The Pomp Podcast - Brandon Arvanaghi, Security Engineer at Gemini: Covering The Popular Crypto Hacking Techniques
Episode Date: August 14, 2019Brandon Arvanaghi is a security engineer at Gemini, specializing in security in cryptocurrency and the Gemini dollar. In this conversation, Brandon and Anthony Pompliano discuss the best security prac...tices for protecting yourself and your crypto assets, popular hacking methods of nefarious actors, and prevention tactics. CRYPTO.COM-----Crypto.com is a pioneering payment and cryptocurrency platform that seeks to accelerate the world's transition to cryptocurrency. With the vision of "cryptocurrency in every wallet", the Crypto.com App offers a full range of financial products with competitive pricing, well designed UX and high security. It is the best place to buy, sell and pay with crypto. COINMINE-----The Coinmine One is like an Xbox that turns your electricity into Bitcoin. You just plug it in, connect to wifi, and tap on the crypto you want. It’s so easy anyone can do it. Everything is controlled from the Coinmine mobile app and the Coinmine keeps getting better with over the air updates that add new coins, features and services to your Coinmine. Visitcoinmine.com/pomp to get a Coinmine and earn crypto for powering a new world.
Transcript
Discussion (0)
What's up, everyone? This is Anthony Pompliano. Most of you know me as Pomp. You're listening
to Off The Chain, simply the best podcast in crypto. Let's kick this thing off.
Brandon Orvnani is a security engineer at Gemini, specializing in cryptocurrency security
and the Gemini dollar. In this conversation, we go over the best security practices for
protecting yourself and your crypto assets. We also touch on some of the more popular
hacking methods of nefarious actors while going over how to prevent each one. I really
enjoyed this conversation and think this is an important episode. I hope you enjoy it
too.
Skrt skrt!
Want to know who has the best URL? Crypto.com. That's right, Crypto.com. They're a crypto
platform with one goal. Mother and mass adoption. That's why we're all here. We're trying to get
crypto in every wallet. Crypto.com is helping people do that through buying, earning, lending
and card payment. Everything you could want at Crypto.com. Go help your boy out. Tell him Pomp
sent you. Download the app or visit Crypto.com. Pomp's got you always. Ever wanted to get into
mining and didn't know how? Don't worry. Your boy Pomp's got you. Everybody got some electricity
and Wi-Fi. All you got to do is go to CoinMine.com. You buy a CoinMine. It's like an Xbox or a
PlayStation that helps you turn your electricity into Bitcoin. That's right. You purchase it. It
shows up at your doorstep. You pull it out of the box. You plug it in, connect to your Wi-Fi.
Five minutes or less, you're mining Bitcoin. All you have to do is control it from the mobile app
they provide, and then you receive over-the-air updates that add new coins and new features
on a consistent basis.
Kind of like how Tesla does over-the-air updates
and updates the car software.
Just you're updating your CoinMine.
Consumer mining made easy.
That's right.
Go to CoinMine.com,
tell them Pomp sent you,
and thank me later.
Anthony Pompliano is a partner at Morgan Creek Digital.
All opinions expressed by Pomp or his guests
on this podcast are solely their opinions
and do not reflect the opinions of Morgan Creek Digital
or Morgan Creek Capital Management.
You should not treat any opinion expressed by Pomp
as a specific inducement to make a particular investment or follow a particular strategy,
but only as an expression of his opinion. This podcast is for informational purposes only.
All right, guys, bang, bang. I'm here with Brandon. We've got a pretty cool episode today
in that we are going to cover an overview of crypto security. So you've been on before.
You are now a two-time guest.
I appreciate you taking the time to come over here and basically teach us how to be safe.
Yeah, it's great to be back, Bob.
Thanks for having me.
For sure.
All right.
Let's start with just the very standard or elementary levels of security, right, and kind of walk us through what kind of is in that layer, right?
For those that don't know, we're going to basically go through three layers of crypto security, kind of a standard or elementary level, a medium level, and then the expert level of security.
So let's start with that standard level and kind of what's in that bucket.
Sure.
So let me make clear first that the standard level is the worst you could possibly be.
So people a lot of times use the same password on every site, right?
