Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

261–270 of 364 posts

Re: A fake job offer took down Axie Infinity

#261

Earlier quoted context omitted.

> Personally I don't update my LinkedIn until I start looking for a new job. Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it…

Yeah, though I'd get dinged by that either way since I normally update my bio to include recent projects/tech I've worked with. This way I can hide behind plausible deniability "Oh, I just got around to adding X company to my LinkedIn" if I need to, whereas updating an existing entry is harder to justify (without giving away you are looking). Though I also try not to work for companies that I would need to worry abou…

I can’t believe how living a life with this level of scrutiny on how you behave online is acceptable to anyone.

Re: A fake job offer took down Axie Infinity

#262
post #99

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

It wouldn't be one machine. The initial incursion would have been used to leverage other local attacks. Then targeting domain controllers and admin accounts.

Probably also reading email; one possible way of finding it needed to get at 5 of 9 keys to unlock.

Re: A fake job offer took down Axie Infinity

#263

Earlier quoted context omitted.

How usable is LinkedIn with a pseudonym? Is that a security industry only practice or could a regular dev get away with that too? I've always been shy about having a profile with my actual name but id consider one with a thin veil of anonymity.

I really wish I could just dump LI and delete my account; it's just spam and another service for those who love to self promote themselves. I won't do it because I'm not sure how it will impact by ability to get a job. How many of you have gotten jobs with no LI account? YEO?

i've never felt the need to use linkedin.

Re: A fake job offer took down Axie Infinity

#264

Earlier quoted context omitted.

because the workstation was compromised by opening a corrupted pdf, but that vector wouldn't compromise the other machines unless users on them could be induced to open the same pdf. not to say it can't be done, but it was unexplained

It doesn't have to be the same pdf, it could have been an attachments from compromised machine via email/slack. "Hey, can you help me figure this unusual log/transaction summary". How many wouldn't open such an attachment from a "colleague"?

Yep, internal security is brittle. The initial pdf vector would be only the start of a long sequence of hacks, including social engineering. e.g. sending email from managers -- or slack messages as you mention.

Re: A fake job offer took down Axie Infinity

#265
post #95

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I'm not sure this is Linkedin's problem to solve. They are just a directory. I suppose they could add a phishing warning for messages sent on LinkedIn, but really it's an education problem, teaching people to identify what phishing emails look like and how to avoid them. This is a problem I've been working on since at least 2003, when we realized that the best way to prevent eBay account takeovers was teaching people…

> I'm not sure this is Linkedin's problem to solve. They are just a directory.

this was the attitude Microsoft had about malware on Windows for a long time and it led to so much misery and ruin across the world.

Re: A fake job offer took down Axie Infinity

#266

Earlier quoted context omitted.

Likely this was a standalone PDF reader hack (rather than a browser), since those can have many more features and a much larger attack surface. It says it was an offer letter, so my guess is that opening it in the browser came up with an error like "to be able to digitally sign this offer letter, please open it in a desktop PDF reader with full scripting support enabled :)"

I guess we all need to be opening anything remotely phishy in VMs to avoid similar issues

No post body was provided.

Re: A fake job offer took down Axie Infinity

#267

Earlier quoted context omitted.

I understand your argument but this kind of reasoning consistently fails to be predictive. If things worked as you describe, there would be way more consensus amongst skilled engineers on political topics. In practice people are very skilled at selectively turning off their brain, especially when they stand to benefit. “It's difficult to get a man to understand something when his salary depends on not understanding i…

I completely agree in principle but the nuance here is that I’m leaning on the belief that people joining Axie do not “…stand to benefit…” because the long term prospects of Axie Infinity are not good (and have never been good) and so anybody analysing the benefit of joining them — who has a broad range of opportunities available to them — would immediately see how little they stand to benefit from getting involved w…

I disagree. Competent engineers go where they will be paid, and crypto startups are often one of the few places that can pay our frankly insane compensation requirements.

I had a recruiter contact me just recently for some crypto game that was offering something like $600k/year (which I unfortunately assume was at least partly stock) for one of them, and that would certainly have been enough to attract real security talent.

Re: A fake job offer took down Axie Infinity

#268

> Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors. This paragraph perfectly encapsulates everything wrong with the way promoters sell Ethereum. Smart contracts can do little of interest beyond straight m…

Oracles that connect to off-chain data are usually understood as points of centralization, I don’t think Ethereum or it’s developers are selling otherwise. Most Ethereum developers are advising against relying on bridges across security zones that would be upheld by multisigs and oracles, they are vulnerable to attacks. A better model than a bridge to sidechain would be a rollup - posting proofs on chain without givi…

A better model than a bridge to sidechain would be a rollup - posting proofs on chain without giving the sequencer the ability to steal or control user funds.

What's a "proof" of an event in the outside world? No such thing exists.

The OP's point that dependence on real world events is a security flaw remains. No alternative programming method can change this because nothing on the Internet can guarantee a real event has happened. This is inherent.

Re: A fake job offer took down Axie Infinity

#269
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

Me too, but I have to say there is literally nothing sensible I have access to, only git repos without secrets and useless code.

Re: A fake job offer took down Axie Infinity

#270
post #239

Earlier quoted context omitted.

It’s fine for a few people to play with such a system. The issue if it’s absolutely clear crypto is incapable of widespread adoption or just about anything else people hype it up as, then it shouldn’t be hyped as if that stuff is a possibility. I could never tell how much was incompetence vs fraud, but either way without the hype vastly fewer suckers would be holding the bag right now. The crypto ecosystem has been j…

Watch it be the reason we get tripped into a recession or some other ponzi-scheme-infused crash.

Crypto isn't big enough to do that on it's own.
Post reply on HN