| ▲ | Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware(theverge.com) |
| 44 points by rzk a day ago | 43 comments |
| |
|
| ▲ | drnick1 21 hours ago | parent | next [-] |
| This underscores a major issue with commercial software like Steam and games obtained therein. You cannot trust that software not to maliciously scan your device for secrets such as crypto wallets or other information. Ideally, you want to run apps like Steam, Discord, Zoom and whatever else does not come from a trusted distribution repo as a separate user. This is not always convenient however, and the compromise I adopted on my gaming PC is to bubblewrap Steam. Do not mount things like /home and devices games should not be using in the sandbox. |
| |
| ▲ | wps 17 hours ago | parent | next [-] | | Agreed. I’ve always disliked having anything to do with gaming on my primary OS, always choosing to compartmentalize that stuff away from anything sensitive. The only exception is DRM free standalone games like Factorio, which has pretty safe mods compared to something like Minecraft. | |
| ▲ | techjamie 21 hours ago | parent | prev | next [-] | | In theory you could change the steam command line fpr each game and have them launch in bubblewrap. Though I'm not sure how well that would play with graphics drivers. It might be friendly with AMD, but my experience is that NVIDIA is a pain to have play nice with containers. | | |
| ▲ | drnick1 21 hours ago | parent [-] | | I sandbox Steam itself for simplicity. My experience with Nvidia and Wayland has been good. I simply exposed /dev/nvidia*, a few networking-related files in /etc and system binaries like /usr. | | |
| |
| ▲ | kibwen 21 hours ago | parent | prev | next [-] | | This is what my Steam Deck is for. There's no gap like air gap. | | |
| ▲ | drnick1 21 hours ago | parent [-] | | Dedicated hardware is definitely the most secure option, but realistically it is even less convenient than a separate user. You can't realistically play graphically intensive games on a Deck, and separate workstations are very unaffordable at the moment. |
| |
| ▲ | akimbostrawman 13 hours ago | parent | prev | next [-] | | flatpak is the most convenient way to securely run steam on linux | |
| ▲ | charcircuit 21 hours ago | parent | prev [-] | | Android solves this problem by making it impossible for an app to access the storage of another app. No matter how much the Steam app wants to see your crypto wallet's key it is not possible (assuming no Linux exploit). | | |
| ▲ | drnick1 20 hours ago | parent [-] | | That's nice, but a cell phone isn't a viable gaming platform for anything but very basic games. And Android, at least in its typical Googled form, has its own set of problems; it's a privacy nightmare. | | |
| ▲ | charcircuit 17 hours ago | parent [-] | | And despite what you claim it is the most profitable gaming platform. There are lessons you can learn from them. | | |
| ▲ | xboxnolifes 16 hours ago | parent [-] | | Skinner boxes of MTX in peoples' pockets is a good business model. The lessons were learned, and gacha games are huge on PC. |
|
|
|
|
|
| ▲ | Cider9986 a day ago | parent | prev | next [-] |
| Criminals should have used Monero. Victims should have not keep crypto on desktops. They are much less secure than Mobile. |
| |
| ▲ | LoganDark 21 hours ago | parent | next [-] | | Modern macOS devices have a secure element just as good as iOS devices. Almost nobody makes use of it, though. (I haven't seen anything yet that uses the secure element to control access to a wallet. Are there any technical obstacles to keeping the keys out of main memory?) | |
| ▲ | fsflover a day ago | parent | prev [-] | | > Victims should have not keep crypto on desktops. They are much less secure than Mobile. Unless it's Qubes OS. | | |
|
|
| ▲ | LoganDark 21 hours ago | parent | prev | next [-] |
| I heard Monero can help against blockchain analysis (though less so if you buy from adversaries). Unfortunately it looks like blockchain analysis was not the attack vector here, but rather buying gift cards through an incompetent intermediary. |
| |
| ▲ | HDBaseT 21 hours ago | parent [-] | | Not really an "incompetent intermediary", Bitrefill, the company used for buying gift cards with Bitcoin received legal requests to identify the user. Bitrefill doesn't proclaim insane privacy protections, they are based out of Sweden but aren't immune to being requested to provide the information. Monero could of helped, although its not easy to transfer BTC to Monero without P2P trades, as effectively every exchange requires KYC. Those source and destination wallet addresses are tainted, you wouldn't be able to deposit on any mainstream exchange and if they do, its for a honey pot purpose. | | |
