Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

51–60 of 364 posts

Re: A fake job offer took down Axie Infinity

#51

Earlier quoted context omitted.

> Personally I don't update my LinkedIn until I start looking for a new job. Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it…

Yeah, though I'd get dinged by that either way since I normally update my bio to include recent projects/tech I've worked with. This way I can hide behind plausible deniability "Oh, I just got around to adding X company to my LinkedIn" if I need to, whereas updating an existing entry is harder to justify (without giving away you are looking). Though I also try not to work for companies that I would need to worry abou…

> whereas updating an existing entry is harder to justify (without giving away you are looking)

I don't think it is at all. Indeed, if you're updating it regularly (every 3-4 months, perhaps?) with new project/task stuff, it's simply keeping things fresh in your mind, vs having to try to trawl back 3 years to think about project FOO.

If you only update it once every 2 years, then people can draw more nefarious conclusions.

Re: A fake job offer took down Axie Infinity

#52

Earlier quoted context omitted.

im guessing it was the ol' ".pdf.exe" trick.

That trick doesn't work anymore for any reasonably modern email client.

You can put it into a .zip archive or just send an email containing a link with a fake PDF

Re: A fake job offer took down Axie Infinity

#53
post #10

Did he get the job? because i guess he was fired from the previous one.

kinda disgusting he got fired for this if that was the case. Its a very sophisticated attack and I think its conversion rate would be rather high.

The article says they are no longer employed. It is possible that this exploit was only possible because of breaking other security policies.

At least, I hope that any reasonable organization doesn't secure $600+ million dollars by relying on the endpoint security of a device used to access LinkedIn

Re: A fake job offer took down Axie Infinity

#54
post #48

Earlier quoted context omitted.

Here's a demonstration of some example attacks using pdf: executing arbitrary js, and connecting to a samba server: https://www.sentinelone.com/blog/malicious-pdfs-revealing-te... I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni... . To some extent, the PDF viewer/OS doesn't matter. A ded…

The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.

I'm in this camp. All employees should be sent a laptop, or work with a remote environment that is isolated from your personal computer.

Re: A fake job offer took down Axie Infinity

#56

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

> LinkedIn is an absolute godsend for bad guys

I am listed as the Principal on a couple of companies, and get constant approaches that are obviously fake (like an attractive young "stewardess" from Dubai, who just happened to like my picture (which is actually my logo)).

I've given up reporting them, as LI always responds with "This is not in violation..."

Re: A fake job offer took down Axie Infinity

#57

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I think one shouldn't discount the attack vector that is just working in the Crypto industry, especially when you're someone who works with startups rather than the big guys.

In the "Web2 Sector", it would be very easy IMO to snuff out a fictitious company. I've gotten a handful of "offers" in the past and you can see straight through them, because the company doesn't exist in real life and you can't find any info on it, huge red flag.

The problem with the "Web3 Sector" IMO is you have a bunch of upcomming players in the space that no one has heard of. Just like investors in Cryto, if you're a developer in the space, no doubt you are jockeying to join a project that might land you a 7-10 figure windfall at the end.

So if an unheard of company approached me, I would tell them to kick rocks. If a similar company approached someone in the "Web3 Sector", they might take it thinking it's an emerging opportunity. I'm sure this still happens with Startups but my gut says it's really bad in the Web3 space.

Re: A fake job offer took down Axie Infinity

#58

Earlier quoted context omitted.

> Personally I don't update my LinkedIn until I start looking for a new job. Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it…

Yeah, though I'd get dinged by that either way since I normally update my bio to include recent projects/tech I've worked with. This way I can hide behind plausible deniability "Oh, I just got around to adding X company to my LinkedIn" if I need to, whereas updating an existing entry is harder to justify (without giving away you are looking). Though I also try not to work for companies that I would need to worry abou…

I doubt they'd actually ask you about it (and thus give you a chance to "explain" yourself), HR would just note you down and you'd be more likely to be laid off, less likely to get promotions approved, etc.

Re: A fake job offer took down Axie Infinity

#59

I'm still not entirely convinced this wasn't an inside job (or entirely made up) and they just put a nice pot of money away somewhere. Wouldn't be without precedent in the wonderful world of crypto...

You don't just take some dude's word for it when dealing with a $600+ million dollar heist. There were multiple third party investigators involved in the aftermath.

Perhaps they not taking his word, but waiting for him to move the funds?
Post reply on HN