And you hear all the time about why this is a bad thing, but you don't exactly hear the reasoning behind it.
So it's not because I think you're going to tell anyone your password, which I know you won't.
But the issue is if you use the same password on every site, then one of those sites is going to be breached at some point.
and say when Yahoo gets breached or when Capital One gets breached,
then that username and password combination that you use there
is going to be publicly visible to the entire world
because what hackers do is they dump the list of usernames and the passwords.
And so what they'll basically do is Yahoo, we'll pick on them for a second.
If they got hacked and your username and password is there,
what they'll essentially do is people will take that email and that password combination
and they'll go try it at a bunch of other websites trying to use the exact same combination.
That's exactly right.
and they're going to get in on multiple other places so at the very minimum you want to use
a distinct password everywhere and there's something called a password manager that makes
that really easy to do okay so we'll get into what a password manager is in a second what some of
those uh may be in terms of the good ones versus the bad ones um so a password is kind of the first
level of defense when it comes to security i think most people are familiar with that then you get
into um this two-factor authentication right usually in this uh first level of defense it's
It's a text message, right?
And my understanding is there's two different reasons why you would have a service text you some sort of code, right?
One is I lost my password, so help me recover it or reset it.
And then the second is as an actual security mechanism.
So I'm going to sign in.
It says we're going to send you a code, type the code, and then we let you into the service, right?
Let's first go to just two-factor authentication via text.
explain exactly how it works and what some of the uh challenges there are sure so that's a great
distinction you just made and that's the most important distinction there is so what you were
talking about when you log in with your password to a site if you have two-factor authentication
with text or sms what happens is they will text you a code and the site will say please enter the
code that we just texted you to your number now this is problematic because phones are fickle
phone numbers are very fickle they should not be used for any kind of authentication
and it's actually more impactful when you have the second thing you discussed which was account
recovery that makes it even worse so you don't even need a password to recover someone's account
with their phone number so what will happen is if i go to your gmail for example and i type in
forgot password it'll say okay we just sent a text to the phone number associated with this email
with a code that allows you to reset this person's password so i didn't need their password at all i
just need control of their phone number and there's a lot of ways i can get access to your
phone number which is which is why this is so dangerous and so what are some of the ways that
people get access to the phone numbers because i think that's kind of one of the core things that
we've seen in crypto over and over again and i'm specifically talking about these sim swaps right
um maybe describe a little bit about what is a sim swap how do they work and then how does that
interface with the security um that most people have absolutely so a phone porting is what happens
when i call say your provider say you have verizon and i say i'm anthony pompliano and i'm changing
control of my phone number to this other SIM card on this other phone because I'm going abroad or
something like that. Now, if I can get them to believe that I'm you, then they're going to give
control of your phone number to the phone that I own. And all of a sudden you'll lose service and
I'll get service and I'll start getting all your text messages. And this is really easy to do
because everyone's identity is pretty much public at this point with all the breaches that have gone
out there and social security number leaks. So what will happen is if I get control of your phone
number and you have something like sms account recovery which we just talked about i will just
be able to get that recovery code and reset your password for your gmail for example and just get
into your accounts like that got it and and we've seen now this happened to a lot of people right
the the sim swapping the porting it's not just for crypto right in terms of i want to steal your
crypto people are trying to use it to get into your bank accounts um in the fiat world also to
get into your twitter account your email right there's all kinds of different services that
they're using to kind of penetrate the security measure um and then we've also even seen people
who have gotten crypto stolen from them right michael terrapin is uh is the um the big guy out
there with a i think he's got a 24 25 million dollar lawsuit against at&t for basically them
you know according to him his claim is that they were complicit right or they've helped facilitate
this um this theft of his uh of his crypto so it's a huge deal exactly um all right so two-factor
authentication via text message can happen with the account recovery or with um the security
measures uh and that's pretty much the standard or elementary level of security then there's the
medium level which i i tend to think that most people in crypto were at the standard level
they realize hey i need a little bit more security because you know bitcoin and other crypto assets
are bearer assets so they've moved on up to this medium level in the medium level there's kind of
