🌟 SEAL Frameworks Stewards Spotlight: Meet @n0guest & @hexnickk from @LidoFinance
Stewards are experts who maintain individual SEAL Frameworks, review contributions, and help others implement security best practices. They help keep our frameworks current and useful!
🧵 (1/3)
Nearly $22B in ETH is staked via @LidoFinance.
Today, we’re glad to announce that Lido has completed the Web3SOC assessment, covering operational, financial, security, and compliance domains across Lido DAO and the Lido protocol.
stETH is moving deeper into institutional workflows.
That makes infrastructure diligence matter.
Lido has received Web3SOC certification from @cantinasecurity, adding another reference point for institutional diligence.
↓
Staking Rewards launched a comprehensive DeFi ratings framework, and stETH earned the highest rating of all rated products: A+
A deep audit history, a 2M USD Immunefi bug bounty, and features like Dual Governance all contribute to making Lido the most resilient DeFi protocol.
@officer_secret@0xKoda Your article is good for a wide audience, because it's trying to help. Kudos for that 👏
But some parts of this article are misleading or just sound like a shake oil pitch. That's what I'm about. Not trying to be rude, though.
@officer_secret Also DNSSEC is good to have, but it's worthless with hijacking situations.
It's like your house is on fire, but you have a gooooood score and a shiny badge on DNS checkups.
@officer_secret That's not a problem with only Gandi, but with many other registrars with employees susceptible to social engineering.
My take here is that your advice of buying some different TLDs is NOT solving the source of such problems.
@officer_secret Yeaah ... So as soon as you buy .com/.io from the same registrar - social engineering attacks stop working against the same people at your registrar.
Cow Swap incident proves that beautifully, yep 🙃
@SCBuergel@androolloyd@openprovider So far I've found info about Hypurr and Stakehouse domains being compromised. No other symptoms around Finland TLD.
6/ 🙏 Thanks to @LidoFinance for contributing battle-tested templates and practice insights that make incident response preparation practical & immediately implementable.
🔗 Start building/strengthening your response capabilities today: https://t.co/F4WwTGcHCV
Framework of the Month for April: Incident Response Template
🆕 Brand new framework launching today!
The best time to build your incident response plan is before you need it. The second best time is right now.
Pre-built assets and practiced procedures are the difference between recovery and catastrophe. (1/x)
@pingdom I already sent you DM 7 hours ago and event sent you a case number (previous communication with your support). Since then there is only total silence from your side. Anything else except keeping straight face on public?
@codeguy@pingdom It could go even worse. You paid then and after that got suspended without any ability to contact their support. So, yes - cancel them ASAP ;)
@pingdom Yeah, it all good except your company acts like a cheap scammers. Accepts payments, but then blocks your account without any heads-up. Way to go, guys. Steal money of your customers, while you can.