SBF Profile picture
25 Oct, 13 tweets, 2 min read
1) thoughts on crypto account security
2) NOT SECURITY ADVICE
3) The first question you should ask yourself is:

"how sad would I be to lose these funds?"

Spend as much attention as makes sense given the cost

a) "lol who cares": username/password, stick in password manager; or log in with google/etc.; whatever.
4)

b) "eh I'd rather not but I'd be ok": username + secure password, ideally + 2FA but not the end of the world. Use a secure password and a password manager.

c) "I'd live but that would really suck": username + secure password in password manager; authenticator 2FA
5)

d) "that would be really fucking bad": username + secure password + authenticator 2FA, plus all the fixin's:

--IP whitelisting
--withdrawal address whitelisting
--separate withdrawal password
--whatever else is available

Yubikey can replace authenticator for 2FA
6) and for all of the above:

Above all, MAKE SURE TO SECURE YOUR EMAIL ACCOUNT. No matter what else you do, if someone gets into your email they'll often be able to get anything.

SMS 2FA is generally bad: coverage is spotty and some countries make it trivial to sim swap.
7) Ok, but how about ledgers/other physical security?

a) if the amount at stake is HUGE then these make sense (think 8-10 figures)

b) if you really like them, then go for it

the operative things here:

--it's hard to not lose them
--they're more secure
8) so the question, really, is: how hard is it to break through version (d) above?

It's really hard, and most approaches just circumvent these entirely. E.g. get into email and reset everthing.
9) But there are some that don't: there are some attacks that only physical security can prevent. Those are *really* hard and only happen if there's a ton at stake, because that's when they become economical.

That's when the gains outweigh the chance of losing the ledger.
10) Or, if it's what feels natural to you and what you'll do a good job maintaining.

Some other random notes:

a) what's up with 2FA instead of just a 2nd password?

Basically: you only pass a hash of your true 2nd password, so intercepting it doesn't give permanent access.
11)

b) no matter what you do, the most likely failure scenario is that you let your friend use your account and they take the money.

Seriously. Most FTX account breaches aren't insecure passwords: A let B use their account and then B took the funds.
12) Also, phishing is real. Don't get phished.

The real defenses against this:

a) use a password manager that warns if the URL doesn't match

b) be on the lookout for things that look weird. If anything seems off, check to confirm.
13) and finally: practice good hygine.

It's ok to use shitty security for things that don't matter, but watch out for whether it's making you put your guard down too much.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with SBF

SBF Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @SBF_Alameda

28 Oct
1) Some updates on Serum Swap!

swap.projectserum.com
2) NOT INVESTMENT ADVICE
3) The SRM airdrop period has started! 1m SRM this month.

Will happen at 20 random times in the SRM pools.

Will post when it does.
Read 9 tweets
27 Oct
1) Some brief thoughts on swap.projectserum.com:
2) NOT INVESTMENT ADVICE.
3) AMMs have problems.

Primarily impermanent loss; or put another way:

blindly providing while people pick you off to market moves.
Read 8 tweets
27 Oct
1) The first AMMs are live on @ProjectSerum!

1,000,000 SRM yield this month!

swap.projectserum.com Image
2) NOT INVESTMENT ADVICE

swap.projectserum.com isn't audited. Use at your own risk.
3) You can create AMM pools for any pair of SPL tokens; trade against the pools; add liquidity; etc.

1 second settlement, $0.00002 gas!
Read 9 tweets
26 Oct
1) HUGE UI/UX improvement to Solana:

Send someone an SPL token just using their SOL address!
2) NOT INVESTMENT ADVICE
3) What does this mean?

Well, on Ethereum, say your address is X.

Then you'd send ETH and all ERC20's directly to X.

Solana is different.
Read 14 tweets
26 Oct
1) AMMs on Serum
2) NOT INVESTMENT ADVICE
3) One thing you can do on Serum is build an AMM, just like Uniswap.

The difference is just that it's faster and cheaper.

Does that matter?
Read 14 tweets
21 Oct
1) calm and storm
2) NOT INVESTMENT ADVICE. NOT WEATHER ADVICE
3) It's been too long since there have been major releases in Serum, or in FTX.

Partially that's because there have been a lot of large things churning in the background which have taken a few montsh.

Partially that's because a few quicker things were delayed.
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!