{"id":239672,"date":"2012-05-15T02:10:57","date_gmt":"2012-05-15T02:10:57","guid":{"rendered":"http:\/\/www.eugenesis.com\/anatomy-of-hack-on-google-leads-plaxo-to-up-api-security\/"},"modified":"2012-05-15T02:10:57","modified_gmt":"2012-05-15T02:10:57","slug":"anatomy-of-hack-on-google-leads-plaxo-to-up-api-security","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/anatomy\/anatomy-of-hack-on-google-leads-plaxo-to-up-api-security.php","title":{"rendered":"Anatomy of hack on Google leads Plaxo to up API security"},"content":{"rendered":"<p><p>  Summary: A malicious attack aimed  at Google but routed through Plaxo highlights the growing  importance of API security using the forthcoming OAuth 2.0  protocol, which protects the users credential information.<\/p>\n<p>    Address book service Plaxo is moving to shore up its API    security after being sucked in as a back-door, silent victim in    an attack on Google.  <\/p>\n<p>    Last week, a spammer armed with stolen credentials for a number    of Google accounts routed their attack through Plaxos servers    by taking advantage of connections the two maintain and an    aging Plaxo authentication mechanism called Address Book (AB)    Widget, which enables Plaxo users to import Gmail contacts.  <\/p>\n<p>      Copyright: Brian Campbell    <\/p>\n<p>    Given the avenue of the attack, it was hard for Google to    detect the malicious traffic being proxied through Plaxos IP    address.  <\/p>\n<p>    The two worked together to dissect the hack and Plaxo has since    retired its AB Widget and will update its Plaxo-Google Sync in    a few weeks to support OAuth 2.0 and take advantage of its    secure authentication capabilities.  <\/p>\n<p>    The moral of the story is that security should be of paramount    concern for APIs as they become a preferred point of    integration within the concepts of cloud computing.  <\/p>\n<p>    To wit, over the past two years, companies such as Twitter,    Facebook, Google, Netflix, eBay and NPR have each been    processing billions of API calls per day.  <\/p>\n<p>    OAuth 2.0 is a forthcoming Internet Engineering Task Force    specification that uses tokens for authenticating API    end-points, which eliminates the need to share credential    information among providers.  <\/p>\n<p>    End-users wont know the technology they are using is OAuth,    said Preston Smalley, general manager and head of product for    Plaxo. But over time users are becoming more and more    sensitive to sharing their user names and passwords with anyone    other than their account provider.  <\/p>\n<\/p>\n<p>View original post here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.zdnet.com\/blog\/identity\/anatomy-of-hack-on-google-leads-plaxo-to-up-api-security\/476\" title=\"Anatomy of hack on Google leads Plaxo to up API security\">Anatomy of hack on Google leads Plaxo to up API security<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Summary: A malicious attack aimed at Google but routed through Plaxo highlights the growing importance of API security using the forthcoming OAuth 2.0 protocol, which protects the users credential information. Address book service Plaxo is moving to shore up its API security after being sucked in as a back-door, silent victim in an attack on Google.  <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/anatomy\/anatomy-of-hack-on-google-leads-plaxo-to-up-api-security.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[577281],"tags":[],"class_list":["post-239672","post","type-post","status-publish","format-standard","hentry","category-anatomy"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/239672"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=239672"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/239672\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=239672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=239672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=239672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}