Opens in a new tab
vmblog logo 2024 wht (updated)

As Easy As 1, 2, 3? Understanding Web3's New Security Paradigm

Share: 

David Marshall | Published: December 13, 2022

By Ronghui Gu, CertiK CEO and co-founder

Web3 represents a fundamental evolution of the internet. It is as much of a departure from Web 2.0 as the social media platforms and streaming services that defined this era were from the early internet’s dial-up connections and Usenet forums.

Along with this major development in the internet’s functionality and infrastructure come new security implications that it’s essential to understand in order to accurately weigh the risks and opportunities of Web3.

In many ways, Web3’s in-built cryptography is a huge step forward for privacy and security. Yet the billions of dollars lost from Web3 platforms tell a different story. As we will see, security is fundamental to the increases in functionality that lead to increases in adoption, which brings value to users all over the world.

Yet the transitions between major epochs of the internet are rarely smooth. It’s important to keep this in mind when considering the rocky road that Web3 is currently traversing on its mission to bring a freer, fairer internet to everybody.

To fully grasp the magnitude of what Web3 is offering – and what stands in the way of it delivering on its promise – let’s take a look back at how internet security has evolved over the last few decades, from the early internet, to Web 2.0, and now to Web3.

The Early Internet

The World Wide Web before the mid-1990s was mainly the domain of academic institutions and dedicated hobbyists: an interesting new technology with a high barrier to entry. It was a relatively closed and permissioned system, which meant that pages were not necessarily locked down with the degree of security that mass adoption of the technology would later require. The transition from closed intra-nets to the open inter-net brought with it some growing pains.

An illustrative example of this comes from a teenage Edward Snowden, who would later go on to play a famous role in the (illegal) disclosure of classified documents relating to U.S. intelligence agencies’ penetration of internet infrastructure, including major Web 2.0 platforms and service providers like Google, Facebook, Apple, and Microsoft.

“I’d been reading some article about the history of the American nuclear program, and before I knew it, with just a couple of clicks, I was at the website of the Los Alamos National Laboratory, the country’s nuclear research facility… [which] had a glaring security hole. Its vulnerability was basically the virtual version of an unlocked door: an open directory structure… I walked as fast as I could from file to subfolder to upper-level folder and back again, a teen let loose through the parent directories. Within a half hour of reading an article about the threat of nuclear weapons, I’d stumbled upon a trove of files meant only for the lab’s security-cleared workers.”

Edward Snowden, Permanent Record

Snowden reported this vulnerability to Los Alamos, and it was subsequently fixed. Yet it highlights the insecurity of transitions between major epochs of the internet, in this case from essentially a military/governmental/academic technology (ARPANET and later evolutions) to a commercial and publicly-accessible technology.

The military’s influence over the development of the internet was broad, and persisted well into the 1990s. The release of open-source encryption software PGP (which stands for Pretty Good Privacy) led to federal charges against its creator for “munitions export without a license.” These charges were eventually dropped and the United States government significantly relaxed its restrictions on the exporting of cryptographic software, though some remain to this day.

The widespread adoption of cryptography unlocked new use cases for the internet: it became possible to enter sensitive data (like credit card information) into websites, without which major industries like e-commerce would not be possible. Encryption represented a quantum leap in the security and functionality of the internet, which soon resulted in the era known as…

Web 2.0

Web 2.0 is largely defined by the centralized platforms that brought the internet to the masses. Google search made the internet legible, Facebook connected billions of users worldwide, and Apple (and Android) put a supercomputer in everyone’s pocket. These companies recognized that the internet had come of age, and they built platforms and products on top of it that took full advantage of its capabilities.

Centralization increased not just on the level of applications but on the infrastructure layer too. Cloud computing began to take off in the early to mid-2000s and has continued to grow since then. Cloud computing now accounts for the majority of IT infrastructure spending, and just two companies – Amazon’s AWS and Microsoft’s Azure – command more than half of the $200 billion market for cloud infrastructure.

The ease of use that made widespread adoption of these platforms possible relied in large part on the efficiencies brought about by centralization. While Web 2.0 brought the internet to the masses, it did so at the cost of decentralization. The tech giants that made the internet accessible now wield unprecedented power via their control of the applications that billions of people around the world use.

