# In Crypto we don’t trust: how protocols approach security | Panel | ETHDam 2024

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2024-10-07
- Duration: 34:56
- Watch: https://streameth.org/watch/yt-p9SoRmuwJ8k
- YouTube: https://www.youtube.com/watch?v=p9SoRmuwJ8k

## Description

Join panel discussion “In Crypto we don’t trust: how protocols approach security” with Jack Sanford from Sherlock, CvH from Polygon, and Kadmil from Lido at ETHDam 2024. Moderated by JJ.
https://twitter.com/jack__sanford https://twitter.com/cvhessert https://twitter.com/kadmil_eth https://twitter.com/jpknegtel https://twitter.com/sherlockdefi https://twitter.com/0xPolygon https://twitter.com/lidofinance https://www.sherlock.xyz/ https://polygon.technology/ https://stake.lido.fi/ 

ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. 

In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. 

ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich.
Keep up with us to see updates on future events: https://www.cryptocanal.org/ 
Follow CryptoCanal on X: https://twitter.com/CryptoCanal
Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity 
Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz

We would like to thank our partners that made this event possible. 🌷
Battleship Partner 
🛳Oasis Network https://oasisprotocol.org/

Jet Ski Partner
🛩⛷  NEAR https://near.org/

Canoe Partners
🛶WAKU https://waku.org/
🛶Trail of Bits https://www.trailofbits.com/
🛶Avalanche https://www.avax.network/
🛶Privacy + Scaling Explorations https://pse.dev/en
🛶Threshold https://threshold.network/

Our Canoe Partner & Official Node Provider
🛶dRPC https://drpc.org/

Sponsor
🤝EF Ecosystem Support Program https://esp.ethereum.foundation/

Paddle Partners
🚣ChainSecurity https://chainsecurity.com/
🚣Lido https://lido.fi/
🚣Cyber Capital https://www.cyber.capital/
🚣Diva https://www.divastaking.net/
🚣Firn Protocol https://firn.cash/
🚣Beefy https://beefy.com/
🚣0xbow https://www.0xbow.io/
🚣Obscura https://obscura.build/
🚣Panther https://www.pantherprotocol.io/
🚣Maven 11 https://www.maven11.com/
🚣Zama https://www.zama.ai/
🚣zkSync https://zksync.io/
🚣Secret Network https://scrt.network/

