# Secure your Dapp or join the REKT list | Christopher von Hessert | ETHDam 2023

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2023-10-07
- Duration: 28:55
- Watch: https://streameth.org/watch/yt-CxtaQyTYu3k
- YouTube: https://www.youtube.com/watch?v=CxtaQyTYu3k

## Description

Christopher von Hessert is a security director at Polygon.
https://twitter.com/cvhessert?s=11&t=3zlJQECNQOGVgRU84E-vDA

ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. 

Privacy is normal. Following the arrest of Alexey Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy, encouraging to build on the shoulders of cypherpunk giants.

ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. 

ETHDam 2024 is on the map already! Keep up with us to see updates: 

CryptoCanal https://www.cryptocanal.org/
CryptoCanal Twitter https://twitter.com/CryptoCanal
Join CryptoCanal Community https://t.me/CryptoCanalCommunity 

We would like to thank our partners and sponsors that made this event possible. 🌷

Our BFF 1inch https://1inch.io/

Our Frens: 
Sismo https://www.sismo.io/
Aleph Zero https://alephzero.org/
Scroll https://scroll.io/
RAILGUN https://railgun.org/#/

And our Sisters:
oasis.app https://oasis.app/#earn
Maven11 https://www.maven11.com/
bitvavo https://bitvavo.com/en
Lido https://lido.fi/
Spankchain https://spankchain.com/
API3 https://api3.org/
Gelato https://www.gelato.network/
VanEck https://www.vaneck.com/nl/en/crypto-etn
Marlin Protocol https://www.marlin.org/
Silent Protocol https://www.silentprotocol.org/
Cyber Capital https://cyber.capital/
… and Proto https://twitter.com/protolambda 🍍

