A fake job offer took down Axie Infinity
theblock.co
theblock.co
1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this.
2. I wish there were more information about what the vulnerability was in the PDF in the first place. I think a lot of people would be wary of downloading a PDF from a stranger, but not from someone who you had multiple interview rounds with and who offered you a job.
Personally, I'm probably not interested in a LI clone for many of the reasons I stopped using LI. I deleted my LI account maybe 8 years ago, after getting too much spam (and I think some security issue?)
How many of you have gotten jobs with no LI account? YEO?
As a startup founder, it’s effective in some contexts, like as a contact point or promotional tool. We never felt the need to use it for recruiting. At least in the software industry, GitHub is a much more effective marketplace of talent. But LinkedIn can have some benefits for a startup outside of recruiting. Posting content about your product is a good way to stay in front of investors you’ve connected with who doomscroll their LinkedIn feed like a dev does HN. :) (it’s also something I need to automate because I block LinkedIn on /etc/hosts for productivity purposes..)
I’m not sure I’ve ever _sourced_ an opportunity from LinkedIn. I also never accept connections without at least one prior interaction. For me it’s a tool for following up and keeping in touch, not introductions. It might also be useful in some rare sales contexts, for some specific archetype of audience especially susceptible to the psychological tactics commonly deployed to the LinkedIn newsfeed. Developers are definitely not that audience (well, not on LinkedIn at least…)
Just something to keep in mind. This post will have a lot of negative LI reviews simply because it was used as a sort of attack vector.
My decision was cemented in 2020 when someone who didn't like a tweet of mine retweeted it to my old company's twitter account trying to get me fired/reprimanded (The tweet in question called out my local PD for a dubious tweet they made, the person who tried to get me in trouble lived in a different state 12+ hours away). Thankfully my current company wouldn't have cared but there is no need to give people ammo.
Perhaps semi-off topic, but note there are companies that sell software (spyware?) to HR departments that specifically trolls LinkedIn looking for when employees update their LinkedIn profiles as a sign they're looking for a new job. This may or may not be a good thing depending on your position, perspective, or company, but just be aware it exists.
I don't think it is at all. Indeed, if you're updating it regularly (every 3-4 months, perhaps?) with new project/task stuff, it's simply keeping things fresh in your mind, vs having to try to trawl back 3 years to think about project FOO.
If you only update it once every 2 years, then people can draw more nefarious conclusions.
I wonder if there are any courses for managers to train them to think logically about this and not switch into bad decisions based on emotion.
Companies waste so much money on hiring and then deciding to react very slowly to changes in market conditions. If businesses treated their staff like they treat their clients...
This is not how companies work (at least the ones worth working for). Retention risk is a reflection on their current role, compensation, manager, etc.
We have absolutely promoted high performing employees and/or given them raises even though we knew they were looking at other opportunities.
You'll be placed in a list with a score next to your name.
> Though I also try not to work for companies that I would need to worry about that.
How do you figure out what kind of software your company uses internally?
I work for smaller companies that are more concerned with building instead of turning their workforce into scores on a list.
Once in a while I check the feed for kicks and it's always 100% spam, cliches, humble brags, and not-so-humble brags.
It introduces the idea of "transitive trust" where person A might not know person B but if the two have a bunch of contacts in common, the odds of A trusting B goes up. When there's a profile with tens or hundreds of shared connections, it looks real by all accounts.
I wrote about this is an intel gathering/attack vector way back in the day but it's 100x better now because connecting is second nature and people trust more now: https://caseysoftware.com/blog/open-source-intelligence-link...
I am listed as the Principal on a couple of companies, and get constant approaches that are obviously fake (like an attractive young "stewardess" from Dubai, who just happened to like my picture (which is actually my logo)).
I've given up reporting them, as LI always responds with "This is not in violation..."
Also, people use LI as a way to aggregate information, then send emails that appear to be from LI, but are not. I got one of those, yesterday, and reported it to LI, saying "These guys obviously used your service to construct this honker."
And LI's reply was ... envelope, please ... "Not our problem. Go away, kid. Yer bodderin' me." but stated a bit more politely.