ETHDam AfterParty Fren
🥳Bitvavo https://bitvavo.com/en

## Transcript

[Music] very excited to be here again today this time I'm going to I'm going to be moderating this one panel today so that's all you have for me um thank you very much darling for doing today very looking forward to it um so we're going to have a panel discussion about security uh so in crypto we don't trust how protocols approach security and uh as was very surprised by this lineup because I think it's pretty [&nbsp;__&nbsp;] dope um so I'm really excited for that so can I please invite to the stage Jack CVH and CAD Mill please and you can sit down grab a microphone um I can see there's two microphones so we may have to share um but yeah so woo [Applause] yay mati please don't judge us hello hello um so yes so the way this is going to work we're going to chat chat ship for like 20 25 minutes and please ask the questions on slido because again as I said yesterday and today these people are here for you so if there's any things that you want please put it in slido um so to kick things off thanks ever so much for being here this morning and um yeah can you each give a quick introduction of yourself and keep it lean mean and sweet yeah quick I'm uh Chris cbh as well I work for polygon I'm a VP of security over there and and um yeah I've been with polygon for like 2 years hey guys I'm Jack I'm the CEO and co-founder of Sherlock um Sherlock is one of the big audit providers out there we specialize in audit contests and we also offer um smart contract coverage after the audits we do hey hey uh I'm cill uh I work for the Ops Team in later down so dope thanks ever so much for coming so to kick things off in your own words why are external audits necessary and valuable uh yeah that's a tough one um I would say yeah F allit no um they are necessary but they're not all inclusive so they are not a guarantee on security I would say it is just a checkpoint in time that actually tells you you know hey things look good they conform to the standard you pass the basic checks doesn't seem to find you know General type of things but I wouldn't say they are necessary I wouldn't say that they are the only thing you should focus on and if you have limited resources limited people um you know just just maybe don't even get another it and focus on some other areas of security but uh yeah maybe my uh Partners over here may think different um yeah I think once you have the context that you can never prove that any smart contract is 100% secure that helps put the right context on audits they're not going to be you know the end all Beall of security um but I think why external audits are valuable is because if you're a team even if you have you know someone on the inside doing security um you can get very familiar with your own codebase you can start making certain assumptions around it and bringing in somebody who has a totally kind of independent Viewpoint coming in with fresh eyes is able to we've seen this in data kind of find you know bugs that uh others aren able to I'd say it's uh I fully agree it's audits are not like Silver Bullet uh but uh basically if you're trying to build something very very very transparent you want to have third party verification of what you build like holds water uh so there are two questions whether like it's doing like auditing or doing any particular security thing uh is doing uh is getting Code 100% secure and like it is not uh but from another Point having third party verification of like someone looked through the code and it's like works and that's what's on within is very valuable and Ju Just to make a point like I hate the fact that we use the word audit for these type of Assessments it's terrible it doesn't represent exactly the job that the security researchers like you know the people that work in your team or the the Consultants do uh and audit is basically a check against the standard ISO you do uh audits on ISO 2701 you do audits on SSA 16 you don't do an AIT of a smart contract you actually do what it would be called a security assessment uh even we could use the term penetration testing because that's a lot what security researchers are doing when they review the smart contracts so I know it's impossible now we you know it's done it's called security audit in the web 3 world but uh yeah I think people should understand very well what that actually means no well and well on that note um what other questions do you think people should be or projects should be asking their Auditors other than just a PDF report yeah I can you want to go I can uh start off on that one so we've done you know hundreds of of audits and and audit contests and I think we have a good sense of what the right questions are to ask us or to ask any auditor um the first one is that an organization cannot do an audit every audit is done by individuals and so you need to know who the individuals are that are going to be looking at your codebase so that you can know okay you know the next question is does this individual have relevant experience on similar code bases you know is there a reasonable reason like likelihood that they'll be able to find bugs in this codebase and understand it um and do they have experience finding bugs in similar codebases I think those are kind of good questions to start with because audits are done by individuals I have not another Viewpoint basically um one of particular things we have been asking the audit teams like do doing uh security research or P testing for the codebase or like you name it unfortunately it's really called security AIT in Industry right now basically uh for like for what D is doing uh having ver verification of not only like that's GitHub commit is saying and adopts the spec and works well uh particular think we're asking is where the addresses of contracts deployed to main to actual blockchain uh is the same uh contain the same code as uh what auditor has audited so you want the full track of record not only between code and audit report and whatnot but uh you want uh for like the voters for holders or general public to be able to actually track uh if on chain code is what auditor audited and what like they think is saying so uh this third party verification should go all the way from the code to onchain yeah that's a tough one I completely agree it's it's a tough one to do obviously cuz uh it's very very technical most people