Live data from Hacker News

PeopleDAO “exploited” by Google Docs edit

twitter.com

1–10 of 87 posts

Re: PeopleDAO “exploited” by Google Docs edit

#3
post #2

Is clicking on a link really “hacking”? > The accounting lead mistakenly shared a link with edit access in a public channel in discord. The hacker gained edit role via the link.

> After gaining the access, the hacker inserted a 76 ETH payment to himself in the sheet, and set it invisible

It might not be a real hack in the traditional sense, but hiding critical information so a human makes an incorrect choice is good enough to be considered social engineering for me.

Re: PeopleDAO “exploited” by Google Docs edit

#4
I know this is a low value way of saying this, so, apologies up front but:

Fucking lol at their bookkeeping and payout system just being a spreadsheet with no other comparison of truth before submission.

We're on course for DAOs to rediscover the basic principles of our existing financial system within the decade.

Re: PeopleDAO “exploited” by Google Docs edit

#6
post #2

Is clicking on a link really “hacking”? > The accounting lead mistakenly shared a link with edit access in a public channel in discord. The hacker gained edit role via the link.

> After gaining the access, the hacker inserted a 76 ETH payment to himself in the sheet, and set it invisible It might not be a real hack in the traditional sense, but hiding critical information so a human makes an incorrect choice is good enough to be considered social engineering for me.

[dead]

Re: PeopleDAO “exploited” by Google Docs edit

#8
post #2

Is clicking on a link really “hacking”? > The accounting lead mistakenly shared a link with edit access in a public channel in discord. The hacker gained edit role via the link.

One way or another, the bad guys are getting their money. Talk to anyone and they'll tell you this is hacking. Many incidents that are more technical and involves exploiting vulnerability also begin with social engineering.

Re: PeopleDAO “exploited” by Google Docs edit

#9
post #2

Is clicking on a link really “hacking”? > The accounting lead mistakenly shared a link with edit access in a public channel in discord. The hacker gained edit role via the link.

Imagine the number of people who have ownership of business-critical documents in the cloud. Now imagine a venn diagram with the number of people who don't realize that granting any permission at all to "Anyone who has this link" is, in the end, security through obscurity.
Post reply on HN