
sudo rm -rf --no-preserve-root /
@pcaversaccio
164 Following
3185 Followers
9 replies
7 recasts
64 reactions
4 replies
1 recast
27 reactions
3 replies
2 recasts
28 reactions
1/ time for a quick vibes check on where our industry's at security-wise; well, folks, guess what, 95% of last months' SEAL 911 tickets were the same shitshows on repeat: folks running sketchy code some rando DMed them (stop cloning & running GH repos you got from some random dude who asks for your "help"), hopping on Zoom calls where scammers walk them through (effectively) self-pwning (dude, believe me you don't need to patch your zoom or google meet) their own machines, teams getting nuked because they thought hiring bargain-bin devs from North Korea was a great idea, or some skiddies calling up victims pretending to be Coinbase support (always Coinbase, like 90% of the time and the rest is Ledger) and walking off with their funds. On top of that, there's the usual: someone falling in love with a random Tinder match and getting rinsed by a textbook Sha Zhu Pan play, and of course, the ever-reliable dev who commits their .env file with private keys straight to GitHub, NPM, etc. 2 replies
1 recast
22 reactions
0 reply
2 recasts
18 reactions
5 replies
1 recast
24 reactions
2 replies
1 recast
23 reactions
7 replies
7 recasts
53 reactions
2 replies
0 recast
26 reactions
2 replies
4 recasts
47 reactions
2 replies
2 recasts
8 reactions
1 reply
2 recasts
12 reactions
2 replies
12 recasts
65 reactions
0 reply
0 recast
13 reactions
3 replies
10 recasts
60 reactions
0 reply
1 recast
9 reactions

People keep asking me since days how to secure their systems and what the best strategy is. I will be very honest with you all as I'm always. If you want real security (and there will be never 100% security), it's not (just) about toolsβit's about fucking mindset. At least 80% of it is pure paranoia. You and your team (can be a small DeFi project, can be a large CEX, ...) need to be paranoid as fuck. Drill it into them. Make it second nature. That's how you cut down risk, big time. The human factor is always the weakest linkβno tech can _fully_ fix human fuck-ups. Sure, we'll kill blind signing, we'll upgrade our tools, but people will always be the problem. The only way to fix that? Train them to be fucking paranoid. There are no fucking shortcuts. If you have 900 employees, it's the leader's job to make sure all 900 are paranoid as fuck. You'll say that doesn't scale? Maybe notβbut if u don't do it, you're effectively gambling with everything. And when shit goes wrong, the price u pay will be brutal. 2 replies
0 recast
10 reactions
3 replies
9 recasts
63 reactions
0 reply
10 recasts
29 reactions
1 reply
1 recast
18 reactions