especially investors users and stuff like that will not be able to easily figure out like from GitHub all the way to uh you know the buy code of the smart contract if anything has changed you know if it has been audited I think there's a lot of um uh companies and even there's a security team trying to solve that problem as well uh but it hasn't been solved so if there are any uh Builders over here that want to abstract what the security teams are doing and making it easier for a user to be able to verify that what's deployed has been audited that it represents what is on GitHub that uh represent that represents as well what you see on the web page itself uh you know please solve that problem yeah just quickly on that I think probably we've looked at a few examples but probably 90 to 95% of the audits you see on a team's website are actually a different version of the code than is deployed which lot of users probably don't 100% 95% ours are good it's it's it's a huge personal pet peeve when you go to like a website that's kind of like coin market cap and you see that they have this audit list and it's just such a full sense of bollocks um uh so yeah so uh audits are great as you've mentioned pen testing whatever we want to call it maybe we can end the day with a new term if anyone has anything please tweet it um what happens when something goes wrong could you share maybe like maybe a story or or maybe something that's happened when something's gone wrong and kind of the feeling the the I think there's a very emotional reaction there's an adrenaline reaction when something like this happens and I'm just looking to maybe share some of that with the audience of of something that's happened to you guys you don't have to get too into into the weeds but uh yeah yeah think I've been through a couple of them in web 3 and web two over the last basically 20 years of my life and what I can tell you obviously the typical Don't Panic you know be be like Napoleon you know Dress Me Slowly you know I'm going to hurry all those type of things but you're going to panic you're going to freak out and I think the best thing you can do is try to reach out that to somebody that can help you if you don't have a security team or somebody responsible for security reach out to the community reach out to your Auditors reach out to anybody that you know you know around there don't shut up don't try to solve the problem yourself ask for help I think one of the things that I've seen in web 3 more than web 2 is the commod that the security Community has it is amazing it is the amount of free hours of consultancy free hours of Investigations free hours of support when a protocol is you know being attacked or anything like that um I I haven't seen that in anywhere in the web 2 world so don't be afraid of asking for help don't think that you know it's it's it's not about getting hacked like everybody's going to get hacked it's just like death you know it's it's it's part of the life cycle of of of being on the Internet or everything else but it's really you know people are going to criticize you around how did you react to that hack how did you react to that issue that you confronted if you reacted it by acknowledging it asking for help dealing the doing the right things your users are going to come back I I'm absolutely sure about it if you did the wrong thing and you hide it and then people started figuring out on Twitter and you know like no that's that's that's a way for you know just yeah I would agree with that I think uh you know hiding it hopefully less and less Auditors are kind of staying uninvolved I think that was kind of a problem maybe a couple years ago you know not to shill Sherlock too much but we are very deeply involved with every single potential security incident that's happening with any of our our customers um especially the ones under coverage because we're fully aligned with making sure that damage is mitigated and anything that's happening you know can be addressed as quickly as possible so we'll help set up the war room we'll do all these different things that need to be done as soon as possible afterwards and I think we've posted on Twitter every single time there's been any kind of potential security incident related to a Sherlock uh audited code base um and yeah I hope that more Auditors move in that direction over time uh don't want to share like the Integrity of the story but uh we we actually had I I had a conversation with with audit team uh for like one of Special Projects we did couple years ago uh with folks literally asking okay you have like too much tvl in that thing and we are working on upgrade and what if something goes wrong we like we can't it was literal question like we can't pay it which like of course you can't like team can't either so like uh and as Story Goes something actually went wrong but not like for all the uh to tokens uh under the specific projects management thankfully but still uh upgrade process missed uh some small part uh we figured how to mitigate it we figured how to make users whole and how to compensate uh for losses in like for it wasn't losses it was like locked in something is locked in in contract but like that was an actual question we went to the team auditing the thing afterwards and said okay there was an issue and we we have figured it out uh but uh like that's been quite a long time ago actually um so things go wrong and you have to go figure you have to like either have a strong security process strong instant response like team uh inside or uh if you you can collaborate that's that's also awesome because like that's a skill which is very hard to acquire but like apart from being in worms for quite some time i' like to add as well and I'm I'm you know I'm to blame as well on these type of things share also the things that happen even if you keep them private or internally with your Auditors like it's it's it's completely normal they will understand it uh you know that they missed something it's it's normal you know and all that is not you know on 100% coverage on security but share it with them else they're never going to learn they're never going to understand okay what did I miss why did I miss it is this a new attack Vector now web 3 is very new smart contracts are very new decentralized technology or distributed technology is very new uh we need to be able to understand to standardize you know and