
Jutta Steiner: Secure Smart Contract Development
Source: YouTube · a16z crypto · published Mar 1, 2023 · 56:56
The video emphasizes that blockchain security extends beyond code to include operational procedures, governance, and organizational culture, requiring a shift from agile development to rigorous, formal methodologies to mitigate risks in decentralized systems 7:25-8:04.
Key Takeaways:
• Security is a process involving people and procedures, not just code, meaning vulnerabilities can arise from internal controls, lifecycle management, or external devices 7:25-8:04.
• Smart contract development is the opposite of agile; it is costly, difficult to upgrade post-deployment, and requires audits and formal specifications to ensure safety 13:00-13:27.
• Projects should avoid rolling their own blockchains and instead use established frameworks to share validator resources, preventing the division of security which makes chains easier to attack 16:04-17:04.
Building secure systems requires humility, a strong security culture, and collaboration across the open-source ecosystem to learn from past mistakes and handle inevitable future failures 31:44-32:19.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Music] thank you [Music] really excited um to be here with you today unfortunately in this remote capacity and it's a bit odd past midnight here in an empty office that's been empty now for two and a half weeks already but we do what we can so let's get started so I've been involved with crypto and security Now for more than seven years I think um joined the ethereum team in 2014 as the chief security back then this was all a pretty new field like I joined to help sort out the security Auto try to launch and then also ensure operational and security um but there wasn't much at the time no audit firms um that were dedicated to this um I stayed on throughout ethereum's launch and was around for um when the dial hack happened although that was already after we founded parity before I joined …