New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Wallet OpSec for the pragmatic - Anirudha Bose | Brave

ETH Belgrade CommunityMon, Oct 7, 2024, 12:00 AM

Transcript

okay good to meet you all Brave users uh so my name is Ani I'm a Staff engineer at Brave where I work on wallets and today I'm going to talk about operational Security in wallets and this is something that I think is really important not just for you all sitting in this room you probably have a framework already but it's also important for nomies because uh if you're on boarding a Nomi and they get exploited they're never going to come back so as uh builders in this ecosystem we have a responsibility towards them that they stay safe in this dark forest and so I'm going to teach you the mindset behind opsc wallet opsc and share some handy tips that you can uh use to protect yourself out there okay so I'm someone who works on browsers uh intersections of browser and wallet so this is what I wanted to talk to you first about I realized that a lot of uh crypto users are browsing in the inab browser of the wallet this is pretty dangerous and I'm going to make my case um so the question is should you use a wallet in your browser or should you use a browser that your wallet already provides and I have have a hall of fame for you this must raise some alarm bells for you so you go to New York times.com I mean uh normally they shouldn't have anything to do with crypto but if you go to New York Times you go to the list of uh websites that it loads like third party links in one of those URLs you'll find that there's a script that accesses window. ethereum Yes you heard it same with CNBC CNBC is uh I think it's loading it's trying to access window. binance something like that I I I forget but the price goes to Tik tok.com because not just uh it not just accesses window.

ethereum and ex filtrates the whole window. ethereum object but it also tries to do Json RPC requests to your wallet in case it's unlocked it can do some uh it can get your accounts it can query various things uh get balances and so on so if this is not real world adoption I don't know what is so what should you do okay before that this is another example I found in a very popular dap I'm not going to name it it's a DEX but I just went to its cookie store and uh when I uh just uh inspected one of its uh properties I saw that I see my wallet address there which is pretty shocking because that's this cookie is for use by a tracking analytics website called mix panel if you know about mix panel so this analytics website has your wallet address and knows everything about you this is pretty shocking so what should you do the first thing is uh understand that if you're using the inab browser of your wallet or any other inab browser for example if you use the X app it has an inapp browser it has the same kind of issues so it exposes you to a lot of problems that you may not be aware of so you can self audit yourself on this nice website called uh covery your tracks. e.org it's by Electronic Frontier Foundation uh so do an audit see if your browser has uh some fingerprinting resistance uh try to use ad blockers so what most ad blockers will do or rather what we do at Brave is since we cannot block individual tracker scripts JavaScript we cannot uh restrict the execution of a script that has already loaded what we try to do is for known scripts we redirect the URL to a dummy script that does nothing so if there is uh if you visit New York times.com and it's trying to access your window.

