🟡🔵 SecOps checklist for UkraineDAO 🟡🔵

I started providing some support to Alona but wanted to help out any other potential signers as well, so here’s the (living) document.

Let’s get the most important security considerations for DAO multisig members and other high value targets right. This target group means that we have to expect you to become the target of state-level attacks, so we should be careful. We should also assume that parts of the internet might be unavailable to you because of internet outages and censorship. So you will need to limit your reliance on typical cloud and web services.

Time is crucial, so let’s handle the most important things first before trying to make a perfect setup.

Multisig

Make sure the multisig requires at least 2 signers (currently there’s only one). But then try to ensure you actually have 2 people available whenever you need to sign transactions.

From experience, requiring 3 or more signatures is a hassle in hectic situations.

When making high value transactions, ask for someone who understands what is being signed for a confirmation that everything looks OK.

Crypto Wallets

Do you have a hardware wallet like Ledger or Trezor or ideally GridPlus? This is ideal, but make sure nobody knows your pin or has seen you type it into the device. If possible, use a separate laptop for signing multisig transactions — one that you do not use for normal web browsing and other activities. If you do not own a hardware wallet, it is still better to use a software wallet (like Metamask) on a separate laptop than just using your primary machine for signing transactions.

Do you have the mnemonic physically backed up (ideally two separate copies) in separate secure locations? The location(s) should be separate from your hardware wallet. E.g. If your house gets destroyed you should have access to your backups in a separate location.

Paper is OK, something durable like this metal plate is ideal.

Email Provider

I suggest you switch to a privacy respecting email provider. Create a free account at ProtonMail.

Passwords

Assume your existing passwords are compromised. Disable "Login with Google/Facebook" wherever you can. Instead choose to log in with email & password everywhere.

Make sure your relevant logins are secured with unique and strong auto-generated passwords (30 characters, including letters, numbers and special characters).

Manage your passwords with a password manager. I suggest a password manager that does not ever touch the cloud - a bit more hassle but doable.

I suggest you get the free and open source KeePass manager which is available for various platforms:

Reset  passwords in order of relevance:

  • Email
  • Centralized crypto exchanges
  • Messaging service (Telegram, Discord, Signal, etc)
  • Social media profiles

Two Factor Authentication

In order to secure your most relevant accounts (especially email and centralized crypto exchanges) you should activate Two Factor Authentication (2FA)

Option 1: use your hardware wallet (Ledger or Trezor). If you are using Ledger, install the Fido-2FA app on the hardware wallet. You can also use your Trezor asvk a 2FA device.

Option 2: Get a YubiKey

Option 3 (not preferred): Use Google Authenticator

Feedback

This document isn’t perfect. It aims at fixing the biggest issues in the shortest amount of time. If you have suggestions in improving it, leave comments in this doc and/or contact Sebastian.

💛💙

twitter.com/Ukraine_DAO