Sherlock│What is security in Web3│ETHDam 2024
CryptoCanal·Mon, Oct 7, 2024, 12:00 AM
Join Dan from Sherlock for a talk “What is security in Web3” at ETHDam 2024. https://twitter.com/sherlockdefi https://t.co/foLgWtdMiC James Campbell - MC of ETHDam, Hackathon Organiser, and Web3 Developer. ETHDam - a conference and hackathon held in the heart of Amsterdam, Netherlands from April 12th to 14th, 2024, celebrated its second edition, gathering more than 600 participants. In the dynamic space of ETHDam, privacy and security took center stage, featuring groundbreaking discussions on hacks, recovery, and the revolutionary work of figures like Pertsev. Privacy is dead in crypto, people that know, know. People who don’t know, should know. ETHDam is powered by CryptoCanal, an education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zürich. Keep up with us to see updates on future events: https://www.cryptocanal.org/ Follow CryptoCanal on X: https://twitter.com/CryptoCanal Join CryptoCanal TG Community: https://t.me/CryptoCanalCommunity Join CryptoCanal Discord: https://discord.com/invite/XJVjpCqQBz We would like to thank our partners that made this event possible. 🌷 Battleship Partner 🛳Oasis Network https://oasisprotocol.org/ Jet Ski Partner 🛩⛷ NEAR https://near.org/ Canoe Partners 🛶WAKU https://waku.org/ 🛶Trail of Bits https://www.trailofbits.com/ 🛶Avalanche https://www.avax.network/ 🛶Privacy + Scaling Explorations https://pse.dev/en 🛶Threshold https://threshold.network/ Our Canoe Partner & Official Node Provider 🛶dRPC https://drpc.org/ Sponsor 🤝EF Ecosystem Support Program https://esp.ethereum.foundation/ Paddle Partners 🚣ChainSecurity https://chainsecurity.com/ 🚣Lido https://lido.fi/ 🚣Cyber Capital https://www.cyber.capital/ 🚣Diva https://www.divastaking.net/ 🚣Firn Protocol https://firn.cash/ 🚣Beefy https://beefy.com/ 🚣0xbow https://www.0xbow.io/ 🚣Obscura https://obscura.build/ 🚣Panther https://www.pantherprotocol.io/ 🚣Maven 11 https://www.maven11.com/ 🚣Zama https://www.zama.ai/ 🚣zkSync https://zksync.io/ 🚣Secret Network https://scrt.network/ ETHDam AfterParty Fren 🥳Bitvavo https://bitvavo.com/en
Transcript
[Music] thank you for being here you are the most knowledge first of them all if you stay till the end uh my name is Dan I'm going to speak about what is security web free and first of all let's first look why why you should even listen to me in the first place uh I work with Sherlock uh we have done 150 plus audits in a year and a half quite a quite a big amount we've worked with one of the biggest projects in the ecosystem I know you may recognize some uh logos here optimism ail GMX and and many many others uh we have a bit of a different system but over the years we have figured out some of the mistakes that people make uh When approaching Security in web free so um I hope this one will help you not repeat those mistakes and avoid as much as possible okay so what are the three stages that a project goes through uh first of all there is a pre- audit when you develop everything you're super excited everything goes Super well uh then you get to the audit to the security review and you quickly understand that a lot of mistakes have been made but you think okay I've done the audit everything is good now and you get to the post audit stage and uh hopefully there are no hacks but if they appear uh you know the adrenaline is pumping you don't know what to do and there is specific protocol you should follow in those cases and and uh we're blank hope hopefully not check in the back okay we're going to wait we're going to wait a little bit are you getting a you getting a signal yeah it was and not only exact same happened yesterday final talk dodgy cable oh yeah maybe I stepped on something I blck electricity yeah that's how it works it's just really shitty wait give me one second okay no problem well we can do a quick Q&A else solidity go rust typescript uh whatever you're using most probably we can audit that yeah actually I'll be touching upon that it's uh we have an interesting approach for it do you do process audits which is an interesting idea that people have been talking about today it's not just the code but yeah the processes behind it do you for you know especially as your teams get bigger and bigger yeah so I guess nobody wants to to hear the talk everybody wants the QA we can do that right uh but I'll be super quick um so usually the for the pre- audit what you want to do in order to uh ensure that you're all good you want to find someone uh that is going to help you develop in a secure way you best thing to do is you know hire an in-house security researcher that is going to help you uh build in a secure way help you prepare all the necessary documentation actually for the audit afterwards because the more you provide to the Auditors the better job they can do they are still human and of course you can consult with them on which audit firm to choose because it's not an easy choice to make and um you know you don't want to get scammed then how do you actually find these solo Auditors that you can hire in house and you know make sure you hire a reputable person first of all look at your competitors who audited them who are those people maybe they did a public