to figure out you know basically write down all the different possible attack scenarios CU that's really what also what I ask an auditor especially if they're an individual know if I hire like an individual or something like that what's your methodology do you use a checklist show me your checklist what what what things are do you cover know when you look at it what's your strong point you know are you defi guy are you you know an NFD guy do you know lending you know do you understand you know whatever those type of things so yeah that's fair and um Jack you're not allowed to answer this question um but for Chris and kadil you know what do you think about the model of of Auditors actually standing behind their audits in a way that Sherlock does where they're actually putting their own cash on the line uh cuz I think this is a much broader macro discussion about auditing in general um there are some people in this room that don't I think that's that's very great uh why because like often times in uh defy protocol um design you look to align incentives and putting something like put putting skin on the game uh is aligning uh incentives to a significant degree uh so that's very strong even if not like most likely not in financial sense because like the lever of uh being security firm or being like a protocal development team uh and actual tvl users put in is is is enormous so like I don't think as as with audits audit is not like Mark of security it's Mark of something else quite a lot of things but Mark of quality but never mind uh like this insurance is not insurance for tvl in general I think that like there's just not enough money in this market uh but in a sense that's like very real alignment of incentives and that's really cool I would say start looking for a new job cuz that's going to be tough to continue over time to be honest um yeah I I like I I like the model I think it's great that there are other security companies as well that have said like oh if somebody found a critical know on on any of the things that we audited you know we'll pay you 10K or whatever it is like yeah I think you know it's more to shill than anything else while you know a good incentive uh it's not sustainable over time I don't think that we have seen the the magnitude of what hacks can actually do we we've definitely seen a lot but you know the space is very small there's not a lot of total value locked in a lot of these protocols imagine if we in 10 years from now we you know 100x the the total value locked um that's going to be tough to sustain an an insurance model or having to pay for hacks um that means also there's going to be even more State actors right now we have like North Korea maybe looking for some money or China or stuff like that but you know in in 10 years time every single country will be looking after you know bugs or vulnerabilities in these protocols because North Korea is going to be on chain and China's going to be on chain and the US and Europe are going to try attacking them and that's going to be cyber warfare it's already happening right now it's just not happening inside of um you know the onchain economy Jack I will let you say something for sure yeah thank you um so you know to CAD Mill's point I think it's really interesting that both polygon and Lio have you know billions of dollars at risk essentially um and there's no coverage protocol there's not even any traditional Finance actor that would ever be able to kind of take on that full amount of risk uh at least not in the near future so I think kind of the middle ground or the first step that Sherlock has taken I think others hopefully will take as well is putting money on the the bug Bounty so like when you put a bug Bounty live and there's code live that is a much more manageable dollar amount usually a million dollars for a fairly high quality protocol I'm sure these guys have even bigger bug bounties than that but that's something that I think is more realistic because a lot of teams have 250k bug bounties or something and I think Auditors can get a lot more involved in having skin in the game and and uh putting money on the line to help those payouts but you need to make sure that the code that is in the book Bounty and the code that is live is actually the code that you audited and as we talked before most of the code online is not the same version that was audited uh I don't know I guess that's that's tough I guess that's a tough situation obviously yes so um when Sherlock does this we actually check so we do the bite code check as well which hopefully is a coming in Foundry it sounds like um and I hope that other Auditors you know would also do that you have to coordinate with the team more because the team is obviously going to want to change things after the audit there's a fix review after most Audits and maybe they want to add more features and so you kind of have to stay in communication about like hey what you know what is actually coming on chain and is it the same thing that we audited you know a month ago but I I do like the power the part where you actually you know match the buck Bounty you don't have to match it fully you know but stuff like that those type of things could be nice incentives you know for certain period of time as well good to the last Point uh like maybe even like being responder for uh B Bounty or like being involved in responding to like actual reports would be another like good measure of um incentive alignment uh because there is a [&nbsp;__&nbsp;] ton of bad uh like low quality bug bug reports for smart contacts and for like not smart smart contact so that's another Rabbit Hole uh but like having better filter here and having Auditors piling in and working there could be also seen as very big like incentive liment vehicle would love to go down that rabbit hole but um this is just a question that literally just popped in my mind um on a scale of 1 to 10 how what's the uh what scale would you give on like will AI be able to replace an order zero being [&nbsp;__&nbsp;] AI 10 being our new overlords that can also audit smart contracts I just want a number um it's like six but to what end basically uh the question you are that's not a number we're going to get all the numbers and then we can discuss ah okay eight nine okay that's a lot uh in terms of one uh 0 to 10 likelihood I would put it out a one okay yeah nice it it obviously it depend it