## Transcript

[Music] I'm not sure if the title of this talk is a threat or a question secure your dap or get wrecked something like that that's a question it's question you'll see now the presentation once we get when I saw it I was like is that kind of aggressive I don't know it's a prediction okay okay oh you're not wrong let's see yet um yeah I'm connected and allowed okay let me try again it's detecting it so there we go oh there we go cool well whenever you're ready take it away cool thank you guys uh sorry that I'm in between lunch so I'll try to make this uh quite quick my name is Christopher uh I currently work for polygon uh part of the security team and before that uh I've been in security and you know managing building engineering teams uh in software as a service crypto and many other things for quite some time so um yeah I think we're good yeah yeah if you can you guys see the presentation good I'm not crazy um cool so um the title of my presentation is basically you know uh you know join U you know secure your DB or join the rec list uh to be honest it's not a question if if you're going to be joining it it's when you're going to join it and how you're going to join it this is just like de nobody is going to escape from some type of hack manipulation or gaming of their protocol of their application of their business no there's there's always something's going to happen you know but you want to most likely be on that corner all the way at the you know bottom right and you don't want to be at the you know top left so um this is going to be a very short talk um this is also uh similar to the talk that I'm going to give an ECC uh so you know just chilling that a little bit um and basically we'll give you some uh guidance about you know just do the basics please you know like I'm tired of seeing protocols getting hacked in the most dumbest ways possible that could have been avoided with just a little bit a little bit of effort so let's let's look at a couple of um you know not recent but you know some of the big hacks that I've happened over the last couple of years now we got the running hack or also axi Infinity that has been done you know so you know some private Keys got exposed for whatever reasons and because of that their Bridge got exploded basically Badger this is also a very U you know very interesting one that has not much to do with crypto smart contracts or anything like that but obviously the implication was you know they were able to inject some code into the web page and then trick users to actually approve stuff and move tokens you know and then you know 120 million was actually exploited from the users um coin check you know they had an Internet connected hot wallet you know who does that nowadays Nomad that also you know could have been very easily solved if you had some policy or not policy but processes in place for making changes to your contracts and last but not least obviously we've seen a ton of this as well as re-entrancy flash loan attacks and stuff like that you know not it's it's not easy to solve and protect yourself from some of these things but you can minimize it you know you can try to make sure that if it happens and not really if when it happens that you you know do the least um no that that it does the least amount of damage and that your reputation also doesn't get uh hit know um a lot of it has to do a lot of projects actually survived hacks just because they had a good reaction they obviously had a good PR campaign after the hack saying like hey guys we're sorry we know what happened we're going to continue forward and they recover for it other protocols completely denied it they're like no we don't have anything going on everything's cool just chill chill chill and my computer just uh went went off sorry um you know so so it all depends also on how you react to it so what do these protocols have in common no I think uh that's uh that's something that if you look at the first one you know hacked private keys this is a little bit about thinking of how do you protect your private Keys know how do you protect um your wallets how do you connect those private Keys into your uh into your application are using a key storage in you know are you using hot wallets uh things like that in the second case Badger this is web apps this has nothing to do with crypto this is you know you got to protect your DNS you got to look at your web page where are you hosting it please don't use name cheap um you know things like that uh is are you using verel are you using AWS um you know look into those things I'm going to go into a little bit more detail in a moment uh for coin check we talked about connecting hot wallets definitely nothing a good thing poorly managed changes um that's an interesting one um you know I bet that most protocols and I can say that as well for polygon itself as good as it is you know we have 10 people uh or even more 12 people doing security over there I'm sure there are processes that are not documented and it's important that you document like if you need to make a change to a Smart contract document how you make a change when do you test it when do you make sure uh when do you make sure that the test actually was uh was um executed properly no did did it have the implication that you expected do you put monitoring around it no and last obviously again cream you know flash loans attack yeah how do you protect from a flash loan attack or you know something similar to that it's really just trial uh try and error it's um you know using testing tools is using potentially formal verification it's potentially using Auditors so again what do they all have in common you know this is hopefully a funny slide I asked Chachi PG to you know get me some good examples of you know people you know representative people representative technology representative processes no so um you know all of these hacks you could have categorized them in three basic ways something failed people failed no in this case Mr Meeks uh for those that watch Rick and Morty uh technology failed you know this is a very controversial one right now uh nothing against The Ledger people you know guys you know from a security person I tell you it's cool their business team sucks but you know from a technology perspective is not that bad you know it's it's okay um and then the the other part is obviously processes you know you can have the best people in the world the most secure people in the world that do everything absolutely right you can have a great technology that is you know super hard hardened super protected you know bulletproof all those type of things but thing can still go wrong it can you can still get hacked because of