Challenges of GraphQL security in 2024
Tristan Kalos, iCarossio
BSides NYC 2024 · Day 1 · Tech - Other
In "Challenges of GraphQL security in 2024," Tristan Kalos and Antoine Carossio, co-founders of the API security company ESCAPE, presented exclusive research from their "State of GraphQL Security 2024" report. The talk delved into the unique security landscape of **GraphQL** APIs, highlighting the vulnerabilities uncovered through large-scale penetration testing of 160 production GraphQL services belonging to various companies worldwide. Their findings reveal a significant and escalating challenge in securing this increasingly popular API technology.
AI review
Decent survey-level research on GraphQL-specific attack surface with real data behind it — 160 production APIs, 30K+ issues, clear statistics. The GraphQL bomb and field-suggestion schema reconstruction angles show some genuine originality, but the overall package feels more like a product-adjacent report presentation than deep technical research, and the vendor conflict is impossible to ignore.