depends a lot no what what exactly I think it will replace the 95% of all the security researchers you know uh Consultants that you see on Twitter basically sorry you know you guys are not security people like in basement you're just following a checklist that somebody else made and finding bugs uh so you are going to be replaced absolutely by Ai and all those type of things the people that are really really really really really smart the the good security people the good security researchers that actually understand how security works that actually go and revise you know look at the slots and you know look at the buy code and all those type of things those are going to be tougher to be replaced but they're the 5% of what we see right now in the community I tend to agree and basically the most value you can get in like security practices you take uh are not easily like checklist like checkl get you the first 90% of work and now you have to work for the rest of 90% of quality and uh like making sure everything is like works yeah so I guess to explain the one out of 10 I you know that's kind of like what is what are the chances that there's a a perfect AGI out there that can basically do everything that we wanted to do perfectly and you get into this problem of like kind of like an oracle problem of how does the age how does it know the ground truth and the you know the intentions of a protocol um but I think it you know it will maybe approach 99% like the AI will get that good that it's 99.9% at this kind of stuff but I also think that teams will develop way more complex protocols once they have the ability to do that and AIS can find way more bugs so it's going to be kind of this like war between how good is the AI at security versus how complex can an AI make a protocol and I don't really know how that plays out but I think people building AIS that are good at Security will be kind of the end State unless we get AGI yeah I think it's more about um will the AGI be able to think as a human cuz really the biggest mistakes are made by humans and human error and human logic that's that's really where where the issues are yeah you'll suck um if if yeah know if AGI gets gets really to that level like I'm sure I'm sure there's there's worse things to realize like Terminator is happening for sure like right um I want to apologize for the people that ask the AI AIT questions I just checked slido and that was a question so credit goes to you guys I feel really embarrassed actually um okay I have a couple more questions and then we'll move on to the slido we're going to try and do this a little bit quick fire so keep the question answer short um how has your approach to security changed in the last year any big shifts yeah uh well before polygon I've done two years I was on web 2 and I've I worked in cloud and suffered as a service and stuff like that and I really had to change my Approach cuz if the cloud gets hacked you know basically I just had angry customers that were not able to use my service but uh in the last two years if the blockchain goes down or we get a hacked a polygon I'm going to have very very angry users that have lost all their money so um let's say the stress levels has gone up a little bit and therefore um you know I've I've spent more time thinking about the deployment process and the development process of everything to make sure that by the time we get to onchain this is really really really really secure like there's very little room for error over here no and and I think I've just become more paranoid you know I've already was paranoid I've already been a pessimist whole my whole life I've just got worse on that area my wife is not happy uh uh yeah I'll try to answer this concisely because we've seen a ton of teams doing a ton of different things the biggest changes over the last year are essentially teams are just doing more so a team that would have got one or two audits is now getting three four five audits um a lot of teams are supplementing audits with an audit contest at the very end to kind of do like a bigger you know we've seen more $1 million audit contests this year than than ever before um and then I think the monitoring and threat prevention is getting a little bit more adoption now which it really wasn't a year ago we spend like basically we used to run uh like minimal blockchain action checklist which spans for like two pages uh at the beginning and now it's like five 5 for6 and we have couple more specific checklist for specific kind of things we are looking to do uh so uh or like your comment we're doing way more types of checks both internal and external so looking not only for auditing but for the biggest upgrades we looking for formal verification on like code level or by and looking for that very very like very intently uh and I dividing way more attention to alerting and to makeing Sure alerting works and what not so that's another like big part of the puzzle yeah monitoring definitely and and I think there's so much room for improvement on the monitoring side of things and alerting and there's there's good teams building it but uh there's a lot a lot a lot to improve and I think that's where AI can really really really really help and predict things that are potentially going to happen before they actually happen and it's not about just looking at the bik uh men code is about Behavior hey there's some Behavior here that looks weird you know polygon have a look because this could be bad so cool um sorry I'm just trying to launch a poll because this is going to be a big discussion point so if you guys can open up slido um and we can put slido on the screen um we're going to ask the question for the audience does a do you think or does a a secure smart contract also equal a quality smart contract and one is going to be no a a secure smart contract doesn't need to be a quality smart contract and five is going to be like yes those things are um I hope that makes sense maybe someone can explain it better I just made this up on the Fly uh while people are voting on that I'd like to go to the Q&amp;A and then we're going to come back to this question with also the audience poll um question number one why audit so expensive oh my God yeah listen to me at 12:00 I'll I'll give [Laughter] you um yeah I guess to try to answer why they're so expensive it's because you need people who are the best in the entire world