two separate components there's the password manager you mentioned earlier and there's a
two factor authentication, not via SMS. Right. Let's do the password manager first. Explain what
that is and how those products work. Exactly. So instead of using the same password everywhere,
what you can do is have what's called a password manager. So this is an application that runs on
your computer that can generate a secure random password for every site that you want to log into
moving forward. So if someone asked me right now what my Twitter password is or what my Facebook
password is the honest answer is i have no idea because i just generated it once in this password
manager and it's stored there and anytime i want to log in now i just open the password manager
i look up twitter and i copy and paste the value into the login field so anytime i want to register
for a new site i generate a new password in this and it saves it forever and i just copy and paste
it into the create password field so every single password is different every single password is
secure and it's just beautiful i don't have to remember anything anymore got it and and on the
password manager side there's a couple of different services i think there's one password dash lane
last pass etc uh anything to look for when you're evaluating the password manager that makes one
better than the other or or maybe more secure or or effective i would just make sure it comes so
these are all good ones that you mentioned i would make sure it just comes from one of these
reputable brands i know last pass has had a good amount of vulnerabilities lately so maybe look
into one password. That's been a strong one lately. Got it. Okay. So password manager,
pretty simple and straightforward. The other aspect of this medium level of security is
two-factor authentication, not via SMS, right? So most people have, I think there's two main
apps that people now have kind of popularized, which is one is a company called Authy and the
other is Duo, D-U-O, right? Explain how these work for two-factor authentication. Right. So that's a
great question. So these are called authenticator apps. And the difference between this and SMS
authentication is that SMS is tied to your phone number, like we talked about, and phone numbers
are fickle. Whereas authenticator apps like Authy and Duo, they generate this code tied to your
physical device. So even if someone else gets control of your phone number, they're never going
to be able to generate those same codes that Duo generates on your app, for example. And that makes
difficult for them. So only your physical device is able to generate those codes that you use to
log in. Yep. And really what you're talking about here is if you go back to the phone porting or
the SIM swapping, a text message can, the scary part to me, right, is I know people who have
gotten SIM swapped and when that text message is generated from a site, it goes to everybody who
has a SIM card with that number attached to it. So it can still go to your phone, but it will also
go to the nefarious actors phone as well that's correct when it comes to these two-factor
authentication uh applications like auth or duo it doesn't matter if somebody else has your sim
card right you're saying it's just the physical device itself whoever has that physical device
is the one who gets the code that's correct but it gets a little bit hairy and this is why it's
kind of in the medium tier there's two things to look out for want to know who has the best url
crypto.com that's right crypto.com they're a crypto platform with one goal motherf***** mass
adoption. That's why we're all here. We're trying to get crypto in every wallet. Crypto.com is
helping people do that through buying, earning, lending, and card payment. Everything you could
want at Crypto.com. Go help your boy out. Tell him Pomp sent you. Download the app or visit
Crypto.com. Pomp's got you always. Ever wanted to get into mining and didn't know how? Don't worry,
your boy Pomp's got you. Everybody got some electricity and Wi-Fi. All you got to do is go
to coinmine.com you buy a coin mine it's like an xbox or a playstation that helps you turn your
electricity into bitcoin that's right you purchase it it shows up at your doorstep you pull it out
of the box you plug it in connect to your wi-fi five minutes or less you're mining bitcoin all
you have to do is control it from the mobile app they provide and then you receive over-the-air
updates that add new coins and new features on a consistent basis kind of like how tesla does
over-the-air updates and updates the car software just you're updating your coin mine consumer
mining made easy that's right go to coinmine.com tell them pomp sent you and thank me later there's
two things to look out for number one you're still dealing with a numerical code so if someone if you
were to tricked if you were tricked into giving this numerical code to someone across the world
even if they don't report your phone or you just you got tricked into giving it to them then they
can log in from Asia or Europe or Mexico, wherever. So that's kind of the issue, number one.
Number two is they also have a feature of these authenticator apps, which is called
multi-device support. And you're going to want to make sure you disable this because what multi-device
support means is that you can say, I'm going to register this same instance of this app on a
different phone just to have a backup plan. And how they allow you to do that is with a text to
your phone number. So it essentially gets back to the same level of security as text if you have
this multi-device support thing on. So it's important to disable that in these apps as well.