ethereum we replace that whole malicious or sneaky script uh and replace that with something that does nothing but doesn't break your browser at the same time um clear cookies on closing tabs it's a setting that most browsers are able to do so even if the DAP is trying to exfiltrate your cookies uh uh your wallet uh addresses through cookies you can at least be sure that once you close once you're done with the browsing it's no longer with them and uh last lastly uh there's a private uh you can access your wallets in private mode just go to chromium settings extension settings and there's a way to enable uh extension access in private window so you should definitely do that if you're worried about uh the website tracking you but note that even in private mode the websites can still track you through a variety of means uh but most importantly being your browser should come with fingerprinting resistance and there is also a website U forgot to mention here but it's known as privacy test.org which lists down all the different popular browsers out there and Compares what kind of protection each browser provides versus others so blind signing transactions this is something even I am guilty of do you know what this transaction does uh this uh it's by the way it's one of the most popular transactions out there in ethereum and like I'm someone who can understand call data but just by looking at it I I don't I don't know what this does for all I know this is a transaction that can totally drain your wallet um so we need better user experience that tells the user upfront what's happening with their transaction or what it's capable of doing at least uh and even like uh maybe you can inspect the contract address and uh be convinced that it's not a malicious one but let's be honest no one's doing that um even if you go to Ether scan it's often not able to um parse really complex hex blob and this is also one of the I mean after the fact that it's included in the blockchain it's too late but it's especially when you're about to sign a transaction uh wallets should be able to do that so here's something that we did so uh this is an example of Brave wallet what we try to do is pass the transaction call data to extract meaningful information not just that but also uh present this information in a way that the user can understand and audit this is how we keep users safe um it works not just for transactions are initiated from the wallet but also arbitrary transactions that you can do through any da this is the example on the right is from a nice de known as matcha so here's something else that you can do uh what you can do is use something known as Transaction simulations what it does is it Forks the network and tries to dry run the transaction observe the side effects it has and produce a difference between uh the original state of the blockchain for your accounts and what the transaction did and show a difference you can see on your screen so if you can try to use wallets that have simulation feature or if you don't uh want to use such wallets then there is an extension called Blowfish and uh I think it's free to use but it works like a side car so along with your extension it'll pop open a simulation window that let you see what the transaction is doing this is not entirely foolproof uh there are ways to trick uh simulation extensions but uh at least it it provides something so on the left it's a DEX transaction on the right what you see is an ec20 approve um you may have seen a lot of examp examples where someone uh allowed a contract to spend all the nfds in a collection uh at least uh a simulation can help you preview what the transaction is about to do so and finally I mean this should be obvious but uh uh we should always verify the ETL plus1 component of the URL from where the transaction is created you can do that when you're connecting a wallet uh in this case you can see that sorry you can see that it's uh highlighted here and uh also when you sign a transaction it's typically very clearly mentioned but uh I think what wallets do and this is something that we are also going to add pretty soon is have a reputation checkm Mark or something uh just beside the et+ one but yeah always verify that uh this is even trickier because um when you sign a transaction it goes to the blockchain uh gets confirmed but uh when you sign an offchain message you don't even need to be connected to the internet uh while you're are signing the message so what happens is a lot of daps they uh they request you to sign some random hex like that which doesn't really makes sense so if you don't understand it you think it's probably uh probably makes sense right so this is an example where Kevin Rose is a nft afficionado someone as expert like him if he can fall for this this is a malicious message that resulted in uh his nfts uh getting uh sold on open SE for pretty much nothing so lot $2 million on that so if this can happen to him it can happen to me to you especially to nomies so what should you do you should think twice before uh you should actually verify which dap is creating this message request another example so we want to have a web tool like experience in web3 and sign in with ethereum is a good example of that but even um signing with messages are not that readable it has nons chain ID version like they have time stamps in a weird format you don't even know what that means uh so what we try to do in Brave wallet is uh not just parse it and display it in a nice UI but also if any of the message Fields doesn't match to the origin of the of the message then uh we raise some uh we show some errors so it's uh I mean it's something that every wallet should do and I think we are not doing enough as an ecosystem but uh we'll only have people coming from uh web to switching over or have specs like sign in with ethereum used in traditional websites if we can offer experiences like this this is even more bizarre like on on the left you have a transaction it's it's a it's a it's actually a message signing request that does a gasless swap so the contract you're interacting with can already spend your assets uh and this message is basically providing the authorization to do that but on the left you can see that it has a bunch of gibberish which it's not it's impossible to understand this but also this is one more counter measure that we have rolled out is ability to understand this message passing it is not that uh difficult and but the uh the main uh value Edition is the UI that the user can easily audit so yeah this is a cow swap order by the way and yeah I found this example from X2 Y2 I don't know what this does do you really want to sign a sh 256 hash of a message message and you don't know what it does probably not so if you have such a request message signing request you should probably not sign it or at least uh verify whether you are providing this authorization to a trusted dap or domain by checking the ETL plus one all right so this is far more common than I originally thought and recent ly uh someone I knew fell victim to this attack an address poisoning attack which kind of uh uh motivated me to talk about this so the idea is that now that we have a fantastic way of generating addresses where the initial the first and last few characters can be similar or be exactly what you desire is just Brute Force you can generate addresses that are very similar to um the ones that are uh in the transaction history of the victim or the potential victim so what an attacker does is uh checks these addresses and just does some zero value or negligible value transactions so that in the hope that the the the victim is going to copy the destination address from the transaction history and believe it or not this is a very uh is a highly uh uh is is it's an attack with a high success rate I don't believe it but even I have copied addresses from transaction history and by the way uh you should never trust addresses in the transaction history or transaction history at all because ethereum doesn't have a vanilla or native way to like a native index from addresses to transactions so always remember that you're relying on the generosity of third party apis to show you the right transactions and if they're not