If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.
If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.
Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.
Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
not to say it can't be done, but it was unexplained
Of course if you can access the software running the blockchain and get everyone to install an update, that works too
Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised... The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.
The system does not require people to sign off, but for the keys to sign off.
I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them
But don’t I own my house keys too?
It should be paying your mortgage, by the way.
- Not your keys, not your coins; always self-custody
- Never use the same machine for trading and for work/surfing the web
- Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.
Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.
I could never tell how much was incompetence vs fraud, but either way without the hype vastly fewer suckers would be holding the bag right now. The crypto ecosystem has been just been terrible for just about everyone and things are far from over.
Bitcoin was $6,000 in March 2020. It hit $63,000 in April 2021. And if you didn't sell that top, it hit $67,000 again in November 2021.
Even now, it has dropped less than Netflix, a supposed bluechip.
I don't know what's the scam in this - you had plenty of entry opportunities and plenty of exit opportunities. The underlying system itself still works exactly as described.
It’s not that Bitcoin or any alt coin has X paper value right now, it’s nobody can get out without someone else getting stuck holding the bag. The underlying system is predatory because mining isn’t free so it’s a negative sum game where people have already cashed out.
I remember being saddened when it was less than 1/1,000th isn’t current value I realized how many suckers where lining up for the fleecing. I briefly thought the odds are very good it’s going sky high, but I didn’t want to be part of someone losing their retirement when things eventually fell apart.
That's true for practically every asset class. If you sold your Netflix stock at $600, someone had to buy it at $600 as well. And now they're out of $430.
There's a losing counterparty in every winning trade.
No, this is false. With stocks, the holder can get paid in dividends. With real estate, you gain value from actually using the land. A bond is actually a form of credit. Et cetera. Which other assets are you thinking of?
Edit: You must be conflating it with the funny money private stocks and their buybacks that a lot of startups have. Those are obviously a gamble, they're not really "investments" for most participants. It's no surprise that the same type of companies tried to go deep into ICOs a few years ago which are like the crypto equivalent of a bogus penny stock.
> There's a losing counterparty in every winning trade
the counterparties are equal in every trade; any winning takes place afterward in the future
and if one party is selling a publicly traded security or commodity at a loss, that doesn't mean it wasn't a good investment, it means it was bought at a fair price and conditions changed
Look morality is only meaningful when it comes at a cost. I sincerely hope you are discouraged from scamming, robbing, kidnapping etc because you think it’s wrong rather than insufficient gain to be worth the effort.
i haven't bought any myself. i just enjoy reading tech and economics stories in general so i've been reading about cryptocurrencies since 2013 or so. but i don't intend to buy any unless one fulfills some need i have better than other solutions. and i certainly don't intend to hold onto any if i can help it.
Who are you going to prosecute in this case? The developers of Ethereum who are making a digital peer2peer smart contract system and have no interest in running a ponzi scheme?
Are you going to arrest Bram Cohen for inventing Bittorrent for what happens on it? What about the people behind Tor?
Can you tell me where the Ponzi is on this page: https://compound.finance/
Isn't that how fraudsters justify their tactics?
Crypto isn't big enough to do that on it's own.
It would make for an interesting black swan event. :)"Free market" in the Smithian sense is not what we have here.
You can't own keys, so you can't own coins. You instead have access to coins when you have access to keys.
Is PDF as an attack vector such a widespread threat? I never payed much attention to them, assuming it's a document format that is relatively harmless even if it can include javascript.
This is an honest question, by the way.
PDFs are "harmless" on their own, but they are user-generated documents that conform to a complex specification. Viewing them requires software that parses them. These parsers are often written in unsafe low level languages.
The (in)security of unsafe parsers reading user-generated input is a tale as old as time itself.
While browsers are sure not without security vulnerabilities, I sure trust the PDF viewer within to be way more sandboxed than most standalone desktop PDF viewer applications.
If the vulnerability (which I assume was RCE) was in a web browser, then it's a major bug.
