Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
There's folks out there now offering tools like Octane, for example, recently won one of the Monad contest winners.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
So like I think stuff like that is definitely very interesting to consider.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
They have a lower cost entry point.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
But yeah, I would suggest anything like that, basically getting them to a much better starting position and not have the first time you're thinking about security, the time you're about to spend a lot of money.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
Yeah, I think so.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
Like, so on the policy layer for like admins, like,
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
The ones I mentioned are actually quite high value, like branch protection and using security keys on GitHub.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
I think integrating strong linters, static analysis tools, as well as AI tooling in your code flow is also very valuable.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
Seeing folks using Coder Rabbit or Codex or Copilot in the PR review process, it's
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
quite helpful, especially for small teams that are trying to build.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
There might not be enough people in the company to review your code.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
You might be just, yeah, you might take a section of the code.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
I might take a section of code.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
We agree on the API and we run off into our own adventure to try and build those pieces out.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
So I think it's really helpful to at least have a feedback mechanism that's happening throughout the day.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
I'm a big fan of linting as it is because I think if you're building idiomatic code, it's going to be easier to review.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
It means that an auditor is going to have a pretty good framing of understanding the tooling.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
A lot of the static analysis tooling will work a bit better if you use idiomatic code, as well as some of the LLMs and or the human review of that code.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
Yeah.
Web3 with Sam Kamani
372: The Security Mistakes Every Web3 Founder Makes (And How to Avoid Them) with Guest Speaker Johnathon Claudius from Asymmetric Research
Yeah, it's pretty, pretty straightforward thing.