I deliberately stay fairly open. I mentioned that, some time ago. It comes with some problems, like a determined bad actor can build up a fairly good profile.
But I have had years of experience, rubbing elbows with professional con artists, so I am maybe a little tougher to fool than many (but some approaches have come close -these folks are good). I would never be so arrogant to say that I can't be phished or whaled, but it's almost certainly not worth the effort.
I'm happy to chat -a bit- about it, directly. Many of the stories that I know, are not mine, to tell.
In the "Web2 Sector", it would be very easy IMO to snuff out a fictitious company. I've gotten a handful of "offers" in the past and you can see straight through them, because the company doesn't exist in real life and you can't find any info on it, huge red flag.
The problem with the "Web3 Sector" IMO is you have a bunch of upcomming players in the space that no one has heard of. Just like investors in Cryto, if you're a developer in the space, no doubt you are jockeying to join a project that might land you a 7-10 figure windfall at the end.
So if an unheard of company approached me, I would tell them to kick rocks. If a similar company approached someone in the "Web3 Sector", they might take it thinking it's an emerging opportunity. I'm sure this still happens with Startups but my gut says it's really bad in the Web3 space.
So you may not find much about the founder or team beyond their public handles.
If you use your own device then do company work in a VM.
This is something I see/hear so often, people using work equipment/network to conduct their personal stuff. This, IMO, should not be allowed at all.
Agreed, I thought that opening a read-only PDF was GRAS regardless of the application.
That "PDF VM" has had many 0-day RCE bugs over the years. Thankfully though the VM is standardized with the format it does have multiple implementations still in different applications and many exploits are application-specific implementation bugs.
I suppose they could add a phishing warning for messages sent on LinkedIn, but really it's an education problem, teaching people to identify what phishing emails look like and how to avoid them. This is a problem I've been working on since at least 2003, when we realized that the best way to prevent eBay account takeovers was teaching people what phishing is. We also identified that education is the hardest solution to achieve.
It's ironic that the security professionals are the ones hiding their identity, given that they are the best prepared to identify and avoid phishing emails.
If the issue reduces user metrics, then they will want to fix it. Ultimate responsibility seems irrelevant.
> It's ironic that the security professionals are the ones hiding their identity, given that they are the best prepared to identify and avoid phishing emails.
I might have demolitions training, but I’d still rather walk around the minefield.
this was the attitude Microsoft had about malware on Windows for a long time and it led to so much misery and ruin across the world.
If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.
What does _phi_ stand for?
pii = personally identifiable information
Unless this was a zero day, but I would have assumed the article would mention that fact ..
"Hey, you need a PDF viewer with scripts enabled for the digital signing.. can you install Adobe XXX?" would be a good line to get the mark to use a less-than-secure PDF viewer.
But also, since it was the North Korea hacking group, I'm not ruling out a 0-day... hopefully more details will come at some point.
do you at least dual boot?
have a separate user account?
I guess its fine as long as your computer doesn't have the credentials to the company slush fund.
Friend of mine I traveled with carried 3 macbooks with her: school issued, work issued, and personal. They had different software licenses tied to the machine, whadyagonnado?
When I was on the road all the time I also had separate phones to ensure I never got stuck with a dead phone.
Counterpoint: I've been completely and utterly allergic to opening anything personal from any company system for longer than that.
I get MDM profile updates from IT on my work machine. One time they auto-installed a cloud backup service and sent out a company-wide email after they already did it. Something like: “Now nobody has to deal with lost data. You’re welcome!”
Huge backlash from employees on that move. But I get both perspectives. These are work machines, and a mundane accident with the equipment shouldn’t incur significant losses to the business.
But apart from the potential loss of personal privacy, it feels wrong. Especially so, when you’re looking for other jobs.
I know they monitor some things because they are upfront about it: Chrome says it's company managed, and there is an antivirus and some VPN software that must be always one.
But why do I care? They don't crack down on us, and know everyone plays games or visits non-work-related sites, watches YouTube, or even do homework on these laptops.
I'm not going to work for the competition using the company's laptop, so why worry?
Is PDF as an attack vector such a widespread threat? I never payed much attention to them, assuming it's a document format that is relatively harmless even if it can include javascript.
This is an honest question, by the way.
PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages.
The (in)security of unsafe parsers reading user-generated input is a tale as old as time itself.
While browsers are sure not without security vulnerabilities, I sure trust the PDF viewer within to be way more sandboxed than most standalone desktop PDF viewer applications.
If the vulnerability (which I assume was RCE) was in a web browser, then it's a major bug.
Yes, I understand this, keep in mind I'm a software engineer.
Let me re-phrase. It's understood that, in general, document formats are more or less harmless unless they execute macros/code, and even then, this code must be able to exploit the platform's vulnerabilities to be able to do harm.
What is different about PDF than, say, JPEGs? I don't know of anyone who would hesitate to open an image file on their work computer, yet they are also complex formats requiring readers (viewers) which are often written in unsafe low-level languages. Yet I have never ever head of someone recommending "be careful before opening a JPEG (or PNG, or whatever) file".
I'm assuming we are not talking about ye olde "PDF.exe" or "JPEG.exe" trick here, but actual vulnerabilities in document files (not just renamed executables).
Both JPEG (or any other ubiquitous image format) and PDFs are nontrivial formats. And both have their fair share of CVEs (the list of JPEG vulnerabilities is also pretty long, based on that CVE database).
Something that sticks out to me is that JPEG (and most other image formats) is basically a header followed by a large blob of compressed image data, whereas PDF is a mixed-media format combining images and other multimedia, fonts, and a PostScript. And of course, we know that PDFs have all sorts of other crazy fancy features like forms and embedded JavaScript and digital signatures. Based on these facts alone, PDF features is a superset of image formats, and certainly by quite a wide margin. And more features means much bigger attack surface.
There's also another practical consideration of how users generally interact with these formats. Users interact with images primarily through browsers (or Electron-based software), which are sandboxed and have very well-funded security teams behind them. User-uploaded images to image hosts are often re-encoded (and sanitized as a side effect). Notable exceptions I can think of are loading images from a camera (generally a trusted source; and certainly there must be plenty of vulnerabilities in RAW parsers, but people almost never share RAWs) and iMessage (...which is a thing). It's very unusual for a user to be forced the view the image outside of a browser.
PDFs are a different situation: while browsers have well-sandboxed PDF viewers these days, they intentionally implement a subset of PDF features (I think forms is a big one left out, and signatures). You can imagine how easy it is to convince a user that need to download the PDF to disk and open it with Adobe Reader so that they can digitally sign a job offer. I'm aware that DocuSign exists, but I don't think it's ubiquitous enough that every user will wonder "hmm why am I being asked to sign with Adobe Reader instead of using DocuSign".
I hope that better answers your question.
Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.
Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
not to say it can't be done, but it was unexplained
Of course if you can access the software running the blockchain and get everyone to install an update, that works too
Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised... The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.
The system does not require people to sign off, but for the keys to sign off.
I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them
But don’t I own my house keys too?
It should be paying your mortgage, by the way.
- Not your keys, not your coins; always self-custody
- Never use the same machine for trading and for work/surfing the web
- Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.
Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.
I could never tell how much was incompetence vs fraud, but either way without the hype vastly fewer suckers would be holding the bag right now. The crypto ecosystem has been just been terrible for just about everyone and things are far from over.
Bitcoin was $6,000 in March 2020. It hit $63,000 in April 2021. And if you didn't sell that top, it hit $67,000 again in November 2021.
Even now, it has dropped less than Netflix, a supposed bluechip.
I don't know what's the scam in this - you had plenty of entry opportunities and plenty of exit opportunities. The underlying system itself still works exactly as described.
It’s not that Bitcoin or any alt coin has X paper value right now, it’s nobody can get out without someone else getting stuck holding the bag. The underlying system is predatory because mining isn’t free so it’s a negative sum game where people have already cashed out.
I remember being saddened when it was less than 1/1,000th isn’t current value I realized how many suckers where lining up for the fleecing. I briefly thought the odds are very good it’s going sky high, but I didn’t want to be part of someone losing their retirement when things eventually fell apart.
i haven't bought any myself. i just enjoy reading tech and economics stories in general so i've been reading about cryptocurrencies since 2013 or so. but i don't intend to buy any unless one fulfills some need i have better than other solutions. and i certainly don't intend to hold onto any if i can help it.
