Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.
A fake job offer took down Axie Infinity
21–30 of 364 posts
Re: A fake job offer took down Axie Infinity
#22Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (The tweet in question called out my local PD for a dubious tweet they made, the person who tried to get me in trouble lived in a different state 12+ hours away). Thankfully my current company wouldn't have cared but there is no need to give people ammo.
Re: A fake job offer took down Axie Infinity
#23Re: A fake job offer took down Axie Infinity
#24Re: A fake job offer took down Axie Infinity
#25Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
Re: A fake job offer took down Axie Infinity
#26Re: A fake job offer took down Axie Infinity
#27Chrome/Edge PDF viewers are pretty secure. You can reasonably safely open anything in them. Desktop PDF viewers like acrobat are gaping security holes... Don't use them!
Re: A fake job offer took down Axie Infinity
#28Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.
I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni....
To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
Re: A fake job offer took down Axie Infinity
#29Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages. My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (T…
Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it exists.
Re: A fake job offer took down Axie Infinity
#30I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.