Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy
A company is using several Google Cloud APIs (e.g., Cloud Vision API, Cloud Translation API) in their public-facing mobile application. They need to secure access to these APIs and prevent unauthorized usage, especially from unintended sources. Which method is the most appropriate and secure way to control access to these APIs for a public application?
- AUse OAuth 2.0 client IDs for installed applications.
- BCreate a service account key and embed it in the mobile application code.
- CRestrict API keys by HTTP referrer and API services.
- DGrant `roles/owner` to the default Compute Engine service account.
Show answer & explanationAnswer & explanation
Correct answer: C. Restrict API keys by HTTP referrer and API services.
For public-facing applications accessing Google Cloud APIs, API keys are commonly used. To secure them, it's crucial to restrict the API key by specifying allowed HTTP referrers (for web apps) or Android/iOS app bundles (for mobile apps) and limiting it to only the necessary API services. This prevents unauthorized use if the key is exposed.
Why the other options are wrong
- A. OAuth 2.0 client IDs are primarily for user authentication and authorization flows (e.g., allowing users to grant permission to an app to access their data), not for securing API access for the application itself to Google Cloud services. API keys are for identifying the project/application making the API call.
- B. Embedding service account keys in public-facing applications is highly insecure and should never be done, as it grants full control over the service account.
- D. Granting `roles/owner` to any service account, especially one used by a public application, is a severe security risk and violates the principle of least privilege.
API Key Restrictions
API keys are simple credential tokens used to authenticate to certain Google Cloud APIs. They should always be restricted by application type (e.g., HTTP referrer, Android/iOS app) and specific API services to limit their scope.
- Identifies the calling project/application.
- Must be restricted by HTTP referrer/app bundle.
- Should be limited to specific API services.
Memory trick: Restrict your API keys to keep them safe.