Earlier quoted context omitted.
The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.
When I first got into crypto, a few things were pretty much drilled into my head: - Not your keys, not your coins; always self-custody - Never use the same machine for trading and for work/surfing the web - Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.
A fake job offer took down Axie Infinity
211–220 of 364 posts
Re: A fake job offer took down Axie Infinity
#212Earlier quoted context omitted.
Opening the pdf wasn't "company work", so maybe everything should be done in a VM? (Not the same VM!)
He opened it on a company device I assume
Re: A fake job offer took down Axie Infinity
#213Earlier quoted context omitted.
Where are my mantis blades?
The people in this review seem to think they're alright, but they look very silly to me: https://www.youtube.com/watch?v=tB4DDM8VHVg YMMV. But hey, maybe you can ask them for their design.
And pretty impractical as well. They look really poorly designed in terms of maximizing leverage. It also looks like they lose a lot of energy in the flexing of the entire mechanism and their arm, compared to a blade held directly in the hand.
Re: A fake job offer took down Axie Infinity
#214Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…
on the other hand I bet you could collect some interesting things by creating a few fake people as linkedin honeypots at FAANGs, and I would be very surprised in their infosec/netsec teams aren't already doing this.
or getting real people who opt-in to have their linkedin profile receive incoming scams, virus, trojans, phish links and pipeline them into the infosec/netsec team.
Re: A fake job offer took down Axie Infinity
#215What's the best practice, security-wise, for viewing PDFs?
Re: A fake job offer took down Axie Infinity
#216Earlier quoted context omitted.
My understanding of the article was that only 1 person was compromised and that the exploit installed on their computer was then used to access the validator nodes themselves. FWIW, I have no idea what a validator node is but I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up).
> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
not to say it can't be done, but it was unexplained
Re: A fake job offer took down Axie Infinity
#217Wow! These folks were really on the ball if it took that much social engineering just to get an employee to open a PDF.
Re: A fake job offer took down Axie Infinity
#218Can someone explain to me how a pdf can execute code?
PostScript the "graphics language" that PDF was built around is a Turing Complete language.
Re: A fake job offer took down Axie Infinity
#219So they lost half a billion dollars because they forgot to set up Multi Factor Authentication?
Re: A fake job offer took down Axie Infinity
#220Seesh, you could finance a war with $2B.