something that has never been seen you know things like flash loans that's a technology or an attack Vector that nobody has seen in the world until crypto actually came to life no so that's why you need some type of you know battle plan in this case this comes from the movie Home Alone you know very very old uh movie probably shows my age um you know and this is the battle plan that he had to prevent the um uh well not the hackers they were not hackers to be prevent the robbers to actually Rob the house no he it was all defense in death how we call it insecurity he implemented a bunch of different measures to ensure that little by little we're going to stop uh slowing the attackers start slowing the hackers so that they do not take advantage of or steal things from their house or if they actually steal them again that you end up on that side that they only stole very little and not you know everything that you had in your protocol everything uh that you had into your treasury so w with that said if these are the main causes of you know hacks or the way you can actually categorize uh causes of hacks you know just Implement a couple of things to make sure that these guys are protected no and I'm going to go to that in in a second what I do want to say is that everything or 90% of I'm what I'm going to show right now in the next slide that's the most important one uh it's basically free you you don't have to pay for it you know security doesn't have to be a cost uh at least basic security doesn't have to be a cost obviously if you want better security you want to improve it you want to ensure that there's more you know you can definitely pay for extra Services you know but um it doesn't have to come with a cost so this is basically my last slide before the end so I'm you know relatively going to take it easy you know people told me I'm before lunch so I didn't want to take you know half an hour fully of your time but uh so hopefully this doesn't take much as I run through it so first of all secure your team I do not care if you are one guy two guys or an organization of a 100 people okay get a security Champion get somebody that actually cares a little bit about security and that his responsibility one day a week or something like that is ensuring that you know the protocol the organization your web applications are actually safe okay so get a security Champion second of all make sure that you implement some training I know you know for those that come from a corporate world uh you know and I've had to do like a lot of uh security awareness training those you know terrible videos that are constructed yeah they're they're absolutely boring but there's a reason why and obviously there's a Reas there should be a way that we can make them more entertaining uh the you know how I see security awareness training is teaching you the ways hackers nowadays try to trick you now I think everybody knows about the Nigerian prince you know scam it's it's you know basically in every single security awareness training like let's get over that let's teach people how how uh people are getting tricked nowadays and let's let's uh let's teach people to do security awareness by showing examples no for example Arthur one you know a very big BC guy that got hacked and and stuff like that um you know let's explain those examples you can do everything right and you can still get hacked um you know use secure passwords ideally don't use passwords use some type of single sign on if you're an admin if you're using you know uh AWS and stuff like that use some type of UB key or or something like that multiactor authentication no so teach your people to think a little bit more secure when they do your job yeah um next on on securing your team is um you know also training um I'm not expecting everybody to be Security Experts over here I don't expect everybody to understand how every single hack works and how to be protective of every single hack but if you're a developer if you're an engineer if you work in devops or stuff like that you should at least know the basics like OAS top 10 OAS top 10 will teach you the top 10 most common attack vectors and how to protect them no like um I do application Security in polygon and I am tired of seeing variables secrets and keys in the code like come on guys don't you know how to use a m like like just at least that and obviously don't submit yourm into your GitHub repository no but it happens it happens every single day and I keep I'm tired of seeing it no or things like that or secure input like you know don't you know that you have to sanitize a little bit your inputs make sure that you're not executing X SQL commments directly from your input and stuff like that if you're a developer if you're an engineer just learn the basics AAS top 10 is not complicated um there's hundreds and hundreds of videos on YouTube some are great some are horrible that will teach you um here are some resources so um you're going to you know be able to get a a copy of your of the slides after uh in the next one but basically I like the one published by S5 it takes like an hour and a half and it really runs you down with really good examples of how to do all was you want to do some more um enhan training like how things happen application. security has some free modules to teach you how to secure your we web apps web assets and things like that and then if you're you know relatively a you know 10 person team or even more Amazon has a really great cyber security awareness training that is completely for free it is a fun video it is you know it it I have to admit It's relatively fun sucks having to look at videos but you know they they made it a little bit more entertaining than the typical corporate like oh here's Jane and Jane is going to the office and she is printing confidential information you know like come on you know I there there's some actual fun ones you know that will will drive you some of this stuff cool all of that is free next test and secure your stuff your applications your systems all of those type of all of those type of things no aim for 100% test coverage that's what I'm trying to do as well in polygon it's an impossible task I know it even if you know things like cold C or coverage tell you it's 100% coverage you know it's not really 100% coverage but aim for it ensure that you're doing the most amount of testing as possible uh into your applications web apps as well as smart contracts especially smart contracts no use security scanners um you know there's a there's there's I cannot tell you specifically for like web apps react JavaScript even PHP I don't know who uses that but you know even PHP and and some other Technologies there are a bunch