audit then you can go to the leaderboards of those uh uh competitions and see who performed and how well they performed we actually on Sherlock uh have such a leaderboard this just some screenshots from it uh you can see who is the top guy second guy and so on and you can see how many vulnerabilities they found which protocols they worked on so you go ahead and find someone that is has specific experience with what you are building are you you lending and borrowing uh are you a compound fork okay now if we talk about the audit itself you have three four routes to go with uh generally from cheap to very expensive uh this is a solo audit a traditional audit and then an audit competition an audit contest Sherlock is also in that realm but I put it separately because I want to touch upon it um so the solo audit what are the advantages and disadvantages biggest advantage of viously it's cheap um you know who is auditing your codebase what is their prior experience are they reputable or not um and you have a very close connection with them you might be asking yourself but Dan I already have a solo Auditor in house why should I hire someone else the reason for that is that solo auditor has helped you write to the code base so most probably um you know they have a bias so they are not really seeing everything that is out there not seeing some edge cases that's why you want a fresh set of eyes to take a look and really dive deeper uh the biggest disadvantage with a solo auditor is it's only one person one person there's so much that they can do and so many things that they can know um you don't know how much time they actually spent for the money you gave them um and they usually don't have a direct incentive obviously they care about their reputation but we should never assume somebody's uh you know somebody will do a fantastic job we should set some uh parameters in place to ensure that so uh there is nothing that can ensure they will do their maximum with your particular audit next the next year up is the traditional audit uh we all know them the chain security the trail of Beats the open Zeppelin of the world obviously uh have been here for a very long time very experienced companies uh biggest Advantage is you have a curated list of people you know exactly who's going to audit your code base you know they tell you what are their accolades uh what they have achieved in the past so that's great uh they do a fix review for you at the end so all the fixes you have implemented are being checked it's more than one person already a step up from a solo audit but what are the disadvantages still you're getting only three four guys there is so much that they can do they get paid by their by by per hour what does that mean um well uh you know what's the difference in the pay if I find two criticals or I find 10 criticals it's none right who knows then usually uh traditional audits especially in the bull market have very long lead times so you have to book them in advance which really interferes with your you know planned road map and they have longer audit duration because obviously for three four people to do a really good job they need to spend a lot of time now the innovation in the space has come with Cod Arena that introduced the audit contest the biggest advantages of audit contest that builds upon a traditional one is hundreds of people are looking at your code base it's not only three or four guys which gives them the ability to set up these audits very quickly and you know they are much faster than a traditional audit so you get your audit report super quick the biggest uh disadvantage with an audit contest is obviously you have no guarantees who is auditing your code base you don't know only after the audit has ended and you don't know how much time they have spent right so you can look at the results and see that some a very good security researcher has found two mediums in your code base did he found them in after five days of intense work or did he find it in two hours and he decided to switch to something else so you don't know that and that's a big problem um because you have no guarantees of the quality uh what you receive but the big Advantage is those people that participate are super incentivized to actually find bucks okay now how does how did Sherlock try to mitigate those disadvantages that an audit contest uh provides now this is a small shill from my side so please be prepared it's going to only last one minute not more than that okay so uh we have as you have seen we have a leaderboard and the leaderboard is based on performance so it's based on a ELO style rating you might be familiar with it from chess or from competitive games so in order to be on the top of the leaderboard you have to actually perform very well against other top security researchers being on the top of the leaderboard gives you great advantages which is extra fixed pay actually being top 20 in the top 20 on the on the Sherlock leaderboard is the highest pay you can have as a security researcher aside of bug bounties obviously um so there is an intense fight for that position now with that gives the US the opportunity to reserve security researchers for you uh which means you know