Look morality is only meaningful when it comes at a cost. I sincerely hope you are discouraged from scamming, robbing, kidnapping etc because you think it’s wrong rather than insufficient gain to be worth the effort.
That's true for practically every asset class. If you sold your Netflix stock at $600, someone had to buy it at $600 as well. And now they're out of $430.
There's a losing counterparty in every winning trade.
No, this is false. With stocks, the holder can get paid in dividends. With real estate, you gain value from actually using the land. A bond is actually a form of credit. Et cetera. Which other assets are you thinking of?
Edit: You must be conflating it with the funny money private stocks and their buybacks that a lot of startups have. Those are obviously a gamble, they're not really "investments" for most participants. It's no surprise that the same type of companies tried to go deep into ICOs a few years ago which are like the crypto equivalent of a bogus penny stock.
> There's a losing counterparty in every winning trade
the counterparties are equal in every trade; any winning takes place afterward in the future
and if one party is selling a publicly traded security or commodity at a loss, that doesn't mean it wasn't a good investment, it means it was bought at a fair price and conditions changed
Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme?
Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?
Can you tell me where the Ponzi is on this page: https://compound.finance/
Isn't that how fraudsters justify their tactics?
Crypto isn't big enough to do that on it's own.
It would make for an interesting black swan event. :)"Free market" in the Smithian sense is not what we have here.
You can't own keys, so you can't own coins. You instead have access to coins when you have access to keys.
Probably also reading email; one possible way of finding it needed to get at 5 of 9 keys to unlock.
The PDF format presents many opportunities for other exploits, either obfuscating a payload or running code, but modern PDF viewers are locking these opportunities down to such a degree that they are not very reliable (most of all because it is difficult to know which PDF viewer your target will use, and many popular PDF viewers today like pdf.js are relatively feature-incomplete which is a significant security advantage in this case). It's possible that something more sophisticated was going on but I would be very surprised if it was anything more complex than using the PDF as an obfuscated transport for a binary packed in it and invoked by the user (e.g. by clicking a link in the PDF with a javascript target). Non-user-interaction PDF vulnerabilities exist but are increasingly hard to come by as there has been more than a decade of work on locking down PDF viewers and the situation has improved dramatically in that time.
Contrary to what people sometimes expect, highly organized groups (such as APTs) tend to stick to very basic, simple methods as much as possible, since they are relatively reliable. The use of recent vulnerabilities in a specific PDF viewer, for example, is high risk due to the likelihood of failure and the opportunities for analysis it presents (you will have to do custom development rather than using off-the-shelf tooling). This is the kind of thing that organized groups try to avoid as much as possible, subject to an ROI analysis. Or in other words, if putting a link to an EXE in a PDF still works, why would you bother with anything else?
Assuming it can't, then the engineer had to click to run some unknown EXE after downloading it... that should hardly be described as a "PDF attack".
I recently stumbled upon a nice write-up [0] that described this class of attack and surveyed which software was vulnerable to it. Many crypto clients were included.
Basic flow was-phisher asked employee to sign a document relating to customs. The phisher had gathered that this employee works with shipping claims and returns, and surmised that they need to deal with customs documents requiring signature. There was a link to an exe hosted on a European cloud service in the PDF titled "install fake signature certificate company to sign this document". This directed to a download of a basic ransomware executable. This did get past our AV to the point of encrypting the employee's machine, but thankfully was blocked from spreading to the rest of the network.
The employee's machine was toast, but I was able to restore from the prior day's backup and no major harm occurred. I was able to see the phishing attack since we use gsuite email so the ransom ware didn't erase the employee's inbox, but they did lose a half-day work and I updated our training. The attack itself was clever from a social engineering perspective, but the technical exploit was something any script kiddy could have downloaded from the open web, nothing advanced at all. But Gmail doesn't always scan links in PDFs, so a clever ruse was able to bypass Google's scanning as well as our local scanning.
What I don't understand: Why do you let your users run downloaded executables, at all?
And due to a legacy system, we can't rely on windows UAC to prevent these attacks either, this user needed to have a local admin account. Yes, this is a security issue in itself, but needs must.