Yes, I understand this, keep in mind I'm a software engineer.
Let me re-phrase. It's understood that, in general, document formats are more or less harmless unless they execute macros/code, and even then, this code must be able to exploit the platform's vulnerabilities to be able to do harm.
What is different about PDF than, say, JPEGs? I don't know of anyone who would hesitate to open an image file on their work computer, yet they are also complex formats requiring readers (viewers) which are often written in unsafe low-level languages. Yet I have never ever head of someone recommending "be careful before opening a JPEG (or PNG, or whatever) file".
I'm assuming we are not talking about ye olde "PDF.exe" or "JPEG.exe" trick here, but actual vulnerabilities in document files (not just renamed executables).
Both JPEG (or any other ubiquitous image format) and PDFs are nontrivial formats. And both have their fair share of CVEs (the list of JPEG vulnerabilities is also pretty long, based on that CVE database).
Something that sticks out to me is that JPEG (and most other image formats) is basically a header followed by a large blob of compressed image data, whereas PDF is a mixed-media format combining images and other multimedia, fonts, and a PostScript. And of course, we know that PDFs have all sorts of other crazy fancy features like forms and embedded JavaScript and digital signatures. Based on these facts alone, PDF features is a superset of image formats, and certainly by quite a wide margin. And more features means much bigger attack surface.
There's also another practical consideration of how users generally interact with these formats. Users interact with images primarily through browsers (or Electron-based software), which are sandboxed and have very well-funded security teams behind them. User-uploaded images to image hosts are often re-encoded (and sanitized as a side effect). Notable exceptions I can think of are loading images from a camera (generally a trusted source; and certainly there must be plenty of vulnerabilities in RAW parsers, but people almost never share RAWs) and iMessage (...which is a thing). It's very unusual for a user to be forced the view the image outside of a browser.
PDFs are a different situation: while browsers have well-sandboxed PDF viewers these days, they intentionally implement a subset of PDF features (I think forms is a big one left out, and signatures). You can imagine how easy it is to convince a user that need to download the PDF to disk and open it with Adobe Reader so that they can digitally sign a job offer. I'm aware that DocuSign exists, but I don't think it's ubiquitous enough that every user will wonder "hmm why am I being asked to sign with Adobe Reader instead of using DocuSign".
I hope that better answers your question.
Unless this was a zero day, but I would have assumed the article would mention that fact ..
"Hey, you need a PDF viewer with scripts enabled for the digital signing.. can you install Adobe XXX?" would be a good line to get the mark to use a less-than-secure PDF viewer.
But also, since it was the North Korea hacking group, I'm not ruling out a 0-day... hopefully more details will come at some point.
Counterpoint: I've been completely and utterly allergic to opening anything personal from any company system for longer than that.
I get MDM profile updates from IT on my work machine. One time they auto-installed a cloud backup service and sent out a company-wide email after they already did it. Something like: “Now nobody has to deal with lost data. You’re welcome!”
Huge backlash from employees on that move. But I get both perspectives. These are work machines, and a mundane accident with the equipment shouldn’t incur significant losses to the business.
But apart from the potential loss of personal privacy, it feels wrong. Especially so, when you’re looking for other jobs.
When I was on the road all the time I also had separate phones to ensure I never got stuck with a dead phone.
do you at least dual boot?
have a separate user account?
I guess its fine as long as your computer doesn't have the credentials to the company slush fund.
Friend of mine I traveled with carried 3 macbooks with her: school issued, work issued, and personal. They had different software licenses tied to the machine, whadyagonnado?
I know they monitor some things because they are upfront about it: Chrome says it's company managed, and there is an antivirus and some VPN software that must be always one.
But why do I care? They don't crack down on us, and know everyone plays games or visits non-work-related sites, watches YouTube, or even do homework on these laptops.
I'm not going to work for the competition using the company's laptop, so why worry?
What does _phi_ stand for?
pii = personally identifiable information
Probably also reading email; one possible way of finding it needed to get at 5 of 9 keys to unlock.