for sure that five six even more security researchers will spend their full time on your code base they receive a small fixed pay for it but uh you have the Assurance of high level Talent spending time on your code base in a very competitive environment because the uh contest aspect is still there now we come to the uh maybe one of the most interesting parts and still very important often uh projects focus on growing the growing their protocol instead of security post audit they thought that okay we did an audit checkbox done we can move forward forget about it the best thing to do is to have continuous update AUD a it and um one of the big reasons why protocols don't do it is because when you switch security providers you have to re audit everything again and that's super expensive so in that sense it's a good idea to stay with one security provider so that you can have a better deal at continuous update Audits and even the smallest changes in your code base can lead to major problems down the line so it's better to continuously check that and obviously with an audit competition you can check who did well in your contest and bring that guy back for smaller continuous updates so you can still continue building and at the same time be secure don't overlook back Bounty programs the if I'm not mistaken the chief security officer from um polygon had a talk here earlier today and he brought up a very good point you can set up a back Bounty program for super cheap and you don't need to go to immuni or any other platforms you can do it yourself self-host post it and there will be Auditors out there that will try to break your code and um they often look who has audited it before so you know if you get a lot of BU Bounty submissions uh probably you didn't choose the best auditor uh because they check for that when they choose which codebase to attack and bu Bounty programs are great because it's a continuous audit once you're on main net you don't have to do anything for it than other than you know have money in your wallet uh for it of course have an incident response process always think of the worst possible situation what you going to do in case of a hack what are the checkpoints that you put in place do you know exactly um you know where the money can be stolen from all of that needs to be checked and uh you have to have a war room uh protocol in case of a hack and also don't be afraid to reach out to security companies where you know we are happy to help we have a lot of resources obviously for that we have been in multiple War rooms unfortunately uh so uh we we are happy to help and obviously real-time monitoring is always a great idea um it's not a silver bullet but um at least it gives you that extra check helps you close off everything um early on rather than later which is uh usually time is very important in this matters this is it this is my telegram for anybody interested to ask me absolutely anything don't worry I'm not going to sell you anything in response so uh you are free to ask me whatever and I'm happy to take any questions thank you so much for staying here and listening to the last Talk of the day thank you very much [Applause] welcome do you have any questions have you thought about doing doing a like escro service where you know you could pay out a certain amount to Auditors and then unlock more over time if that protocol hasn't like there hasn't been vulnerabilities found so you can like pay 50% up front and then the other 50% a year later uh we have done it the other way around uh whereas so Sherlock only pays out medium and high uh t vulnerabilities right and there are protocols that come to us after let's say six audits seven audits they say we think we are very secure but we wouldd like to do this final check before we go to main net so in those cases we can set up a variable Conta spot so in case a medium is found you know one tier opens in case a critical is found another tier opens right so we start with a lower Base number but depending on the result TI open interesting okay thanks you're welcome uh regarding realtime monitoring yes what is the best approach that you have seen like done it's very custom it's very custom right because it depends from uh protocol to protocol I would say it's best to bring uh somebody from the outside or um have a consultant help you set that up that is specifically or intimately familiar with your type of project and have set has set up that in the past I would even reach out to to Big projects that or you know the chief security officers at those big projects if they are similar to yours or if you have forked that code base in order to uh get let's say more detailed recommendations on things you should look out for it's very difficult to give a all-encompassing answer here unfortunately but right now there are more tools that do all the monitoring on chain rather than offchain which I think is we needed that a long time ago to have it all decentralized and at the Smart contract level so I would look in that direction as well any final questions no final questions wonderful thank you very much that was a great way for end the day [Applause] [Music]
Automatic transcript — names and jargon may be misspelled.