Ledger高管:AI时代加密攻击更易发生,冷钱包安全靠设计
Crypto Hacks Easier With AI: Ledger's Rogers
Ian, new title. Used to be chief experience officer. Now you're chief human agency officer. I've never spoken to chief human agency officer before. We're gonna get to what your title means in just a few minutes. But first, I wanna talk to you about this latest hack as we just heard from Alix Steel over at Galaxy. He referenced your product, and he said, not all cold storage is at risk. Why would this not happen in your view to Ledger's products?
Ian,新头衔。以前是首席体验官。现在你是首席人类能动性官。我以前从未与首席人类能动性官交谈过。几分钟后我们将讨论你的头衔含义。但首先,我想和你谈谈最近这次黑客攻击,正如我们刚刚从Galaxy的Alix Steel那里听到的。他提到了你的产品,他说,并非所有冷存储都有风险。在你看来,为什么Ledger的产品不会发生这种情况?
Well, this is for us, this is threat number one that you that you take that you consider when you're looking at securing your product. You know, what happened in this case is that they had a vulnerability in their in their firmware that that basically stored the Bitcoin over too small an address space. An address space that was small enough that that an attacker could effectively explore that whole address space and find the and find those addresses.
嗯,对我们来说,这是你在考虑保护产品安全时需要考虑的头号威胁。你知道,这次发生的情况是,他们的固件中存在一个漏洞,基本上将比特币存储在了太小的地址空间中。这个地址空间小到攻击者可以有效地探索整个地址空间并找到那些地址。
We we actually found a similar bug in in the trust wallet back in 2022, and we went through the responsible disclosure process and helped them, you know, move those customers to safety through through finding it. You know, I think that that what this is really pointing to is, you know, how these attacks are different in in the the age of AI when, you know, when when you, you know, you simply have a lot of firepower, and I mean, engineering firepower or programming firepower, to to go and find issues like this.
我们实际上在2022年也发现了Trust Wallet中的类似漏洞,我们经历了负责任披露流程,并通过发现它帮助那些客户转移到安全的地方。你知道,我认为这真正指向的是,在人工智能时代,这些攻击有何不同,当你拥有大量火力时——我指的是工程火力或编程火力——去发现这样的问题。
So, you know, for, for wallets such as Ledger, you know, we actually do that with what's what's called entropy. That's done in hardware using special secure hardware. And then it goes through a certification process that that specifically targets that entropy to make sure that it does exactly what it says. There's no software fallback on that. It happens it happens on the chip in hardware, and, you know, it effectively, you know, gives you an address space with, you know, the number three with 67 zeros behind it, which is, you know, more than sufficiently large to to avoid an attack like this, where that's simply not the case in in this, vulnerability that was exploited last week.
所以,对于像Ledger这样的钱包,我们实际上使用所谓的熵来做这件事。这是在硬件中使用特殊的安全硬件完成的。然后它经过一个专门针对该熵的认证过程,以确保它确实如其所说。没有软件回退。它发生在芯片上的硬件中,而且,它实际上给你一个地址空间,数字3后面跟着67个零,这远远足够大,可以避免这样的攻击,而上周被利用的漏洞中情况并非如此。
So, Ian, the big question here is whether people are drawing the wrong conclusions from this hack. Why shouldn't investors take away that this is evidence that hardware wallets and maybe self custody is inherently risky? I mean, to me, this is, you know, any, crypto that's anywhere, even if it's on an exchange, it's somewhere protected by some kind of security. At the end of the day, crypto is fundamentally a self custody exercise.
那么,Ian,这里的大问题是人们是否从这次黑客攻击中得出了错误的结论。为什么投资者不应该认为这证明了硬件钱包,也许自我托管本身就存在固有风险?我的意思是,对我来说,你知道,任何地方的加密货币,即使是在交易所上,它也在某种安全措施的保护之下。归根结底,加密货币从根本上说是一种自我托管的实践。
And whether that that custody is in the hands, of an exchange or an institution, or in the hands of the individual, the security is paramount. So I think that that it it would be wrong, to, you know, to to look at this as, you know, a self custody issue or, a hardware wallet issue. At the end of the day, wherever your assets are stored, you should be interested in the level of security that's protecting them. Yeah. I wanna go back to what you said about security in the age of AI.
