John Furrier sits down with Anand Prakash of AppSecure at HoshoCon 2018, the first ever blockchain security conference.
#HoshoCon #theCUBE
https://siliconangle.com/2018/10/22/apis-are-leaving-crypto-door-ajar-to-burglars-says-white-hat-hacker-hoshocon/
APIs are leaving crypto door ajar to burglars, says white-hat hacker
White-hat bounty hunters put enterprises’ cybersecurity systems to the test for pay. Their clients figure it’s preferable to pay a skilled hacker a reasonable fee to point out vulnerabilities than wait for a black hat to rob them blind.
These pros are now putting cryptocurrency exchanges and initial coin offerings to the test — and their grades are nothing to boast about, according to Anand Prakash (pictured), founder of AppSecure India Pvt Ltd.
Prakash spoke with John Furrier, host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, during the recent HoshoCon event in Las Vegas. They discussed the need for greater security in the expanding crypto market.
Cryptosecurity needs kick in the pants
Prakash has a reputation as one of the most talented white-hat bounty hunters around. He has hacked Facebook, Twitter, Uber and other services. With cryptocurrency hack becoming the modern-day bank robbery, it was clear to Prakash that crypto businesses needed to take a hard look at their security checks. So he began hacking ICOs and crypto exchanges — and all were surprised at how easy it was.
“They thought putting up a two-factor authentication or something like that makes their account secure,” he said. This is not the case at all. Prakash was easily able to hack through their application program interfaces. In fact, APIs and URLs are two access points now quite popular with hackers — and many companies are not properly securing them, according to Prakash.
“We don’t need a big, high-end machine to hack into services,” Prakash said.
Most of the cryptocurrency exchanges he has hacked lacked basic security checks. “They have a password screen on the [user interface], but I can simply hit the API, and with no authentication or authorization, I can just log in to anyone’s account. And then I can get funds out of their system.” Also with tokens, he also has obtained personally identifiable information of users.
Prakash recommends crypto businesses get busy cleaning house and securing their API entry points and other vulnerabilities.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of HoshoCon 2018:
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
HoshoCon 2018 | Las Vegas. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For HoshoCon 2018 | Las Vegas
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for HoshoCon 2018 | Las Vegas.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
HoshoCon 2018 | Las Vegas. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to HoshoCon 2018 | Las Vegas
Please sign in with LinkedIn to continue to HoshoCon 2018 | Las Vegas. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Anand Prakash, AppSecure | HoshoCon 2018
John Furrier sits down with Anand Prakash of AppSecure at HoshoCon 2018, the first ever blockchain security conference.
#HoshoCon #theCUBE
https://siliconangle.com/2018/10/22/apis-are-leaving-crypto-door-ajar-to-burglars-says-white-hat-hacker-hoshocon/
APIs are leaving crypto door ajar to burglars, says white-hat hacker
White-hat bounty hunters put enterprises’ cybersecurity systems to the test for pay. Their clients figure it’s preferable to pay a skilled hacker a reasonable fee to point out vulnerabilities than wait for a black hat to rob them blind.
These pros are now putting cryptocurrency exchanges and initial coin offerings to the test — and their grades are nothing to boast about, according to Anand Prakash (pictured), founder of AppSecure India Pvt Ltd.
Prakash spoke with John Furrier, host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, during the recent HoshoCon event in Las Vegas. They discussed the need for greater security in the expanding crypto market.
Cryptosecurity needs kick in the pants
Prakash has a reputation as one of the most talented white-hat bounty hunters around. He has hacked Facebook, Twitter, Uber and other services. With cryptocurrency hack becoming the modern-day bank robbery, it was clear to Prakash that crypto businesses needed to take a hard look at their security checks. So he began hacking ICOs and crypto exchanges — and all were surprised at how easy it was.
“They thought putting up a two-factor authentication or something like that makes their account secure,” he said. This is not the case at all. Prakash was easily able to hack through their application program interfaces. In fact, APIs and URLs are two access points now quite popular with hackers — and many companies are not properly securing them, according to Prakash.
“We don’t need a big, high-end machine to hack into services,” Prakash said.
Most of the cryptocurrency exchanges he has hacked lacked basic security checks. “They have a password screen on the [user interface], but I can simply hit the API, and with no authentication or authorization, I can just log in to anyone’s account. And then I can get funds out of their system.” Also with tokens, he also has obtained personally identifiable information of users.
Prakash recommends crypto businesses get busy cleaning house and securing their API entry points and other vulnerabilities.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of HoshoCon 2018: