Damus
Lance R. Vick profile picture
Lance R. Vick
@Lance R. Vick
I have audited or done security due diligence on a -lot- of fintech companies and the status quo should terrify most people.

In fact, I challenge anyone to show me a single crypto-asset custodian that does not grant one, or even hundreds of people, the power to do irreversible transfers of tens of millions of dollars alone.

Seriously, show me just one.

These companies are an open buffet for state actors, or often even any mildly motivated teen skiddies.
1
Lance R. Vick · 52w
"But but MY favorite custodian has multiple people use multiple keys. They can't all be hacked at once!" Yeah, they do that shit on macbooks controlled by JAMF that the IT team can control at any time. Also they do it with unsigned packages from Brew that any of 500+ internet randos can also change...