无论这种托管是在交易所或机构手中,还是在个人手中,安全都是至关重要的。所以我认为,将此事视为自我托管问题或硬件钱包问题将是错误的。归根结底,无论你的资产存储在哪里,你都应该关注保护这些资产的安全级别。是的,我想回到你关于人工智能时代安全的说法。
And and and in your view, how, you know, the potential vulnerabilities can be uncovered, not just by, you know, good and bad actors more quickly as a result of AI, but also how you create protection for these assets in the age of AI. What's Ledger's approach to doing that? Yeah. I I would actually zoom out a bit and say that this is pointing to, you know, the ability for AI to to find vulnerabilities in all kinds of things.
在你看来,不仅好人或坏人如何能借助人工智能更快地发现潜在漏洞,而且你如何在人工智能时代为这些资产创造保护。Ledger 的做法是什么?是的,我实际上想稍微放大一点说,这指向了人工智能在各种事物中发现漏洞的能力。
So it makes sense that that that attackers would be would be targeting, you know, people with with you know, that were anywhere they can in the digital asset space. But, you know, we're we're hearing stories about attacks on, you know, The US water supply, and and the reality is is that attacks are are simply easier. You know, they've always been a concern for us. That's that's the business that ledger is in. You know?
因此,攻击者针对数字资产领域中任何可能的地方的人,这是有道理的。但是,你知道,我们听到关于攻击美国供水系统之类的故事,现实是攻击确实变得更容易了。你知道,这些一直是我们关注的问题。这就是 Ledger 所做的业务。你知道吗?
But I I stood on stage, you know, saying we're moving into an agentic future. And an agentic future where we give our passwords, our credit cards, and our identities to agents is is a security nightmare. I said that at the end of last year, and I didn't really get much response to it. You know, at the beginning of this year with, with Open Claw, people started saying, oh, I I see this thing that you're that you're talking about.
但我站在舞台上说过,我们正在进入一个代理型未来。一个我们把密码、信用卡和身份交给代理的未来,那将是一场安全噩梦。我在去年年底说过这话,当时没得到太多回应。你知道,今年年初随着 Open Claw 的出现,人们开始说,哦,我明白你当时说的东西了。
You know? And then, of course, we've had mythos, and, we've got hugging face. And now, you know, to me, the cold card attack goes in that lineage, as much as anything else. And I would look at this from three different angles. One, it's, easier than ever for an attacker to go find these kind of vulnerabilities. Also, we're all using AI to create more code, which creates more surface area for those attackers. And then third, we are, you know, in our enterprises, employing agents, which are effective you know, effectively probabilistic coworkers, you know, who are working alongside us that have access to our secrets.
你知道吗?然后,当然,我们有过神话,而且,我们有了Hugging Face。现在,你知道,对我来说,冷卡攻击和任何其他东西一样,属于那个谱系。我会从三个不同的角度来看待这个问题。第一,攻击者比以往任何时候都更容易找到这类漏洞。此外,我们都在使用AI来创建更多代码,这为那些攻击者创造了更大的攻击面。然后第三,你知道,在我们的企业中,我们正在使用智能体,它们实际上是概率性的同事,你知道,它们与我们并肩工作,能够访问我们的秘密。
And those secrets, you know, they might just be email or Slack, but those are still secrets that we're expect not expecting to be, to be shared outside of our company. So, you know, I think that, you know, we're this is kind of a a brave new world. And from a security expect perspective, AI is, is is coming at us very quickly here. Well, maybe that's a good segue to talk about your new title, chief human agency officer.
