Hey, how are you guys? How's everything? Well, today I I had a workshop, but they but they told me, "Okay, you don't have an hour, you have 5 minutes." So, I'll make it brief and I'll go to the conclusions. Well, I'm Pablo Sabatella.
I do web3 operational security at Obsec, where we train and audit companies for everything that is not in a smart contract. And I am a contributor of Celer 101, where we do incident response for blockchain. So, what are we going to talk about today? Simple things that we can do to enhance our our Obsec, right? So, one thing that is very important to know is that it's not so important if I use Windows or Mac, Android or iPhone, Chrome or Safari or whatever.
The important thing is how we configure the tools that we use, right? So, first thing I want to talk about very fast, two-factor authentication. Things that you not have to do, do it with SMS. And we cannot do it anymore with TOTP apps like like Google Authenticator or Authy. Those kind of 2FAs can be fished and are being fished every day.
We need to use YubiKeys, right? But not the YubiKey with the normal OTP mode. YubiKey with FIDO2. That cannot be fished. This is happening a lot in the ecosystem.
Next, social engineering. We have to be very very very careful for this. Like professionals hack people, not systems, right? Today it's much cheaper to attack someone and much easier than to attack a system. So, be very careful with supposed recruiters, busy funds, investors, and journalists that want to invite you to some call or something.
Never download anything. Be very careful with PDFs that you open. They are usually infected. And if someone looks if something looks like strange, it's probably it's probably a scam, right? And everything is a scam until proven otherwise.
Everything. Next, eventually all of us will get hacked. That will happen. It's not a matter of it will happen or not. It's just a matter of time.
So, we need to be able to contain the damage. So, that you know when someone in your team has been hacked, the damage will be contained. Even the founders, even the CISO, even the CTO. Everyone. Use an antivirus and a firewall.
People think that no, I use a Mac. I don't need an antivirus. Use an antivirus. MacBook is not uh good with viruses alone. There's a good uh foundation called Objective-C that has many tools for security in Mac.
One more thing, the attack will come from a trusted source, right? For example, we saw how they were hacking the Eventbrite of the events at Elcom 1 hour before the event and they sent a message from the real account to everyone, "Hey, you have to mint this NFT." You mint it, your wallet is drained completely. Uh you receive an email that says that it's from Trezor and it's really from Trezor from their official system, but it has been hacked. They send you a drainer.
You are done. One more thing, use a password manager and never never ever reuse a password, right? But let's use password managers and we have to have to have them configured very securely, but never ever ever, and this is very important, very important, never put a seed phrase in a password manager, right? For sure many of you have done it. Yeah?
And you say, "Oh, we did it, but it's okay. My password My password manager is secure." No, it's not. If you have ever put a seed phrase in a password manager, you cannot use that wallet anymore. You have to move to a new one.
Use hardware wallets. Hardware wallets are important. Many will think, "Okay, these things that these guys are telling us are very basic." This basic stuff is the reason why today 85% of lost of lost funds are the are lost every day, right? In blockchain, it's not anymore due to smart contracts.
We have gotten very very good at security with with smart contracts. Uh and money is being stolen like this. So, you have to be really really careful. Well, I hope you you liked it. I will be here if you want to talk more about this.
Like this was a very very very small resume, but um operational security is important. It's the number one reason how we are being attacked by very sophisticated third actors. Something that is happening is that in the industry, we have one of the worst offsets in all the industries worldwide because we don't have regulations. So, any company does whatever they think that it's okay, and it's not. And on the other side, we have very very sophisticated third actors from nation states that are doing this kind of attacks, and they know what they're doing.
So, be extra extra careful. I hope you liked it. Thank you, Pablo. Any questions for Pablo? Yep.
Okay. Do you want to give it a go cuz it's on your side? Uh do you want to throw? Oh. I have to throw it there?
Okay. Oh. Sorry. You're much better than me. Um so, what would you recommend to people to store their seed phrases securely?
Because I think the challenge is I mean, I'm a CTO as well. Uh you you either have to make it secure or if you you you want to prevent people writing it down on a posted, right? So, what I think that writing down seed phrases is one of the best ways to store them. One hack that you can use that is very very simple, uh was told to me by one of the guys from the Red Guild, is buying anti-tampering bags, the ones that you commerce use. So, you write it there, and wherever it is that you you save it, you save it with that.
So, with that you are sure that it has never been seen by anyone. If sometime it was seen by someone, they have to break that. So, that's another very good way, and I really like Shamir, like having your your seed phrase and cutting it in places in three lists, but you only you need two of those three lists. That gives you confidentiality and availability. So, I think that's pretty good.
Thank you. Do we see any other questions? Oh, over there. There was one question. Yep.
All right, I actually wrote down my question. Uh how do you choose a product for secrets, like SSH keys, OAuth tokens, etc. management across multiple cloud providers? Uh so, a product for what, sorry? A product for secrets management, like SSH keys, OAuth tokens, across multiple cloud providers.
Uh I don't have a good answer for that. So, I'm not uh I'm not sure what would I use. Um The guys that I am really because I only talk about stuff that I am really really good at, right? And the guys from the Red Guild guide like very good guide on on on that, so they will be maybe able to answer those questions far better Thank you. than me.
No, thank you. What do you think? What is the more secure multi-sig wallet or hardware wallet? Now, I think that safe is good, and regarding hardware wallets, I consider that all of them are also very good. Trezor, Ledger, SafePal.
I think it's how you use them, right? But I I think that all of them are are very good, and I think that SafePal is also very very good. Yeah, there's a question over there. All right. You covered a lot of stuff there, but is there any advice you give on browsers or how you deal with browsers?
And that's generally where a lot of stealers are sitting in a wallet. Yeah, yeah. Browsers, be very very careful with the extensions you download. Like we have to be very very careful with extensions. There are lots of malicious extensions.
And the other good practice is to have more than one session. For example, you use Chrome, you have five sessions. One for work, one one for DeFi, one for personal stuff, one for this or that or that. And you also can have another browsers, right? Or even better than that is having another session in a VPN, right?
So you have it Sorry, in a virtual machine. So you have another virtual machine with another browser if you want to keep it like really separate, and that's also pretty good. Okay, thank you. Thank you very much.
Automatic transcript — names and jargon may be misspelled.