DEF CON 32聚焦:CertiK安全工程师揭秘dApp的安全挑战

币界网2024-08-15 tarihinde yayınlandı2024-08-15 tarihinde güncellendi

币界网报道:

IBKWHYY43lzqNa4Baqpi4gP3LzMd3KWZf4fr1v0L.png

8月10日,CertiK的安全工程师Wang Peiyu在DEF CON 32会上发表了题为“Web2遇见Web3:黑客攻击去中心化应用”的演讲,通过Dapp漏洞和攻击手段的真实示例,深入分析了Web2与Web3集成所带来的新型安全问题,并提出了如何识别和防范这些风险。

演讲不仅揭示了去中心化应用(dApp)所面临的独特安全挑战,还分享了CertiK安全工程师Wang Peiyu在dApps渗透测试过程中积累的宝贵经验。他强调了恶意行为者如何利用dApps的漏洞,通过窃取种子短语、私钥、签名和API密钥等敏感信息来控制加密资产和托管人,进而操纵合约状态。

此外,演讲还深入讨论了dApp威胁建模,通过一系列实际案例,展示了客户端和服务器端的常见漏洞,包括跨站脚本攻击(XSS)、子域接管、DNS劫持、供应链攻击以及服务器配置错误等。他还提出了几个关键的安全建议,包括进行渗透测试和智能合约审计,以确保dApps的安全性。他强调,开发者需要对Web2和Web3的安全知识有全面的了解,以防止漏洞的引入,并保护用户资产不受侵害。

DEF CON是历史悠久的年度黑客大会之一,自1993年首次举办以来,一直面向白帽黑客群体举办,以其前沿的演讲、研讨会和竞赛而闻名。今年,CertiK的安全工程师Wang Peiyu受到特别邀请,参与了这场盛会,与全球网络安全领域的顶尖专家一道,深入探讨并分享了最新的安全技术进展和行业趋势。

İlgili Okumalar

The War Without a Unified Name: The Domestic Tech Giants' World Model Landscape

The article outlines the diverse and fragmented landscape of "World Models" in China's tech industry, where major players are pursuing similar goals under different names like world foundational models, physical AI, or integrated within autonomous driving and embodied intelligence systems. The core aim is to enable AI to create an internal, dynamic environment for simulation, reasoning, and learning, reducing reliance on infinite real-world data. This "data engine" allows for unlimited generation, experimentation, and iteration. The report categorizes the approaches of different companies: * **Internet Giants:** Alibaba is developing models for linguistic, virtual, and physical worlds (Qwen-AgentWorld, HappyOyster, Qwen-RobotWorld). Tencent's HY-World focuses on 3D, game, and social scenarios. ByteDance leverages its vast video data for a potential "digital twin" model. Huawei integrates its model into industrial applications like smart cars and robotics without separately branding it. Baidu embeds world model capabilities within its Apollo autonomous driving and Ernie systems. * **Automakers:** Companies like NIO, Li Auto, XPeng, and Geely are using world models as virtual "driving schools" and "testing grounds." They generate complex scenarios (e.g., rain, snow) to train and validate autonomous driving systems in simulation, aiming for more capable and safer AI drivers. * **Autonomous Driving Suppliers:** Firms such as Momenta, Horizon Robotics, Haomo.ai, and DeepRoute.ai are building the underlying "world engines." They focus on large-scale video generation for simulation, reinforcement learning, and enhancing end-to-end autonomous driving models, often integrating these capabilities into commercial products. While startups bring focus and innovation, they face challenges like limited data, compute resources, and deployment channels. Large companies possess these advantages and are rapidly transitioning world models from research projects into core business infrastructure powering products in vehicles, games, and industry. The conclusion is that world models represent an evolution and convergence of existing AI fields into crucial industrial infrastructure, moving the competition from simply building a model to effectively deploying it to understand and interact with the physical world.

marsbit11 dk önce

The War Without a Unified Name: The Domestic Tech Giants' World Model Landscape

marsbit11 dk önce

The Crypto Industry Enters the 'Show Me' Era: Vision Alone Is No Longer Enough

The crypto industry has entered a "Show Me" era, where grand visions and white papers are no longer sufficient to gain traction. This shift is driven by increased skepticism, high-profile bad actors, and notably, the serious entry of traditional finance (TradFi) institutions like BlackRock, Fidelity, and JPMorgan Chase, which are launching real, scaled products such as tokenized funds and blockchain-based settlement. This raises the bar for what constitutes a credible project. The communication dynamic has fundamentally changed. The focus is no longer on "what you are building" but on "what you have built and who is using it." Startups must now provide a "proof stack": verifiable data like mainnet transaction volume and active wallets, genuine partnerships with signed contracts, and evidence of organic product-market fit from real users, not just investors. Announcements must be backed by concrete, chain-verifiable evidence. For communication strategies, this means leading with proven facts and hard data—even if modest—rather than speculative narratives. A compelling story must be grounded in demonstrated results. While vision remains important, the balance has inverted from 80% vision/20% substance to the opposite. This higher threshold ultimately benefits builders with genuine traction, filtering out noise and allowing their real signals to stand out clearly. The "Show Me" era is a permanent maturation, demanding that communication strategies prove value, not just promise it.

链捕手43 dk önce

The Crypto Industry Enters the 'Show Me' Era: Vision Alone Is No Longer Enough

链捕手43 dk önce

Meta Follows the Trend into Prediction Markets: Can It Avoid Repeating the Failure of the Metaverse?

Meta, the tech giant behind Facebook, has reportedly formed a team to develop "Arena," a new application focused on prediction markets. Users would use platform points to place bets on outcomes in politics, sports, and global events. This move follows Meta's massive, nearly $900 billion, losses from its heavily-invested metaverse division, Reality Labs. The prediction market industry is already showing strong demand, with leading platforms like Kalshi and Polymarket facilitating hundreds of billions in annual volume. Meta, with its 3.56 billion daily active users across its apps, possesses the unprecedented scale to bring this niche activity to a mainstream audience, similar to its past success in cloning features like Stories and Reels. However, Arena faces significant hurdles. Meta plans to start with a points-based system to avoid strict financial regulations, but this may dilute the core incentive of accurate prediction that real-money markets provide. More critically, Meta enters the space with a major trust deficit stemming from its past regulatory battles, notably the failed Libra/Diem stablecoin project, and its controversial history with political content and misinformation. The prediction market sector itself is under increasing regulatory scrutiny, with recent CFTC actions including fines and the first-ever insider trading case. While Meta's vast user base offers a unique opportunity to expand the market, its success hinges on navigating complex regulations and rebuilding the credibility necessary for a platform dealing with sensitive topics like elections. The outcome could range from Meta dramatically growing the industry to Arena becoming a high-profile regulatory target before it can scale.

Foresight News1 saat önce

Meta Follows the Trend into Prediction Markets: Can It Avoid Repeating the Failure of the Metaverse?

Foresight News1 saat önce

İşlemler

Spot
Futures
活动图片