APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.