at what they're doing um because if you had let's say all of the black hats you know some of us have heard of North Korea having some smart people who can hack smart contracts over there if those guys are the very best in the world and the white hats the other Auditors can't come close then crypto is kind of we're in a bad spot um and so the reason Auditors are so expensive is because you really need somebody who's in that like a 90% auditor doesn't do you much good you need an auditor who's in like the 99th percentile who can find that critical bug that only a couple people in the world can find and those people have a lot of opportunity and so they're expensive if you had to name that person like Chad or something what would you call them go go ahead no maybe a legend I don't know I think the main reason like why why I would it say as expensive and like teams are spending way more resources on security in general is because of them like lever uh protocols have a lot at stake and a lot of users of like tokens at stake so that's it's really scary and you want to make sure it's like as safe as possible so that's like the market force behind pricing as well it's also about talent I think for those of you that are auditing companies over here is like how do you how do you keep somebody hired in your auditing company if you know if you know if they can go and just become a black hat or a white hat independently you know and make tons of more money yeah there's ethics and everything else but uh you know in the end uh you got to pay them good cuz else like sorry I'm just going to go to Sherlock and be an independent guy I'm going to make much more money yeah uh cool the next question if uh if an audit finds an issues and then you fix those should you ask brackets and pay for a followup audit do customers actually want this yes definitely should be included uh okay you if you fix something and want to redeploy you actually like okay uh in light the teams are following the process which requires you to have an audit even for small smallest changes so that's the case if it's included or not is is another topic and like is a big one but like I tend to agree with you but don't think that's Mutual cool no no yeah for for for sure that was a yes I think um on a scale of 1 to 10 how big is your prequantum encryption anxiety Chris I don't want to bring more anxiety to you sounds like you have enough content computers I I think it's fine in general as long as you keep building the problem is the fact that if you leave Legacy code Legacy encryption algorithms on the blockchain or you know anywhere else on the internet those could potentially be broken in a 100 years so you know those pictures that you encrypted you know with zzip like 20 years ago maybe in 20 years in the future they're going to be able to decrypt that just reencrypt it again encryption goes you know Hand by hand yeah I don't I don't lose much sleep over it but I might be undereducated in this area I think you know if you have a a 20 character address with Quantum Computing the address just needs to be longer essentially you don't know everything about quanton Computing come on man [Music] um cool uh now we're going to discuss the poll so I'd like you guys to turn around and actually have a look at this because what I really like about this is it's very split H which is a nice surprise so it seems like um yeah there's a split there's a huge split and the fun thing is that we were discussing this before this panel this exact question and so I would like you guys to um basically pick aside and uh discuss whether you think a smart contract equals a quality smart contract U no it kind of doesn't I I'm for like closer to one uh why because uh like there are multiple layers of uh if the thing is secure even if the think is secure and if it's like code of good quality and thinking of good quality is another issue but basically you want like layers uh you want auditor to to to to check if the code adorns to spec and you want to like and you want a good auditor to think where respect spec makes sense even so that that's one thing of thinking through things and if it's implemented in good code or bad code is the whole other other thing so that's that's closer to one I guess um yeah I would say you can you can have a quality smart contract that is not secure and you can have a secure smart contract that is not high quality um you know you can have a quality smart contract that does a lot of things well I guess there's a lot of features outside of security that a smart contract is expected to have such as potentially readability or the ability to execute a transaction with low gas you know if you have a very inefficient smart contract then you would call that maybe a lowquality smart contract um but that contract could be very secure perfectly secure even so I think uh you uh there's definitely not a strong correlation between secure and quality think quality definitely helps security it just doesn't guarantee it security has nothing to do you know better security doesn't mean anything quality there's a lot of smart contracts that were built years ago that are horrible horrible use a lot of gas you know revert all those type of things but they're unhackable like like they you know you cannot steal the funds so uh I would definitely say yeah okay I would definitely say like definitely aim for Quality it's going to help your security but don't expect that just because you use good napsack and you know good gas you know uh functions and all those type of nice things that that means that your smart contract is secure it's just going to help it and Auditors are going to be very happy if you have you know good quality code cool thanks so much and thanks everyone for participating in that um I really like how people are changing their answers buggers um but I hope that was informative and got you thinking a little bit uh there was one question that I can get to which was um kind of what are the newest tools that people are adding to their security stack so I'm actually going to ask you if you all can make a tweet after this with some of the tools that you would recommend and just do use the hash eam I think that's going to be the most valuable for also everybody here um but thanks so much for coming this morning and thank you all for coming and please give a huge round of applause for this panel panelist [Music]