doing a good job or they fail to detect an address poisoning attack then you're pretty much screwed so lesson is never copy addresses from your transaction history uh use a use an address book like have a notepad or a lot of wallets have a dress book feature already um the second one is easier always use test transaction that doesn't matter if it's to prevent address poisoning in general it's a good practice to do uh try to use enss domains if you can um these days you can get a free ens domain or subdomain uh that's that offered by many wallets so uh if you can by all means uh use them and finally uh there are some wallets who can detect poisoning uh attempts so if your address is is poison it get it it shows you a warning or if you're trying to send to a poison address it shows you a error or something right before you're about to sign but even you should not trust those uh or not rely completely on those extensions because uh they can have uh false negatives okay so uh I mean I'm a big proponent of Open Source but it should be obvious to everyone but let me show you an example to drive home the point this is about a wallet again I should not name the wallet but it's obvious from the slide it's a salana wallet that got drained users funds got drained uh in a span of two days worth 4 million that's a lot of money and you know why because uh they were logging some stuff uh and sending it to the uh to the in-house logging servers and the logs had the 24 or 12w recovery phrase which is shocking it wouldn't normally happen in an open source wallet the fact that it it was a closed- source wallet uh was uh the reason why this exploit existed in the first place because the developers would think they can get away with a lot of stuff uh but then uh if you follow uh this kind of uh security principle than uh like security from being close Source then it's only a matter of time where someone figures out a way to exploit it so I came up with a with an idea of shinger wallet uh it's is just to provoke you to think that if your wallet is closed source and you cannot really know if it's custodial or non-custodial so you should assume that it's both rather I would say you should assume that it's uh custodial but yeah we get the point so what should should you do uh first find out if the wallet your favorite wallet is open source or not um shockingly I didn't include it in my presentation but uh if you take a list of all the popular wallets out there like top five or top 10 wallets more than half of them would be closed source and maybe uh 15 or 20% would be would not be using open permissible licenses so you can see the code but you cannot do anything with it so yeah uh understand the risks of close Source software especially when it comes to crypto wallets and try to use wallets or stack that's uh that follows open development processes uses permissible licenses it's not just open to see but also open to modify according to your preferences and that has public security audits uh very important so a lot of us uh uh just use daps which which ask unlimited approvals and we just blindly say yes take it uh what this lets uh uh these smart contracts do is ability to spend all your token balances so avoid granting unlimited approvals ideally you want to uh you want to edit the approval request to just use as much as your balance at Max more than that doesn't make any sense it's just exposing yourself to uh security risk and yeah in general try to use same long-term values so that you can save on gas if you're worried about that doesn't make sense on l2s but if you're worried about it by all means uh go for it but never use unlimited approvals um there's a neat tool known as revoke docash it allows you to audit uh all the approvals on various smart contracts uh not just uh token approvals but also permit signatures permit two signatures and uh and uh yeah you should use it periodically so last is uh Hardware wallets and having worked on Hardware wallets before Brave uh I can tell you that I mean if you if you have a portfolio value that's exceeding the cost of standard Hardware wallet please get it uh forget about airga computers because it only offers a mental satisfaction uh because the air gab computer can of course it can it can uh restrict access to the external world but it still doesn't protect you from Bad Randomness and uh to uh explain the point further you can consider the uh use of paper wallets so never ed paper wallets by the way uh one of the most popular paper wallets in Bitcoin was vulnerable to bad Randomness for a very long time and it was the top search result on Google for like years uh the idea is that the paper wallet is deterministically going to generate some uh 24 words or 12 words that the attacker controls already so it doesn't matter if the computer is a gapped or not it's uh yeah it's going to be uh it's going to drain your wallet at some point uh never enter your 24 words this is again very obvious but never enter this these 24 words outside the hardware wallet and uh most hardw wallets have this recovery app if you're paranoid that you your 24 words do not work anymore you can put them there and check if uh the uh 24 words result in the same accounts uh and I mean this is probably the most important point is uh verify what you paste and not what you copy uh because you should always operate with the assumption that your clipboard has been hijacked what you're going to paste is something that's controlled by the attacker so uh always verify that and not just the first and last few characters of your address that's the whole point of a trusted display the hardware wallet and uh finally if you ever lose your Hardware wallet just go home get a new hardware wallet sweep the uh the entire fund into a fresh seat because um believe it or not a lot of these hard wallets especially the ones that do not use secure elements they are not designed for physical safety so if I have physical access to a hardware wallet it takes an equipment of under $100 to extract the seed from it unless it's a it's a hardware wallet that's specifically designed for that uh so to conclude should not worry too much about the market sending the crypto price to zero uh because there's a higher probability that you'll lose it all in an attack if you're not being careful uh be aware of what you're doing what you understand and especially what you do not understand be choosy be choosy with your wallets with the daps you interact with and finally always have a protocol to follow uh like a plan whenever you are transacting on ethereum and mitigate your risks uh thank you so if you have questions we [Applause] fre cool thanks uh great presentation first question is short do you have any hardware wallets you recommend that are secure even if an attacker has it if they steal your Ledger or whatever yeah a ledger would be a hardware wallet that has a secure element protecting you from that there's also cold card so any hardware wallet that uses secure elements go for it uh but again a lot of users do not have that as an attack Vector if you're never taking a hard wallet outside home probably good with a treasure or any open source hard wallet okay and then I just want to uh give like a personal anecdote so you mentioned the address poisoning and in our safe we received ARB and an attack haer deployed their own ARB token and sent the same amount to our safe and it was like within 30 seconds and so our safe history showed both and there was no way to differentiate because they had mined like enough of the address and we're so confused and it was wasn't until we went to the block Explorer and saw a bit more of the address that we real because we thought like our had sent us Twi two transactions of their token so anyways yeah add just poisoning is is super common now yeah yeah yeah did you get exploited by the way no no no no no no no we we had nothing to send back but we were confused why we received it twice and then it obviously turned out the second one was just a shitcoin extremely common yeah yeah any other questions do we have any more questions well with that being said any congratulations and amazing talk let's give it up for Annie

Automatic transcript — names and jargon may be misspelled.