Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

251–260 of 364 posts

Re: A fake job offer took down Axie Infinity

#251

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

All social networks with thorough mappings create vulnerability because of the trust people have in each other.

Re: A fake job offer took down Axie Infinity

#252
post #99

Earlier quoted context omitted.

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

> The main problem was using a machine that had access to half a billion dollars Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.

There is always that person.

Re: A fake job offer took down Axie Infinity

#253

I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…

Axie was always a pyramid scheme, not an actually enjoyable game. Being able to write off $540 million in crypto loss and ALSO keep the coin? Sounds like a pretty neat way to end a scheme.

Re: A fake job offer took down Axie Infinity

#254

I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…

More like Cryptonomicon without the Nazi gold backing.

Can't forget Stephenson, he's the third head of the '80s cyberpunk triad.

http://www.openthefuture.com/wcarchive/2004/10/stephenson_an...

Re: A fake job offer took down Axie Infinity

#255
post #246

Earlier quoted context omitted.

Exactly. I was on a meeting a couple of years ago and the co-worker who was presenting his desktop received a personal iMessage that flashed for everyone to see.

yeah but that's solved by disabling notifications before presenting.

True, but that’s just one of several reasons I’m reluctant to share work and personal activity on a single computer. I certainly wouldn’t conduct a job search on a work computer.

Re: A fake job offer took down Axie Infinity

#256
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

I can't believe a software developer is using an operating system/pdf viewer that isn't patched for security vulnerabilities as major as an RCE. Unless this was a zero day, but I would have assumed the article would mention that fact ..

I really wish we had details here too, but someone made a good point:

"Hey, you need a PDF viewer with scripts enabled for the digital signing.. can you install Adobe XXX?" would be a good line to get the mark to use a less-than-secure PDF viewer.

But also, since it was the North Korea hacking group, I'm not ruling out a 0-day... hopefully more details will come at some point.

Re: A fake job offer took down Axie Infinity

#257

Earlier quoted context omitted.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I think you are joking to bait us. At least use a VM running a VPN within it. It won't protect you from screen captures or keyloggers your employer put on your machine, but it will segregate files and network activity.

Believe it or not, not everyone gets a work-issued laptop (although this might be more common with hourly contractors)

Re: A fake job offer took down Axie Infinity

#258
post #239

Earlier quoted context omitted.

Its an entirely free market. Just because one person doesn't understand the tech and loses his money doesn't mean that everyone else shouldn't be allowed to use it either. Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.

It’s fine for a few people to play with such a system. The issue if it’s absolutely clear crypto is incapable of widespread adoption or just about anything else people hype it up as, then it shouldn’t be hyped as if that stuff is a possibility. I could never tell how much was incompetence vs fraud, but either way without the hype vastly fewer suckers would be holding the bag right now. The crypto ecosystem has been j…

Watch it be the reason we get tripped into a recession or some other ponzi-scheme-infused crash.

Re: A fake job offer took down Axie Infinity

#259

Earlier quoted context omitted.

Government regulatory body and a pilot's union.

Do countries without a pilot's union have more unsafe air travel?

No idea, but in the context of "why can't airlines scapegoat more pilots rather than deal with root causes?", unions are on the list of labor protections to consider.

Re: A fake job offer took down Axie Infinity

#260

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I’ve gotten vague legal threats from competitors who just browsed linked in and searched who they maybe thought could make the change they wanted and emailed me.

They seemed to avoid contacting executives or senior staff… but instead targeted folks capable of maybe making the change they wanted, and maybe jr / low enough on the pole enough to panic and do it.

I’ve seen it happen three times now, pretty scummy IMO.

Post reply on HN