 2017, 12:18:07 AM
 #1

 We are evaluating security risks for our new bitcoin network.  My sense is that the API calls are a real weak point.  I don't see alternatives to Oauth2 and/or API keys. 

  Have others evaluated the relative risks for different protocols?  I'm curious if it makes sense to be more imaginative in our API security or whether there are other API security approaches that have been considered in the community.

  I'm looking over places like:
https://developers.coinbase.com/api/v2
https://www.luno.com/en/api
https://spectrocoin.com/en/integration/spectrocoin.html#/introduction/overview

 In searching the bitcointalk archives, there doesn't seem to have been an extensive discussion of this issue.  Is there a reason not to look more carefully at the entrance/exit of information from the network?
achow101
Staff
Legendary
*
Offline Offline

Activity: 3402
Merit: 6641


Just writing some code


View Profile WWW
October 14, 2017, 01:12:31 AM
 #2

Those APIs are not Bitcoin's APIs but rather specific service APIs. This is a problem for services and something for them to deal with, not the Bitcoin network.

Willful_Grok
Member
**
Offline Offline

Activity: 60
Merit: 10


View Profile WWW
October 14, 2017, 01:40:03 AM
 #3

this is a very pertinent question and I'd like to know more as well. I haven't had any luck finding information on it anywhere within the forum.  Security is becoming more of a recognized concern within blockchain.

///***********DaiWare   - A Leader in Artificial Intelligence Predictive Analysis********///
*********************DAIWARE*******************
///____DISRUPTIVE TECHNOLOGY IN DIGITAL HEALTH ANALYTICS____///
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!