of security scanners that can be used in order to detect and they're all free you know you can use them they're very good they're very concise and they even give you recommendations if not solve your Cod automatically and last but not least penetration testing security audits I know it's a little bit controversial some of it is you know can be potentially expensive but penetration testing doesn't have to be expensive like you can get a pen tester on Fiverr for like 50 bucks uh I'm not going to tell you it's the best guy in the world but at least he will probably do the basic scraping and will detect if you actually put a m in uh in your code know so uh please uh you know just just just just do some basic stuff from a security audits perspective um there's a great Twitter thread that is going to going be a referenc in the next slide that basically talks about U you know how to do security audits on a budget if you don't have a budget at least use chat gpg I'm sure that chat gpg will detect like the most stupid stupid stupid uh code errors and vulnerabilities on your code if you have let's say 200 bucks 500 bucks to uh to spend on an auditor hire a a freelancer there's a bunch of Freelancers that come from C4 no code for arena or some of the other Sherlock um I forgot and you know they will do an audit for 500 bucks 1,000 bucks it's good it's a good uh system of defense and obviously if you have more budget if you've raised enough funds and stuff like that go for some you know some good auditing company it doesn't have to be a tier one like you know all the flashy ones that you see in Twitter you know that that polygon uses or un swab uses there are nowadays so many good auditing companies look at the people that work over over there look at the team they use um obviously things like code for arena I think are really good they wouldn't be my first uh choice of an audit to go for code for arena I would first use a normal auditor company or something like that and then in parallel or you know as a Next Step then do something like code for orena uh because it really depends on who participates no maybe you know if you do a code for arena uh test on Christmas I'm not sure a lot of hackers are actually going to do do we do that or if you do it if you put it if you schedule it during ECC uh or or you know if Devcon or stuff like that I'm sure the guys have something else to do than actually look at your code on code for arena uh so a couple of resources here code cough all of them free foundary Forge to do your test cases uh I'm not sure if everybody knows but sonor Cube I'm a fan of sonar Cube obviously I come more from the web 2 side of things uh but I've used sonar cube a lot it is absolutely free to use it you can create your own instance either from yourself uh install it even on your laptop and it's an amazing security scanner for web applications and almost every technology go goang Java C++ um even PHP and stuff like that so uh yeah Sonar cube is amazing obviously in the solidity side of world in smart contracts we still don't have really good security scanners and testing tools you know slit so far is still you know one of the best ones look at the different plugins and um you know parameters that you can set over there but again it's all free no there's no reason why you should not be using that uh it's also a waste of money uh because if you're hiring a a security auditing company the first thing they're going to do is going to throw a slitter or you know a sonar Cube or stuff like that and that's a waste of time why do you want the auditor wasting you know half a day or a full day running those scanners when you can run them your yourself and solve them you know ensure that you're you know spending your money appropriately um Keys Secrets you can use GitHub secret scanning you can use uh oh sorry I skipped the sneak and dependabot so dependencies a lot of hacks in the traditional World also come from dependencies uh a lot of issues U you know coming with SSL recently in the last couple of years that's all dependencies and it's so simple to solve it just use sneak use the pandabot um ideally have it to automatically upgrade with you know with testing obviously but automatically upgrade your dependencies um GitHub secret scanning great tool to detect keys on your code uh you know even private Keys uh so that they don't get exposed G Guardian as well has a pre uh a free um uh version of it truffle hog um what else and you're if you're using AWS or Google to host some of your infrastructure um a AWS security Hub is free free now obviously you're paying for AWS so it's included inside of it h Google security commment Center is not free uh you actually have to pay for it it's not that expensive to be honest if you're already paying for Google services it's not going to add up uh much more into your bill and it's really good honestly it will just look at your whole infrastructure give you some recommendations and in most cases it can automatically solve a a lot of those things so you don't have to be a security expert again anybody in your company you know from an that has some engineering experience development experience uh can actually run these tools and um you know just just solve them and incre decrease your attack uh surface last over here um best practices and standards um you know when I joined crypto I I've been doing crypto for you know a lot I actually mined Bitcoin then lost at computer and you know through everything this stupid thing why would anybody use it and then ethereum came and it's like oh okay this uh this is a little bit more interesting um than Bitcoin to be honest uh where's that old computer ah yeah no didn't exist but um you know where I'm going to is a lot of these a lot of the issues that we see nowadays have been solved you know we don't have to reinvent uh incident response process we don't have to reinvent how to do vulnerability management we don't have to reinvent How We Do change management all type of things there are standards yeah if you do not know how to you know like have an incident response plan chat gpg hey chat gpg can you give me the 10 steps for a good incident response plan it will give you the 10 steps for a great incident response plans you know and stuff like that so um you know follow best practices use GitHub actions to automate as much as possible things inside of your repository uh create some CICS if you have Dev guys or if you are the devops guys into into things like that you things like automatic deployment so you don't make mistakes when you're deploying a new version of your uh of your dab or of your application uh use Branch Branch protection I you know I wanted to do and actually I