When I was at lockheed we had an incident whereby a bunch of folks had attended some defense conference, and after the fact received emails from folks they had 'met' at the conference, something along the lines of
"Hey Bob, we met at the [defense] conference this last week and I wanted to be sure you had my contact info: malware-contact.vcf"
or some other payload.
This installed a very slow sprawling worm which would slowly trickle data out of lockheed to China.
It was not discovered for quite a while due to how slowly it operated, but someone had complained about machine performance and IT looked at the machine and discovered the worm... after removing it - this somehow sent a signal to China that they had been found and all the worms started to firehose as much as they could until egress was closed. At the time, all of Lockheeds 150,000 employees had just three egress points to the internet. They had to shut them all down to kill that worm.
If pdf is compromised, is it fixed? This seems like the kind of vulnerability that would ruin pdf's reputation permanently. It was the safe alternative to sending someone a .doc particularly because of it's limited functionality.
It is used for sending documents because its function is to have a fixed layout for printing (and look the same on every device), not because it's safer than other document formats.
If you really want a safe PDF, there's a function in Qubes OS that basically opens a PDF in a new VM, makes screenshots and then creates a new PDF from those. You'll lose advanced functions (e.g. forms) as the pages simply become pictures but that's a tradeoff you have to make.
on the other hand I bet you could collect some interesting things by creating a few fake people as linkedin honeypots at FAANGs, and I would be very surprised in their infosec/netsec teams aren't already doing this.
or getting real people who opt-in to have their linkedin profile receive incoming scams, virus, trojans, phish links and pipeline them into the infosec/netsec team.
They seemed to avoid contacting executives or senior staff… but instead targeted folks capable of maybe making the change they wanted, and maybe jr / low enough on the pole enough to panic and do it.
I’ve seen it happen three times now, pretty scummy IMO.
People on LinkedIn, using a name sufficiently far enough away from their real name so as to not be able to be easily found, listing their security jobs with again, sufficiently far enough away org names.
Turtles all the way down.
> Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed.
It's not in William Gibson's style, sounds more like Bruce Sterling's.
> Axie Infinity was huge. At its peak, workers in Southeast Asia were even able to earn a living through the play-to-earn game. It boasted 2.7 million daily active users and $214 million in weekly trading volume for its in-game NFTs in November last year — although both numbers have since plummeted.
> Earlier this year, staff at Axie Infinity developer Sky Mavis were approached by people purporting to represent the fake company and encouraged to apply for jobs, according to the people familiar with the matter. One source added that the approaches were made through the professional networking site LinkedIn.
Also gives me Charles Stross vibes.
You definitely haven't been paying attention to Gen-Z people then. The 80s are back.
And pretty impractical as well. They look really poorly designed in terms of maximizing leverage. It also looks like they lose a lot of energy in the flexing of the entire mechanism and their arm, compared to a blade held directly in the hand.
http://www.openthefuture.com/wcarchive/2004/10/stephenson_an...
They opened the PDF and that installed a keylogger on their system (it doesn't explain how).
The attackers then used that engineer's credentials to take over 4 of the 9 validators on the blockchain which they then used for their heist.
Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian Key into 9 pieces and divided them across the realm, each protected by a powerful, mystic dungeon. Also, Dave can access them any time he says the secret word."
Rather than think of their primary business as securing digital assets, think of their primary business as convincing people that a perpetual money machine in the shape of a video game is possible. The valuable digital assets are just a narrative tool — and so it follows that they wouldn’t have the expertise in securing digital assets.
Nobody capable of building a secure system for digital assets would waste their time working for a company like Axie, after all, the entire premise of their business is flawed so people with the critical thinking skills necessary to build a secure system would apply that critical thinking to the viability of the company — and, of course, conclude it’s destined for failure and not hitch their wagon to it.
“It's difficult to get a man to understand something when his salary depends on not understanding it." -Upton Sinclair
I’m under no illusions about the intelligence of software engineers (of any specialism) — we are all idiots at least some of the time — but I struggle to believe that a competent engineer with lots of opportunities would somehow believe that Axie Infinity is the best opportunity available to them, hence, their system is built by people who don’t have other opportunities and have produced an insecure house of cards (more insecure than the average system anyway — all systems are insecure in some capacity).