So that's exactly right. Well, you call this the medium tier. It's not the best tier yet.
Got it. Okay. And so let's move on to that expert tier. What do you see in the expert tier as if I
want to protect myself, whether it is in the fiat financial world, in the crypto world, or even my
non-financial applications like email, Twitter, etc. What is the best kind of approach to building
that security? Right. So you're already using a password manager like we discussed. That's great.
Security keys is the answer to that question. Okay. What is that? A security key is a physical
device that uses the same mechanism to protect your account as what makes Bitcoin so secure,
for example. It's public key cryptography. So there's nothing to spoof. It's a signature that
can only come from that physical device so if you have a yubi key for example or even your touch bar
on the new max you can log in and the attacker would need physical access to these things to
to impersonate you and that's very difficult for them to do obviously okay so you mentioned two
things the touch bar on the max and then a yubi key let's start with the yubi key because that's
more um can you work for android or uh mac or really any operating system um it is an actual
piece of hardware. That's right. That is quite small. It's like basically the size of like a
thumbnail almost, right? It plugs into one of the ports on your computer. That's right. And
the ones I've used, at least in the past, is you basically tap the YubiKey and it generates what
looks like a incredibly long random string of letters and numbers. And that is essentially
the public cryptography that you're talking about that will authenticate this is the person who is
supposed to be accessing this product. So independent of those letters, there's actually
a signature that it will do under the scenes and behind the scenes. And what it's signing
is your connection to that site. So there's nothing any attacker outside the world can
steal from this connection. They can't impersonate that connection because they can't get that
signature from you. So that's the key point is that no one can spoof this signature just like
no one can spoof a Bitcoin transaction, for example. Got it. And then how does the touch
bar work? Is it very similar to the YubiKey? It's just a different form factor on the hardware?
Yeah, that's exactly right. So Gemini actually was the first custodian and exchange to allow support for all these with something called the WebAuthn spec.
I don't need to go into the details of that, but what that means is we were the first custodian and exchange to allow use of these security keys, which use public key cryptography to log in.
And that includes the touch bar on your Mac, that includes YubiKeys and a lot of other security key options.
Got it. And so let's go to security at Gemini, right? And not so much like, hey, how do you secure people's crypto assets, but more from like a framework standpoint, how do these exchanges and these infrastructure providers think about design of security, right?
So the way I see it is like you have to have certain things that are built that people don't know how they work, right?
That's part of the security is the fact that they don't have the information.
At the same time, you have to design the security functionality that you provide to users in a way where it's intuitive from a user experience standpoint and it's usable, right?
You don't have to be highly technical to actually be secure on the site.
Like how do you think about it from a framework standpoint as you kind of build these nuanced features?
So with the security keys that we're talking about, that's a great question, by the way.
All I do is great questions on this podcast.
I should stop saying that.
People who use these security keys, if you're in the crypto space already, you're on the bleeding edge of understanding how public key cryptography works, the future of money, and how to secure yourself, right?
Security keys are very much going to be the next big thing in terms of securing your accounts.
It'll be the standard across everywhere shortly.
So with Gemini, it was very important for us to be on that front line, leading that push to get people on security keys so no one can phish their accounts anymore if they have security keys only and no other backup plans.
So being on the front lines of security is very important to us, and educating our user base about that is very important to us.
For sure. And look, it's one of these things also where I've even seen exchanges that they move funds quite consistently because the example that one of the security folks at this exchange that does this told me is like it's hard to hit a target, but it's even harder to hit a moving target.
Right. And so the movement of the funds is almost where they don't know where something will be at any one given time.
And so when you start to think about the complexities of security, right, it's not just can we keep people out?
It's also even if they get in, is there a way for us to prevent them from getting into a place where there's all of the money or the crypto, right?
So compartmentalizing it and doing all these different things I think is not very well understood by users, but obviously very important if you're an infrastructure provider like Gemini.
Right, right.
Yeah, and that's where kind of cold storage and cryogenic storage, geographically separated, makes it very difficult for anyone to try to target any one person or one place.
For sure. For those that are listening and have not yet read Ben Merzrich's new book, Bitcoin Billionaires, when he came out, I think we talked about it as well.
