Instant Threat Modeling - #17 Hacking Blockchain Security

preview_player
Показать описание
This episode presents the most common threats applying to blockchain solutions such as HyperLedger.

Threat actors:
- anonymous, external attacker
- one of the organisations
- owner of certain private keys (authorised user)

Threats:
- private key compromise.
- web application attack vectors
- API attack vectors
- CA key compromise
- infrastructure attack vectors
- Node DoS
- bypassing channel policies
- too powerful organisations
- remote code execution and other smart contracts vulnerabilities
- smart contracts access control issues

Instant mitigations:
- encryption at rest
- web applications base threat model (BTM)
- BTM for APIs
- infra BTM
- each organisation should maintain their node
- policy configuration review + per-organisation access analysis.
- design review
- granular smart contracts

Instant Threat Modeling by Jakub Kaluzny (SecuRing).
Рекомендации по теме
Комментарии
Автор

Cheers for posting! Looking for help: My OKX wallet contains some USDT trx, and I have the seedphrase: -clean- -party- -soccer- -advance- -audit- -clean- -evil- -finish -tonight- -involve- -whip- -action-. What’s the best way to go about transferring them to Kraken?

TrentonGreenland-rd
welcome to shbcf.ru