I had a recruiter contact me just recently for some crypto game that was offering something like $600k/year (which I unfortunately assume was at least partly stock) for one of them, and that would certainly have been enough to attract real security talent.
That doesn’t excuse their poor security practices. They shouldn’t have built their asset custody system in-house if they didn’t have the expertise. They could have used Fireblocks or a Gnosis Safe Multisig with hardware wallets and they would be safe.
Someone with low ethics interested in a very good paycheck?
And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.
The company fully blames the employee. I wish software companies had the same level of professionalism than airlines. "It's the pilot's fault" does not help to improve security. Nothing is learned.
I won't argue this, but I think that it depends on where you look. Cryptography audit services are books out for months or years because of the demand from cryptocurrency projects. There's never been a vulnerability in the Bitcoin or Ethereum networks that allowed an attacker to steal funds or execute a double-spend. And cryptocurrency projects have pioneered whole fields of cryptography like zksnarks for security purposes.
Cryptocurrency projects often have a fundamentally very difficult problem to solve, and attackers are also very sophisticated. There are currently very few people with the expertise needed to implement a complex cryptocurrency project securely.
Disclaimer: I'm a protocol developer for a cryptocurrency project (not one of the ones mentioned here)
And that's why I don't believe the story. No owner of such business would make this possible.
This paragraph perfectly encapsulates everything wrong with the way promoters sell Ethereum. Smart contracts can do little of interest beyond straight monetary transactions without information about the outside world. That information comes from "oracles", or what the article calls "validators".
The security guarantees of this system are far, far weaker than the Ethereum consensus protocol, as the article demonstrates. And yet, the system is hyped to the n-th degree by sheisters who ignore this basic fact with ludicrous claims about security and stability.
Zooming out, basically Ethereum is hyped as a platform for "smart contracts." But the minute a smart contract does anything beyond basic money transfers, it needs an oracle. And with the oracle comes radically reduced security.
Eventually, this will be obvious. For now, shenanigans like this will continue.
Most Ethereum developers are advising against relying on bridges across security zones that would be upheld by multisigs and oracles, they are vulnerable to attacks. A better model than a bridge to sidechain would be a rollup - posting proofs on chain without giving the sequencer the ability to steal or control user funds.
What's a "proof" of an event in the outside world? No such thing exists.
The OP's point that dependence on real world events is a security flaw remains. No alternative programming method can change this because nothing on the Internet can guarantee a real event has happened. This is inherent.
One of the long term goals of blockchains interfacing with the "real world" is to build oracle marketplaces that compete to provide "proof of true events". You can essentially build a reputation by selling valid data. The same way different news outlets and journalists compete for providing the "proof" for events.
Moreover, the legal system isn't intended as merely a means to determine whether a contract is fulfilled. It's also intended as a institution for preventing "cheating" and it has a concept of cheating. IE, me just satisfying a proxy for my end of a contact while not fulfilling the actual intent will not result in a judgement that the contract isn't fulfilled but also penalties of various severity if I intended to defraud a customer. If I build a bridge out of cardboard and, say, show pictures as proof of my supposed actions, I may well go to prisoner for fraud rather than prospering, even if it takes a while.
Smart contracts, in contrast, inherent can't distinguish between a proxy-value and a real situation - and their inability to do so is seen by their naive proponents as being their appeal. Equivalently, they have no concept of cheating. Thing considered "Hacks" and "fraud" have been prevent in etherium sure but by the opaque actions of governing boards, much less transparently than the ordinary courts.
And you can't make the problem go away with a reputation system since if the benefit lying gets higher than the cost of losing reputation anyone may lie with no other repercussions. And reputation always leaves the possibility of hacks to systems open - as the article shows.
I still remember in 2017 shills on arkcoin slack trying to sell agricultural insurance that paid based on weather. They kept selling how decentralized it was but at the end of the day they just admitted that a central authority would input that data and we were back at square 0.
Validators and Oracles are two different things entirely. That factual error aside, this is like saying that the US Federal Reserve is a weak system because Lehman Brothers and the MBS market failed.
