Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

81–90 of 364 posts

Re: A fake job offer took down Axie Infinity

#81

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I think one other thing that bears mentioning is that LinkedIn's reporting doesn't easily let you explain how someone is performing a scam. If you're diligent you can find the link somewhere where you can actually explain it but when you just "report" someone or a job the response from LinkedIn is usually "We didn't find anything indicating this is a scam" or similar.

Re: A fake job offer took down Axie Infinity

#82

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

> LinkedIn is an absolute godsend for bad guys I am listed as the Principal on a couple of companies, and get constant approaches that are obviously fake (like an attractive young "stewardess" from Dubai, who just happened to like my picture (which is actually my logo)). I've given up reporting them, as LI always responds with "This is not in violation..."

Isn't LI owned by MS?

Re: A fake job offer took down Axie Infinity

#83

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

It’s a shame too. In my experience LinkedIn has been great for job hunting, indeed et al. were worthless time sinks for me. I want to keep it just for the ability to job hunt and get results but as you said…it’s a risk too.

That's the only thing it's good for, but that thing actually works. My last three job offers were from LinkedIn (I ultimately rejected one because my employer at the time gave me a counteroffer when I handed my notice, but I did accept the other two). The "content" on LI (feelhgood / motivational BS) is do ridiculous that I sort of contempt-read it ("hateread" would be to strong a word) for the heck of it, but I can't wrap my head around WHY people would participate in this nonsense for real.

Re: A fake job offer took down Axie Infinity

#84
post #82

Earlier quoted context omitted.

> LinkedIn is an absolute godsend for bad guys I am listed as the Principal on a couple of companies, and get constant approaches that are obviously fake (like an attractive young "stewardess" from Dubai, who just happened to like my picture (which is actually my logo)). I've given up reporting them, as LI always responds with "This is not in violation..."

Isn't LI owned by MS?

Yup. I'm gonna remove my cynical comment (although I still totally believe it). It's just not helpful. I think people can figure it out, for themselves.

Also, people use LI as a way to aggregate information, then send emails that appear to be from LI, but are not. I got one of those, yesterday, and reported it to LI, saying "These guys obviously used your service to construct this honker."

And LI's reply was ... envelope, please ... "Not our problem. Go away, kid. Yer bodderin' me." but stated a bit more politely.

I deliberately stay fairly open. I mentioned that, some time ago. It comes with some problems, like a determined bad actor can build up a fairly good profile.

But I have had years of experience, rubbing elbows with professional con artists, so I am maybe a little tougher to fool than many (but some approaches have come close -these folks are good). I would never be so arrogant to say that I can't be phished or whaled, but it's almost certainly not worth the effort.

Re: A fake job offer took down Axie Infinity

#85
post #83

Earlier quoted context omitted.

It’s a shame too. In my experience LinkedIn has been great for job hunting, indeed et al. were worthless time sinks for me. I want to keep it just for the ability to job hunt and get results but as you said…it’s a risk too.

That's the only thing it's good for, but that thing actually works. My last three job offers were from LinkedIn (I ultimately rejected one because my employer at the time gave me a counteroffer when I handed my notice, but I did accept the other two). The "content" on LI (feelhgood / motivational BS) is do ridiculous that I sort of contempt-read it ("hateread" would be to strong a word) for the heck of it, but I can'…

Yeah I really don’t see any appeal beyond jobs (my current job came from it). The content is just SEO/personal branding fodder.

Re: A fake job offer took down Axie Infinity

#86

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

Isn't the issue here that they used their work laptop or were on their work's internal network(VPN?) to "apply" for this job?

This is something I see/hear so often, people using work equipment/network to conduct their personal stuff. This, IMO, should not be allowed at all.

Re: A fake job offer took down Axie Infinity

#87

I think the media and tech writes overestimate the efficacy of spear phishing attacks. There is tons of research involved in finding suitable targets and then planning out the attack, such as the exploit, fake websites, fake emails, and other ingredients.

Huh? Don't understand your point. When the potential bounty is $540 million, seems like investment well spent. Just another reason crypto is a godsend for bad guys (obviously other financial crimes occur, e.g. with convincing folks to send fake wires) but there aren't many better ways to steal half a billion dollars I think. But, yeah yeah, "HN is so mean and hates crypto!!!"

This is a huge outlier though and it's not $500 million of cash but $500 million of crypto that must be processed/laundered slowly into usable cash, which may not even be doable. Given the recent crash it's probably more like a 100 hundred million now.

Re: A fake job offer took down Axie Infinity

#88
post #47

Earlier quoted context omitted.

You can easily embed arbitrary javascript into any PDF, and you can obfuscate it pretty well enough to get past most endpoint security tools on the market.

Is there a good no-nonsense way to clean PDFs of possible threats? Hunting around I see mentions of converting PDF->Postscript->PDF to remove junk, but I also see mentions that Postscript is its own security mess.

Your only option is to disable all of those fancy features. That config only lasts until someone needs to file a form with the government though.

Re: A fake job offer took down Axie Infinity

#89

Earlier quoted context omitted.

How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.

Same, although my perception is that LinkedIn has moved past its peak usefulness, and it would be better to spend time on other platforms than creating a LI account. All I hear about LinkedIn these days is spam.

LinkedIn sceptic here -- I would assume that in 2022, the closer you are to real, legal Microsoft-ecosystem roles, the more useful it is.. meanwhile, the independent people in tech get splashed with mud. No comment in this discussion has indicated to me that LinkedIn is not useful for certain swathes of established professions, even now.

Re: A fake job offer took down Axie Infinity

#90

Did this use a code-execution vulnerability in the PDF reader? or did they just trick the user into opening an executable?

I’m assuming it was an exploit in Adobe reader. The target cloud have even been persuaded to install Adobe reader to “e-sign” the document. PDFs don’t have the best track record when it comes to security
Post reply on HN