Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

231–240 of 364 posts

Re: A fake job offer took down Axie Infinity

#231

Earlier quoted context omitted.

Most PDF "attacks" in the real world are very unsophisticated. One of the most common uses of PDFs in a phishing context is just as a way to deliver a link that would likely result in blocking by email security products (many don't inspect inside PDFs, and even for those that do the PDF format is complicated enough that it offers tremendous opportunities for obfuscation). I would wager money that the "PDF attack" inv…

If it's just a javascript link to download an EXE, doesn't the target of the hack still need to run the EXE? Or are you saying that a link in a PDF can install and execute code on its own? Assuming it can't, then the engineer had to click to run some unknown EXE after downloading it... that should hardly be described as a "PDF attack".

There is a whole class of attacks related to “deep linking” and custom URL schemes that the operating system can pass to any application that registers itself to match it. At that point the sanitization is up to the application.

I recently stumbled upon a nice write-up [0] that described this class of attack and surveyed which software was vulnerable to it. Many crypto clients were included.

[0] https://positive.security/blog/url-open-rce

Re: A fake job offer took down Axie Infinity

#232

Earlier quoted context omitted.

This doesn’t mean it wasn’t an inside job. Dude could have a nice payday for “oops I got PDF hacked”, plus giving away enough information about their internal organization to make the attack feasible.

The organizations that were called in to investigate this are very well aware of the likelihood of insider-threat attacks. It is basically financial fraud 101. They haven't released any information beyond what was detailed here, but you can be certain that it was thoroughly covered.

Given it's crypto, there might be game in a game. You never know.

Re: A fake job offer took down Axie Infinity

#233
post #99

Earlier quoted context omitted.

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

When I first got into crypto, a few things were pretty much drilled into my head: - Not your keys, not your coins; always self-custody - Never use the same machine for trading and for work/surfing the web - Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.

I'd put an addendum to the first one

You can't own keys, so you can't own coins. You instead have access to coins when you have access to keys.

Re: A fake job offer took down Axie Infinity

#234
> Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors.

This paragraph perfectly encapsulates everything wrong with the way promoters sell Ethereum. Smart contracts can do little of interest beyond straight monetary transactions without information about the outside world. That information comes from "oracles", or what the article calls "validators".

The security guarantees of this system are far, far weaker than the Ethereum consensus protocol, as the article demonstrates. And yet, the system is hyped to the n-th degree by sheisters who ignore this basic fact with ludicrous claims about security and stability.

Zooming out, basically Ethereum is hyped as a platform for "smart contracts." But the minute a smart contract does anything beyond basic money transfers, it needs an oracle. And with the oracle comes radically reduced security.

Eventually, this will be obvious. For now, shenanigans like this will continue.

Re: A fake job offer took down Axie Infinity

#235
post #169
post #68

Earlier quoted context omitted.

> In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.” The company fully blames the employee. I wish so…

I don't think you can generalize Web3 companies to all software companies. Web3 companies have shown time and time again that they don't care much about security or good software development practices. I'm not sure if it's because the industry is so nascent or because the people joining are simply incompetent or because they don't care (or a combination of all three) but it's clear that Web3 companies have major inci…

> clear that Web3 companies have major incidents at higher rates than most other software companies

I won't argue this, but I think that it depends on where you look. Cryptography audit services are books out for months or years because of the demand from cryptocurrency projects. There's never been a vulnerability in the Bitcoin or Ethereum networks that allowed an attacker to steal funds or execute a double-spend. And cryptocurrency projects have pioneered whole fields of cryptography like zksnarks for security purposes.

Cryptocurrency projects often have a fundamentally very difficult problem to solve, and attackers are also very sophisticated. There are currently very few people with the expertise needed to implement a complex cryptocurrency project securely.

Disclaimer: I'm a protocol developer for a cryptocurrency project (not one of the ones mentioned here)

Re: A fake job offer took down Axie Infinity

#236

Earlier quoted context omitted.

Airlines would behave the same way if there wasn't an aggressive government regulatory body forcing them to learn from failures.

Government regulatory body and a pilot's union.

Do countries without a pilot's union have more unsafe air travel?

Re: A fake job offer took down Axie Infinity

#237

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.

As an engineer I never found LinkedIn useful. But during college I made sure to connect with everybody, even if I barely knew them. The only jobs I’ve had I got through other means, in some cases even “connections,” in the traditional sense of the word, which incidentally exist on the LinkedIn graph, but that’s just a mirror of real life and it’s not like the coordination occurs over LinkedIn messages anyway.

As a startup founder, it’s effective in some contexts, like as a contact point or promotional tool. We never felt the need to use it for recruiting. At least in the software industry, GitHub is a much more effective marketplace of talent. But LinkedIn can have some benefits for a startup outside of recruiting. Posting content about your product is a good way to stay in front of investors you’ve connected with who doomscroll their LinkedIn feed like a dev does HN. :) (it’s also something I need to automate because I block LinkedIn on /etc/hosts for productivity purposes..)

I’m not sure I’ve ever _sourced_ an opportunity from LinkedIn. I also never accept connections without at least one prior interaction. For me it’s a tool for following up and keeping in touch, not introductions. It might also be useful in some rare sales contexts, for some specific archetype of audience especially susceptible to the psychological tactics commonly deployed to the LinkedIn newsfeed. Developers are definitely not that audience (well, not on LinkedIn at least…)

Re: A fake job offer took down Axie Infinity

#238
post #79

Earlier quoted context omitted.

Cyberpunk is now, just sans the 80s fashion inspirations :)

> sans the 80s fashion inspirations :) You definitely haven't been paying attention to Gen-Z people then. The 80s are back.

That's a fair assessment of my attention

Re: A fake job offer took down Axie Infinity

#239

Earlier quoted context omitted.

and this is part of why i think cryptocurrencies should have died before large number of people wasted their money on it. for the average user without the time/knowledge/patience to handle cryptos "properly", the choice is between losing money while handling this shit yourself or losing money while trusting someone else to do it right.

Its an entirely free market. Just because one person doesn't understand the tech and loses his money doesn't mean that everyone else shouldn't be allowed to use it either. Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.

It’s fine for a few people to play with such a system. The issue if it’s absolutely clear crypto is incapable of widespread adoption or just about anything else people hype it up as, then it shouldn’t be hyped as if that stuff is a possibility.

I could never tell how much was incompetence vs fraud, but either way without the hype vastly fewer suckers would be holding the bag right now. The crypto ecosystem has been just been terrible for just about everyone and things are far from over.

Re: A fake job offer took down Axie Infinity

#240

Chrome/Edge PDF viewers are pretty secure. You can reasonably safely open anything in them. Desktop PDF viewers like acrobat are gaping security holes... Don't use them!

Does Adobe Acrobat really that bad? We use Acrobat Pro because it easy to modify pdf file with it. Other software can't do that much. Is there other pdf 'editor' that you can recommend?

Acrobat in a virtual machine that you don't connect to the network?

Most malware these days can't function without internet connectivity. The exploits typically connect to a server to get the rest of their code because they don't want any pesky researchers getting their hands on stuff.

Post reply on HN