Yet Web 2.0 suffered (and continues to suffer) from major security issues. The centralized databases that these companies maintain are the resource from which they draw much of their power (data is the new oil, anyone?). But these databases are prime targets for hackers, and major companies, health providers, and even government law enforcement agencies have repeatedly proven they cannot be trusted with users’ sensitive personal data. Clearly, Web 2.0 security has not kept pace with the scale of the data these organizations now control.

Web3

Web3 addresses many of the issues inherent in Web 2.0. Smart contracts built on immutable blockchains provide a much more transparent and decentralized method of digital coordination, one in which the customer is on equal terms with the service provider and not reduced to having their data sold as the product.

Blockchain technology is powered by encryption. It’s what makes Web3 fundamentally a security technology. Just like SSL did decades ago, blockchain makes the internet a safer place to transact and enables a whole suite of new Web3 applications.

There are parallels with Web 2.0’s reliance on cloud computing, too. Whereas Web 2.0’s cloud infrastructure is heavily centralized, Web3 relies on globally decentralized data storage. That’s the whole point of blockchain: to securely manage and update a database stored on thousands of computers across the world where there are strong incentives for dishonesty and malicious behavior.

But new technology brings new security implications, and Web3 is no different. While it’s important not to conflate the merits of the technology itself with the nefarious uses that malicious actors can put it to, it’s undeniable that Web3 has a security problem.

DeFi protocols that hold hundreds of millions of dollars worth of tokens become lucrative targets for bad actors. Rugpulls – where an unscrupulous actor deploys a token, hypes it aggressively, and then disappears with their profit at the most profitable moment – continue to plague the industry. And market manipulation, insecure cross-chain bridges, and a host of other security incidents have hurt retail users and damaged faith in this revolutionary technology. So far this year, a total of more than $2.5 billion has been drained from Web3 protocols.

However, this number is still just a fraction of the losses incurred by Web3-adjacent centralized exchanges and lending platforms that operate opaque, unverifiable business models. Blockchain technology offers solutions to these problems, and centralized crypto organizations are doing everyone a disservice by not adopting them.

How Web3 Secures Its Future

FTX’s collapse will unfortunately tarnish the industry as a whole. However, the shady accounting, hidden insolvency, and alleged outright fraud that led to its downfall are simply not possible in Web3. With few exceptions, a smart contract cannot defraud anyone. The terms of its agreement are immutable and agreed upon by all parties involved.

DeFi protocols have another inherent advantage over centralized finance: their solvency is published on-chain with every new block. But most lack the dedicated security teams that large organizations can retain. Luckily, there is a suite of security solutions out there for DeFi protocols to utilize.

Pre-deployment auditing is critical to ensure vulnerabilities are picked up on before they can be exploited. Web3 is open-source by default, but it’s also an increasingly complex system that requires a multi-faceted approach to security. Expert manual review combined with AI-powered scanning of known vulnerabilities combine to create defense in depth.

But security doesn’t stop there. It’s critical to make use of post-deployment on-chain monitoring tools that work around the clock to watch the blockchain for suspicious activity, proactively flagging it to give DeFi teams a headstart on their response. And since open-access and transparency are core tenets of the Web3 space, users should be able to take advantage of these tools too.

Web3 offers a new vision of a free and fair internet. It offers vastly more functionality than the early internet while remaining unconstrained by the centralized service providers of Web 2.0. As we work to make this vision a reality, it’s important to keep in mind the features that make Web3 an improvement over previous evolutions of the internet. Transparency, security, and decentralization are what distinguishes Web3 from opaque, insecure, centralized platforms.

While the transition between major epochs of the internet has not historically been particularly smooth, Web3 can ease its own transition by committing to its underlying ideals and making use of the technology that’s available to protect users, protocols, and the future of the internet.

##

ABOUT THE AUTHOR

Ronghui-Gu 

Professor Ronghui Gu is the Tang Family Assistant Professor of Computer Science at Columbia University and Co-Founder of CertiK. He holds a Ph.D. in Computer Science from Yale University and a Bachelor’s degree from Tsinghua University. He is the primary designer and developer of CertiKOS and SeKVM. Gu has received: an SOSP Best Paper Award, a CACM Research Highlight, and a Yale Distinguished Dissertation Award.