Online and via mobile apps – for nearby charging stations to ‘fuel’ their electric vehicle. They can differentiate on type and availability and even monitor the status during charging. All data is fetched and stored dynamically via services exposed via Amazon Web Services Powering Mobile Apps
'13 - (yes, 2013!) Initial contact made with vendor. After a few e-mails back and fourth their reasoning was legacy code and they'll "get right on it". 26th Sep '14 - Follow up e-mail. Issue still not resolved. ETA "before Christmas" 5th Jan '15 - Vulnerability still exists with ample amount of time given to vendor to fix the issue. Bad stories continue…
•API Firewalling •Embedded AV •Thortteling and Quotas •Deny by Default Transport Security •Secure by Default Assistance •SSL / TLS •HSM Integration Fine grained Access Control •IAM Connectors •OAuth (Client+Server) •OpenID Connect Data Integrity •Signature •Encryption •Schema Validation Certification and Compliance •FIPS 140-2 •CC-EAL2 •CSPN •PCI • Central Security Configuration and Control • Visibility at all Levels • Integration with exsisting Security Infrastructure like SIEM • Supports Scenarios with high Compliance Mandates like PCI or HIPPA • Allows Fine grained Access Control based on exisiting IAM
Action API Portal Register Connect Developers Production Apps API Gateways Manage Admins Secure Policy Metrics End-Users Use Production Development Connect Secure Development Apps Test Get API Keys, OAuth Client IDs and Client Secrets