Fwd: [security-lunch] Jul 22 | Nurullah Demir on "Exposed API Credentials on the Web"

2 views
Skip to first unread message

Alan Karp

unread,
Jul 21, 2026, 4:58:40 PM (5 days ago) Jul 21
to <friam@googlegroups.com>

--------------
Alan Karp


---------- Forwarded message ---------
From: Michael Leo Paper via security-lunch <securit...@lists.stanford.edu>
Date: Tue, Jul 21, 2026 at 11:41 AM
Subject: [security-lunch] Jul 22 | Nurullah Demir on "Exposed API Credentials on the Web"
To: securit...@lists.stanford.edu <securit...@lists.stanford.edu>


Security Lunch ☀️ Ed. — Wednesday,  July 22nd, 2026, 12:00 pm @ CoDa E160

Exposed API Credentials on the Web
Nurullah Demir
Can't make it in person? Join us on zoom.
See our past & upcoming events on our website


Abstract: 
Application programming interfaces (APIs) are a central part of modern IT environments, and developers authenticate to them with sensitive credentials such as API keys and tokens. Prior work has studied credential exposure in source code repositories and cloud storage; however, the web remains unexplored. We conduct a large-scale analysis of API credential exposure on the web, analyzing 10 million webpages. We identify exposed credentials on 10,000 webpages from 14 critical service providers (e.g., cloud and payment services), affecting high-stakes services. This includes access to the infrastructure of a global bank, the distribution software of a firmware developer used globally in RC devices such as drones, and many other critical infrastructure providers. In this talk, I will share the root causes of these exposures, show that exposed credentials persist for a year on average and in some cases up to five years, and explain how our responsible disclosure reduced this risk by half within two weeks.

Bio:
Nurullah Demir is a Visiting Postdoc at Stanford (ESRG) and holds a Ph.D. from the Karlsruhe Institute of Technology. His research focuses on building automated, agentic systems to identify and mitigate structural security and privacy risks at internet scale. He is a core maintainer of the open-source project HTTP Archive and Editor-in-Chief of the Web Almanac, an annual technical report on the state of the web.
_______________________________________________
security-lunch mailing list
securit...@lists.stanford.edu
https://mailman.stanford.edu/mailman/listinfo/security-lunch
Reply all
Reply to author
Forward
0 new messages