state of bitcoin security - inside bitcoins april 2014 - bojan simic

18
tate of Bitcoin Securit an Simic jansimic @cryptosecurity [email protected]

Upload: bojan-simic

Post on 06-May-2015

545 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

State of Bitcoin Security

Bojan Simic@bojansimic @[email protected]

Page 2: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

When it comes to security….

Page 3: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Remember the 5th of November

Page 4: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Enigma Machine in WW2

Page 5: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

00000000

Page 6: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Need a Debit Card?

Page 7: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Internet Security

Target – 70,000,000 credit

card records

Adobe – 38,000,000 CC

numbers & user accounts

American Business Hack – 160,000,000 credit card

numbers and bank accounts

SONY PSN – 77,000,000 User

Accounts

US Military – 76,000,000 SSNs of

Veterans

Top 4 hacks of 2013 resulted in 575 MILLION compromised accounts!

Page 8: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Bitcoin (In)security

Bitcoin Savings & Trust

Page 9: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Why?

Page 10: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Hackers are getting smarter, there’s more of them, and there are more targets every day

91% of surveyed companies had a security incident in the last 12 months.

Page 11: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

So what can you do about it?

Page 12: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

The average security breach costs $50,000 – $650,000

Page 13: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Hire or train developers qualified in security

Protecting Sensitive Data

Preventing Injection Attacks

Preventing XSS

Access Control Strategy

Business Function Access Control

Data Layer Access Control

Securing User Sessions

Managing Identities in Apps

Using SSL

Threat Modeling for Apps

18.8%

77.0%

70.0%

30.0%

55.0%

40.0%

51.0%

61.0%

69.0%

24.0%

Developer’s Scores

Companies that train developers in security have 73% less vulnerabilities

Page 14: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Store your bitcoins securely!

Paper Wallet

COLD STORAGE!

Smaller businesses are victims of cyber crimes more often than big firms

Page 15: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Encrypt EVERYTHING!

• Transactions• Passwords• SSNs• Addresses• Images• Credit Cards• DOB• Other PII…

73% of Americans have been victims of a cyber security crime

Page 16: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Take advantage of free resources & tools

Page 17: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

Start a security bug bounty!

Fixing a security vulnerability post-release costs 30X more than in dev

Page 18: State of Bitcoin Security - Inside Bitcoins April 2014 - Bojan Simic

Bitcoin Security Project

?’s(Donations)

• Follow @cryptosecurity • Sign up at bitcoinsecurityproject.org• [email protected]