Regardless, The Oracle Problem is already incredibly obvious and well-documented[0][1][2][3].
[0] - https://blog.chain.link/what-is-the-blockchain-oracle-proble...
[1] - https://encyclopedia.pub/entry/2959
[2] - https://cointelegraph.com/magazine/2021/12/30/can-blockchain...
I'm not sure about this attack specifically, though, and in Ronin's post mortem they aren't really talking about that: https://roninblockchain.substack.com/p/back-to-building-roni....
To some extent, the PDF viewer/OS doesn't matter. A dedicated and well resourced attacker like the Lazarus Group will find holes in all of them. The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
What usually happens is that layers 1 and 2 of 3 are constantly compromised, no one cares to follow up, and one day layer 3 gets compromised, shock of shocks.
I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
Figure out a company uses <some-saas> register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details.
If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?
This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
This might just result in employees finding ways to remote access their work computer from their personal computer from wherever they are, but at least that's an additional wall for would-be attackers to hurdle.
I don't install anything personal on my work computer, but I wouldn't hesitate to open an email or pdf from a seemingly trusted source. I don't really blame the dev here.
What you propose is a reasonable solution, but I feel like it slams in the face of actual human behavior. Most people act the way I describe, even most tech professionals.
I think the clear move here should be to avoid pdf, just like the move is to avoid doc
I dispute this: the web browser is one of the most defended pieces of software of all time, especially relative to its complexity. I would find it much safer to open a potentially malicious PDF in my browser's JS-based reader than using a desktop reader.
> The "right" move here would have been for the employee not to download the compromised pdf, and short of that, for the IT Security team at Ronin to quickly detect the weird traffic that resulted and isolate the validators to prevent a compromise of their critical assets.
It also probably would have been helpful if one employee didn't have access to almost half of the validators, especially on a system they're accessing email with.
But you never know.
[0] https://helpx.adobe.com/reader/using/protected-mode-windows....
It says it was an offer letter, so my guess is that opening it in the browser came up with an error like "to be able to digitally sign this offer letter, please open it in a desktop PDF reader with full scripting support enabled :)"
What's the point of using a Blockchain if you end up centralizing validations like that?
https://home.treasury.gov/policy-issues/financial-sanctions/...
And it has already been moved:
https://www.blockchain.com/eth/address/0x098B716B8Aaf2151299...
Some PM in 2006 thought it would be a good idea if PDFs were turing complete. I'm sure the word sandbox wasn't even thought about. 10 years later PDF (and more notably, Flash) became huge attack vectors.
I think a far more interesting hack is when NSO used a PDF to embed a virtual machine inside an iPhone to develop a zero click exploit over iMessage:
https://hothardware.com/news/zero-click-malware-pwns-iphone-...
Now whatever cursed embedded software on the printer reads the PDF is probably a lot easier to exploit than an updated PDF viewer, but that's not what these people are going for.
The going price for Adobe PDF RCE zero-days is $80,000
Desktop PDF viewers like acrobat are gaping security holes... Don't use them!
Most malware these days can't function without internet connectivity. The exploits typically connect to a server to get the rest of their code because they don't want any pesky researchers getting their hands on stuff.
People are conditioned to trust certain verticals, Google, Apple, Microsoft (which owns LinkedIn) and a bunch of others and will lower their guard. Which is why it works so well. In fact I've received email from some of those where I was pretty sure I was being spearphished but they turned out to be real (but not on LinkedIn, which I refuse to join).
I'm beginning to contemplate what value LN provides as LN has focused on more aggressive marketing tactics, and it's starting to feel like Instagram with the engagements metrics...
Oh yea, I'm still perplexed on how anyone would ever go into an interview w/out doing any homework on the company...even the smallest of start-ups have a presence on the net. They better damn-well have a pitch deck for new capital and employees.
Are we sure this heist wasn’t an inside job? Axie was collapsing under its own weight and an employee decided to swipe all of the crypto after making up this crazy job offer PDF story to cover their tracks.