而这些秘密,你知道,它们可能只是电子邮件或Slack,但这些仍然是秘密,我们不希望它们被分享到公司外部。所以,你知道,我认为,你知道,我们正处于一个勇敢的新世界。从安全角度来看,AI正非常迅速地朝我们而来。嗯,也许这是一个很好的过渡,来谈谈你的新头衔——首席人类能动性官。
You were, for four years at Ledger as chief experience officer. You've had a background in in luxury and technology. You were at Apple, helped create Beats. You your background goes back many decades into the nineties in in terms of thinking about the Internet and and what this technology can do. What is a chief human agency officer? Yeah. So, obviously, I have a proclivity for, for, conversation starter titles. You know, chief experience officer was about improving the experience in crypto and chief human agency officer.
你曾在Ledger担任了四年的首席体验官。你有奢侈品和科技领域的背景。你曾在苹果公司工作,帮助创建了Beats。你的背景可以追溯到几十年前的九十年代,那时你就在思考互联网以及这项技术能做什么。什么是首席人类能动性官?是的。所以,显然,我倾向于使用能引发对话的头衔。你知道,首席体验官是关于改善加密体验的,而首席人类能动性官……
My focus at Ledger is artificial intelligence and the security related to artificial intelligence. Our position is that, you know, our AI security is probably a top three problem, for humanity at the moment, and that's not for us, that wasn't an AI title. It because our what is Ledger's role in that? Our role in that is keeping humans safe, protecting the secrets of humans, and keeping humans in the loop. Meaning that, you know, for us, there the as we say, even, we've always said when it comes to crypto security, the only security is by design.
我在Ledger的焦点是人工智能以及与人工智能相关的安全。我们的立场是,你知道,AI安全可能是目前人类面临的前三大问题之一,而且这不是因为我们,那不是AI头衔。因为我们在其中的角色是什么?我们的角色是保护人类安全,保护人类的秘密,并让人类保持在循环中。这意味着,你知道,对我们来说,正如我们所说,甚至,我们一直说,在加密安全方面,唯一的安全是设计上的安全。
You know? And I think that that's really come up in in this cold card case. You know, the security that that is a must to keep consumers secure is by design. And the the very same, you know, way of thinking applies to, to AI security in that there needs to be a division of labor between the secrets that our AI holds and what it's able to do on its own and then, you know, where the security of that lives. And the analogy that I like to use is, one of, you know, a 16 year old and the car keys.
你知道吗?我认为这在冷卡案中确实体现出来了。你知道,保护消费者安全所必需的安全性是设计使然。同样的思维方式也适用于人工智能安全,即需要在我们的人工智能所持有的秘密、它能够自主执行的操作以及这些安全性的归属之间进行分工。我喜欢用的一个类比是,一个16岁少年和车钥匙的故事。
Right? The car keys are not in the 16 year old's bedroom. They're with dad. And whether or not he can use the car, you know, depends on the moment. If it's 8AM on a Monday and he's driving to school, that's, you know, you can say within policy. And, of course, he may do that. If it's 10:00 on a Friday night and he's drunk, that's outside of policy. And, of course, he may not do that. But we fundamentally have these probabilistic coworkers.
对吧?车钥匙不在16岁少年的卧室里,而是在爸爸那里。他能否用车,取决于具体时刻。如果是周一早上8点,他开车去上学,那可以说是在政策允许范围内,他当然可以这么做。如果是周五晚上10点,他喝醉了,那就在政策之外,他当然不能这么做。但从根本上说,我们拥有这些概率性的同事。
And, you know, whether you're working with crypto and we have, a full suite so that you can securely give an agent a wallet, but not the keys to the wallet, or anything else that an agent might do, the security around, the secrets that the, that the agent has access to is is just as paramount as it is in crypto.
而且,无论你是在处理加密货币,我们有一整套方案,可以安全地给代理一个钱包,但不给钱包的钥匙,或者代理可能做的任何其他事情,围绕代理可访问的秘密的安全性与加密货币中的安全性同样至关重要。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力