Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

361–364 of 364 posts

Re: A fake job offer took down Axie Infinity

#361

Earlier quoted context omitted.

Why do pdfs even allow executing code outside of the pdf env ie why isn't there a sandbox/apis that allow very limited operation?

>Why do pdfs even allow executing code outside of the pdf env Some PM in 2006 thought it would be a good idea if PDFs were turing complete. I'm sure the word sandbox wasn't even thought about. 10 years later PDF (and more notably, Flash) became huge attack vectors. I think a far more interesting hack is when NSO used a PDF to embed a virtual machine inside an iPhone to develop a zero click exploit over iMessage: http…

What's the solution? Open pdfs on a VM, and never on your phone?

Re: A fake job offer took down Axie Infinity

#362
post #350
post #337

Earlier quoted context omitted.

> That doesn’t absolve the con artist for running one though Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme? Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?

In the case of a literal Ponzi scheme it is pretty obvious who to prosecute. In the blockchain space many players have figured out ways to avoid being prosecuted for their schemes (many of which are little more than outright scams), but that doesn’t make what they’re doing ethical

You missed my point, they're building a decentralised smart contract system, there's nothing in the Ethereum smart contract code that says you must build a ponzi.

Can you tell me where the Ponzi is on this page: https://compound.finance/

Re: A fake job offer took down Axie Infinity

#363

Earlier quoted context omitted.

Yep, internal security is brittle. The initial pdf vector would be only the start of a long sequence of hacks, including social engineering. e.g. sending email from managers -- or slack messages as you mention.

How do you defend against getting email from internal people, especially from people you expect email from?

You can call your colleague on the phone to confirm they sent the email asking you to open an attachment.

Re: A fake job offer took down Axie Infinity

#364

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

The easy fix for (2) is to only view the PDF in the cloud (e.g., Google Docs).
Post reply on HN