Edit: I thought the lack of details was fishy but the following would be tough to fake:
the FBI has attributed North Korea-based Lazarus Group, highly skilled hackers, to the Ronin Validator Security Breach. The US Government, specifically the Treasury Department, has sanctioned the address that received the stolen funds
bonus free VPN endpoint and exploit library to make it look like it was us!
Wow! These folks were really on the ball if it took that much social engineering just to get an employee to open a PDF.
I know a lot has been said about bullshit jobs, and that it is a controversial concept, but I cannot find any job more bullshitty than having to earn a living by playing an NFT Pokémon like game or whatnot.
It's depressing.
At least, I hope that any reasonable organization doesn't secure $600+ million dollars by relying on the endpoint security of a device used to access LinkedIn
Job offer PDF was downloaded to office computer. PDF had spyware that infiltrated the system.
[1] https://www.microsoft.com/en-us/insidetrack/protecting-high-...
The Adobe tools in particular have been a bountiful source of exploits for decades, but it's a complicated spec and there are plenty of opportunities for bugs.
I would say Firefox is the safest here, because its built-in PDF viewer is written in JS, although Firefox's sandboxing is not as strong as Chrome's.
So, our best effort is to constrain what certain data can do when we process it, in the hope that this prevents surprising negative consequences like a PDF that steals privileged information and sends it elsewhere.
Notice that, in some sense, a PDF which just contains a photograph of your wife tied to a chair and holding today's newspaper, plus human readable text like, "We have your wife Sarah and all three kids Beth, Jim and Amanda. We are watching. Do not try to call for help. Email the privileged information to crooks@example.com or we will kill your family" is also potentially effective at doing this, but we would not usually consider that an exploit in this context.
One irritation in this space is that programmers love General Purpose Programming Languages. The idea of the general purpose language is that it can do anything. But the problem in this sort of situation is that we don't want programs which can do anything, in fact doing anything is our worst case scenario. We actually want Special Purpose Programming Languages. We want to write our PDF data processing software in a language that even if we were trying can't do the things that should never happen as a result of processing a PDF.
This is the purpose of languages like WUFFS: https://github.com/google/wuffs
You can't write a WUFFS program to, for example, email anything to crooks@example.com even if you desperately needed to, which means you definitely won't accidentally write a program which can email the privileged information to the crooks when fed a PDF. Of course the PDF mentioned earlier with the kidnap note inside it could still work. And also of course making a PDF renderer out of WUFFS would be a really big ask. WUFFS-the-library today can render PNG, GIF, BMP but notably not yet JPEG. But it's clearly possible for something like PDF rendering to happen under these constraints. Nobody ordinarily viewing a PDF wants it to do arbitrary stuff.
FiM++ - Esolang
Page 414 and forwards. And if you're generally interested in PDF feature bloat, go to page 511 to find out how to embed 3D art, including the manipulation of the virtual camera, in your PDF document.
What could go wrong?
https://blog.google/threat-analysis-group/new-campaign-targe...
Just another reason crypto is a godsend for bad guys (obviously other financial crimes occur, e.g. with convincing folks to send fake wires) but there aren't many better ways to steal half a billion dollars I think. But, yeah yeah, "HN is so mean and hates crypto!!!"
Seesh, you could finance a war with $2B.
In other words, can I run `pdf-make-safe` on a file before opening it to make sure it can't execute arbitrary code the moment I do?
I found this:
https://github.com/freedomofpress/dangerzone
Is it any good?
It seems like the entire legal profession, for instance, should be crippled by this vulnerability disclosure, if true.
So we basically have a worse banking system even if you believe crypto is a currency (it's not)
With so much money at stake I am surprised there was not more isolation.
Or a second authentication factor?
...Oh wait, this is crypto
From time to time there are real startups that decide to fly under the radar until they're ready to show the world what they've built. Of course, many such companies turn out to be massive duds... Like Cuil.
That said, for lower income people you'll be absolutely inundated with scams, a good friend of mine just hit me up cuz someone wanted to promise him for $100 or so a week, you'd somehow become a crypto millionaire. I actually think crypto in its entirety is a giant scam, there's just levels of sophistication to it.
Not everyone's going to fall for give me $100 and I'll turn that into $10,000 , but a ton of people fell for buy a bunch of crypto coins and hold ,time the market and sell.