Earlier quoted context omitted.
Why do pdfs even allow executing code outside of the pdf env ie why isn't there a sandbox/apis that allow very limited operation?
>Why do pdfs even allow executing code outside of the pdf env Some PM in 2006 thought it would be a good idea if PDFs were turing complete. I'm sure the word sandbox wasn't even thought about. 10 years later PDF (and more notably, Flash) became huge attack vectors. I think a far more interesting hack is when NSO used a PDF to embed a virtual machine inside an iPhone to develop a zero click exploit over iMessage: http…
A fake job offer took down Axie Infinity
361–364 of 364 posts
Re: A fake job offer took down Axie Infinity
#362Earlier quoted context omitted.
> That doesn’t absolve the con artist for running one though Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme? Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?
In the case of a literal Ponzi scheme it is pretty obvious who to prosecute. In the blockchain space many players have figured out ways to avoid being prosecuted for their schemes (many of which are little more than outright scams), but that doesn’t make what they’re doing ethical
Can you tell me where the Ponzi is on this page: https://compound.finance/
Re: A fake job offer took down Axie Infinity
#363Earlier quoted context omitted.
Yep, internal security is brittle. The initial pdf vector would be only the start of a long sequence of hacks, including social engineering. e.g. sending email from managers -- or slack messages as you mention.
How do you defend against getting email from internal people, especially from people you expect email from?
Re: A fake job offer took down Axie Infinity
#364Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…