Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

21–30 of 364 posts

Re: A fake job offer took down Axie Infinity

#21

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.

Same, although my perception is that LinkedIn has moved past its peak usefulness, and it would be better to spend time on other platforms than creating a LI account. All I hear about LinkedIn these days is spam.

Re: A fake job offer took down Axie Infinity

#22

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages.

My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (The tweet in question called out my local PD for a dubious tweet they made, the person who tried to get me in trouble lived in a different state 12+ hours away). Thankfully my current company wouldn't have cared but there is no need to give people ammo.

Re: A fake job offer took down Axie Infinity

#25

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

It’s a shame too. In my experience LinkedIn has been great for job hunting, indeed et al. were worthless time sinks for me. I want to keep it just for the ability to job hunt and get results but as you said…it’s a risk too.

Re: A fake job offer took down Axie Infinity

#27

Chrome/Edge PDF viewers are pretty secure. You can reasonably safely open anything in them. Desktop PDF viewers like acrobat are gaping security holes... Don't use them!

I use PDF Expert on MacOS for its editing and markup abilities; built-in browser viewers aren’t good for that. What should I do?

Re: A fake job offer took down Axie Infinity

#28

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te...

I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni....

To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.

Re: A fake job offer took down Axie Infinity

#29

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Personally I don't update my LinkedIn until I start looking for a new job. There is absolutely no need for anyone to know where I work (or at least for me to share that far and wide publically) and I'm not interested in cold emails/cold linkedin messages. My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (T…

> Personally I don't update my LinkedIn until I start looking for a new job.

Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it exists.

Re: A fake job offer took down Axie Infinity

#30

I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.

It helps when your boss is a state actor and your target chooses to put $625 million in assets behind what amounts to a single point of failure
Post reply on HN