But there's a story of Cameron and Tyler Winklevoss, who are the founders of Gemini, that when they first started buying Bitcoin in sizable amounts, they actually went ahead and wrote down the private keys, split them up into different writings, and then flew around the country and put them in safety deposit boxes.
And so if you want to hear that story, you can go read that book.
Ben, I'm trying to help you sell books, man.
Give me some love every once in a while.
Let's go to hardware wallets, right?
So everything we've talked about is kind of software products, right, where I kind of log into an online infrastructure provider.
There's plenty of people who are using these hardware wallets.
Where are you and kind of help us think through the security on the hardware wallet side?
Sure.
So hardware wallets are a really innovative part and a unique part of the cryptocurrency industry, right?
It's an exciting part that existing banks don't let you use.
There is a trust relationship with the hardware wallet.
So anyone who tries to make you believe that there's no trust involved in a hardware wallet is being completely disingenuous.
So just keep that in mind when you purchase these products.
You're essentially trusting that company.
Now, what we offer, we say that security is our product, and that's important to us.
So going back to the idea of security, one of the things that I've seen on Twitter is people are very interested in the security of their cryptocurrency.
They're very interested in how do I protect my email, my Twitter.
They kind of go down this rabbit hole of security once they start trying to secure their crypto.
Before we started recording, you were telling me that there's a hack around a voicemail pin in WhatsApp.
Tell me more about this.
So the research was done by a guy named Martin Vigo, and it's really exciting.
We talked earlier about SMS account recovery.
So if you forget your password, if you write forget password, then the service will send a text to the phone number associated with that account with a code to reset your password.
Now, some services also allow you to get this code via phone call.
So it'll be a robot voice on the other end of the call saying your code is 82653.
Now, the issue is if you don't answer this call, it goes to your voicemail.
and that code is still being read by that robot voice in your voicemail.
Now, the thing about voicemail is that they're remotely accessible.
I don't need access to your phone number.
I don't need to have control of your phone number
to be able to try to log into your voicemail.
So if you don't have a voicemail pin set,
then yours is the default for your carrier.
And some carriers just make that default
the last four digits of your phone number, for example.
So I can remotely log into your voicemail,
recover this code from this automated voice being played,
and log into that service.
So WhatsApp is a really good example of a service that's affected by this.
Anyone who has no voicemail pin is effectively vulnerable to having someone else access their WhatsApp
because they don't have a voicemail.
What's the connection between the voicemail and WhatsApp?
So WhatsApp is a service that allows you to reset or give control of your WhatsApp to a different phone number,
and you get that verification code via a call to your existing phone number.
So when that call goes to your voicemail and that robot voice is reading that code,
that anyone can get control got it so if you're able to listen to the voicemail then you could
get the code and they can go to the whatsapp and you could hack into it exactly yeah and so um in
most phone settings i'm guessing you can just put in an actual voicemail pin number or even disable
it you can even call your carrier and disable your voicemail altogether so i don't have voicemail
set up it's not not for security reasons because i don't i don't want to get anybody to leave me
messages but i i was being more secure than i even realized that's right awesome man um anything
else that uh that's kind of top of mind for you when it comes to security and crypto i think we
enumerated a lot of really good steps here and it's just that simple everything that we just
talked about today can take you from very bad security to very good security for your personal
accounts and anyone listening to this anyone who's involved in crypto or wants to have secure
accounts should implement these simple steps awesome man thank you so much for coming to do
this i think this is uh probably one of the shortest podcasts we've ever done but one of
the most important because uh there's so many people i meet that they simply have a email and
a password with all their crypto on an exchange and it's just waiting for somebody to come and
take it right and um hopefully people listening to this can move from whatever level of security
they are to a a more expert level of security um over time so thanks so much for uh for coming in
and sharing this thank you so much anthony hey everyone pop here if you like this episode of
off the chain and want to help us take crypto to the top of the apple spotify and other podcast
charts please do us a favor and rate review and subscribe to review simply go to the off the
chain homepage scroll down until you see the five blank stars taking 15 seconds to fill those stars
in and leave a quick review goes a long way in helping us take the entire crypto ecosystem to
the top of the charts i appreciate you listening and see you next time on off the chain
