The intersection of blockchain & infosec: #cryptosec. Moderator Team @find_evil, @0xBanana, @_iphelix, @_sniko, @424f424f, @lojikil. Join the chat on Telegram!
Thank you @BCOSvillage, @ajithatti, @defcon, and @coinbase for the BlockChain Village this year. Special shout out to @IntegrityShow and @nathan_hauk. I’m happy I was able to speak, meet new people, and talk crypto and security. Can’t wait to see what next year brings!
Stay tuned for @find_evil and me
on the next @GMCyberspace Special
🍷🍷
Talking about threat modeling and hacker life, dumpster diving, brain implants, tank turrets, types of Cyberspace adversaries and why not to lose time figuring out who they are
A little less than 4 hours left to steal the blockchain in CHAIN HEIST. @maurelian_ is catching up to @iphelix in the last few hours to get that 11 #ETH prize at #DEFCON27. https://t.co/UrYZo1jY63
Exploits that were previously only available to nation state actors are gradually being adopted by less sophisticated #cybercrime players - read our #cryptojacking blog here https://t.co/3N7vLbP4I5
Came across a fun Golang PE/ELF meterpreter & coinmining (?) cluster w very low detections all around.
One runs this wmic cmd:
wmic path Win32_PerfFormattedData_PerfProc_process where (PercentProcessorTime > 30 and idprocess > 0) get idprocess
Really excited to host @TechGirls at @block_one_ . This @ECAatState initiative encourages women to pursue STEM careers. With women under-represented in #blockchain and #CyberSecurity, we are thrilled to sponsor a program connecting talented young women with companies like ours.
https://t.co/5aTtQep6VJ
Join me on August 14th for a Smart Contract Security Webinar. We will also be auditing code live and asking for volunteers to submit their code to be reviewed for this interactive session.
#blockchain#consensys#smartcontracts#securityaudit#solidity
There is a fake @krakenfx app on Google Play. If you download it and attempt to login, they will use your credentials to compromise your account.
We reported it as soon as it popped up, but it’s still there. Anyone at @Google follow me that can assist?
https://t.co/B1zZKfidUJ
Here's the updated version of the guide I created for cryptocurrency security. As always, assess your own risks and choose the level of security you are comfortable with. Please share this resource with your friends and family!
Good piece about known risks with RSA, but "flat out unacceptable to use RSA in 2019" is too radical IMHO. Someone could probably list ECC failures and write a "Fuck ECC" post. The article for example omits to mention that PSS and FDH are more "misuse-resistant" than ECDSA.
Unfixable Seed Extraction on Trezor - A practical and reliable attack: https://t.co/llqWJH0sHg
https://t.co/9bgRiuuGtA
* Extracting seed from Ellipal wallet: https://t.co/LoCOGDlVtU
** Breaking Trezor One with Side Channel Attacks: https://t.co/1o2aZDU2ST
cc @DonjonLedger
SIDECHAINS ARE NOT LAYER 2
Let's put a myth to bed.
Thread on the history of sidechains, their security properites, concluded by their differences to Layer 2 solutions.
(there’s a lot of resources, feel free to skip/bookmark for later!)
👇