didn't have time check around all major projects in in just like the crypto space and uh figure out who has Branch protection if you don't know what branch protection is it means basically that uh you cannot commit uh a code change directly into production basically no and that actually you need to get approvals you need to open a pool request you know just that it helps verify that nobody is putting anything malicious and that also you're not putting anything that has uh um code issues uh bug Bounty and responsible disclosure programs again you know pen testing testing in General Security audits they're just a snapshot in time you know they're testing your codee at that specific moment and you're going to make changes and spe specifically in crypto and just technology in general you know we're moving faster than we can actually test and verify applications so uh Buck Bounty responsible disclosure programs are a great way to make sure that you have other people looking at your project and uh again also very controversial uh but you don't have to put million doll bounties if you don't have them you can also put like 10 ,000 bounties $1,000 bounties $50 bounties now obviously the amount of the bounty will tell you the amount of hackers you actually are going to get looking at your code but it you know at least have a way for people to report stuff okay because there's actually good people in the security Community not everybody wants to steal your money there's actually people that want to actually help make your protocol more secure and I've heard this time over time like does anybody know a contact on this project I found something and I don't know how to report it like I don't want money I just want to make sure that the guys fix it there is a lot of people like that I promise you um change management incident response um at polygon for example we just rebuild our changes to our contracts like if we need to on board offboard a validator set or we need to I don't know change the stake in you know what is the uh amount of Matic that you need to be uh staking in order to become a validator and stuff like that those are changes to Smart contracts those smart contracts hold a ton a ton of money and it's not only the money it's just the fact that you know they control certain aspects of how the protocol works so we have a 13 step uh uh process in order to make changes to our contracts no and between those 14 steps there's at least four of those that are security steps mean meaning there are AIT checks there that means that checking the call data checking that the guy that submitted the transaction is actually allowed to submit the transaction checking that the guy that submitted the transaction actually submitted the appropriate data in the transaction cuz he probably copy paste but you know he can make mistakes and stuff like that you know unfortunately in crypto and when working with multi6 and stuff like that it's not that easy especially if you're not good at it and it's very prone to error so just you know make a little process you know about every time you make a change you know just just um you know that that that you follow the same steps and uh that comes to something I learned in my previous job where um the CTO told me this is like if you do something more than two times uh the same thing more than two times write it down and it's a process it doesn't matter if it's three bullet points if you did it twice write it down because I'm sure you're going to do it again yeah and that's how you go and then you go improving it and then you add another step and you add another step and you add another step and in a couple of months you're going to end up in probably polygon having you know 13 steps to actually make a little change into a contract but that ensures that that ensures that that we're not losing anything and um well took me more than I expected but and uh what else did I have over here incident response I already said chbg will build you a great incident response plan uh so couple of resources over there how to set up Branch protection Cloud Fair please don't use name Chap and if you're using it please use multiactor authentication and domain protection uh but if not Cloud fair is free and it provides you a lot of other tools to protect your DNS to protect your uh um domain um yeah hacker one Buck crowd immuni in terms of you know Buck Bounty uh programs and then um yeah the vulnerability disclosure put a security do uh MD file into your GitHub or into your um domain so that actual good hackers know where to report stuff that they find so that was it um here's a couple of extra info that I really like and I always uh recommend to people asking me for stuff like a high hitter guide uh for the Galaxy or two security by Emiliano bossy great great uh information over there uh some application we application security checklists if you have a web app uh some upsc you know like you're all in your conferences over here I'm sure you're all flashing your ledgers not like crazy oh yeah I got a million dollars in my ledger you know that's that's great upsc over there um I don't know how to do this one the how to do lowbudget audits that's a really great resource know even with recommendations of different Auditors depending if you know how much you can pay for it uh Dey hack lags I love this one if you're actually interested in producing hacks that happened in the past uh this guy over here or this company over here actually put together a way to uh simulate or recreate all these hacks that you know have been happened in the last couple of years and last but not not least you know smart contract auditor guide um this is our you know uh um just an aggregation of a lot of uh Audits and findings from audits that have been found over the last couple of years on many different platforms so um there's a q code if you want to get the presentation immediately I'm sure you know if not they're going to be available somewhere in the conference site and stuff like that um yeah I I I hope uh that that this was useful like like please please please don't fall for the stupid things like if you get hacked like get hacked properly find a new attack Vector like you know like cool man look what this guy actually did this is absolutely new and don't be the dumb one that actually submitted their AWS key into GitHub or you know stuff like that because it happens and it happens a lot and it's it's sad that it happens because it's so dumb so yeah if you want to follow me on Twitter I do not post I only retweet stuff and obviously I just you know browse and you know have fun of the crypto drama um that was it uh I'm hungry so I hope you guys are too and thank [Applause] you