| ▲ | tancop 5 hours ago | parent | next [-] | | thats why btc/monero is not as great as a lot of people think. ethereum has stablecoins and dex swaps so you dont have to do p2p once you have any tokens in the ecosystem, all you need is some eth to pay gas fees. and its the only crypto project i trust completely. for privacy theres railgun and aztec, both have canonical bridges back to layer 1 and enough users to give you correlation resistance. tornado cash has compromised governance but i dont think the core contracts are broken so you can use that too, just be careful when you deal with americans because its illegal there. kinda ironic that bitcoin is designed to be as trustless as possible but you need to trust third parties with you money a lot of the time because the core protocol is too simple for its own good. | |
| ▲ | Cider9986 19 hours ago | parent | prev | next [-] | | >Monero could of helped, although its not easy to transfer BTC to Monero without P2P It's really not hard but it probably gets much harder to transfer tainted Bitcoin. Trocador.app aggregates various no-KYC CEX swaps and is regarded well in the Monero community. As we can see from the various Monero pumps, which often stemmed from cleaning coins. Thieves don't want to sit on the Bitcoin so they drive up the price of Monero selling it fast. Yeah P2P is more technical. Hopefully with Serai we can get a good UX decentralized exchange. Swapping into fiat is a different beast. | |
| ▲ | LoganDark 20 hours ago | parent | prev [-] | | Making it possible to identify a user is incompetence, exactly because of legal issues like this. You don't run a service that accepts crypto for gift cards and then keep information on file that identifies the buyer personally, that's just stupid. But then again, you don't illegally obtain crypto and then give out your info when you go to use the illegal funds, that's just stupid as well. Is P2P that big a deal? I swap coins on Bisq all the time. It's super easy to pick up and use if you already have the BTC. The biggest obstacle is obtaining some BTC in the first place when you don't have any yet. Once you have enough for the security deposit, you can buy/sell or swap thousands of dollars in funds at a time. |
|
|
|
| ▲ | zuzululu a day ago | parent | prev [-] |
| He was smart/determined enough to risk it all. Why didn't he just try find a job that pays $200k/year ? Why play into the stereotypes ? |
| |
| ▲ | tancop 5 hours ago | parent | next [-] | | job market is insane today. its hard to find a job in retail in some places, software is way more competitive. retraining to some in demand trade takes money you might not have and its still not guaranteed success. and even if you get hired for a stable job theres no guarantee your company will let you work your way up to 200k when they know you cant afford to quit. the uncertainty of crime is better than endless waiting for an offer that might never come. if you take 10 scammers or drug dealers one of them will get rich, 3 will go to prison and the rest have a relatively normal life. that might be genuinely better odds than a mainstream career for some. | | |
| ▲ | zuzululu 3 hours ago | parent [-] | | crime has short term certainty with long term uncertainty. a legitimate job has short term uncertainty with long term certainty. its stupid silly and dangerous way to view it as an escape from your current job situation. I don't know why people keep whining about job markets. I'm currently working 3 different remote jobs each past 200k/yr point my total salary is close to 800k. if one of them fires me i can easily hop to another job. I've been doing this for well over a year now and everybody is happy. there's really no need to justify criminal behavior when legitimate options are in front of you and you are too lazy, weak willed to see the upside. |
| |
| ▲ | robotnikman 21 hours ago | parent | prev | next [-] | | >Why didn't he just try find a job that pays $200k/year ? Probably was not able to get into MIT or another prestigious school that many of those companies look for on a resume. | | |
| ▲ | vorpalhex 21 hours ago | parent [-] | | None of my peers went to any school of note, nor did I. A fair bit of community college, some lower ranked state unis, and one guy did a bootcamp. All well above 200k. | | |
| ▲ | Obscurity4340 3 hours ago | parent | next [-] | | Is it worth enrolling in a local public college for programming? I think its a 2-3 year course but would it have good bridges to actually getting experience and emplpyed in software? Might have to do it part time but id still be into getting out of my current job which i cant see myself lasting long-term in. I need something with more latitude and definitely better pay, prospects. Im at a dead end and nughtmare i cant wake up from if i stand still any longer | |
| ▲ | darksim905 20 hours ago | parent | prev | next [-] | | What do they do, _exactly_? Because in the real world out of YC, the rest of us can barely top $200,000 a year unless we move into management or Executive level roles. | | |
| ▲ | vorpalhex 6 hours ago | parent [-] | | Software engineers. None of us work for YC, we are based in Texas. No oil/gas, nor defense, nothing like that. Years ago I had a recruiter that wanted to hawk me and I asked for 180k comp and he told me it was "impossible". Hung up, was hired at 185k a few weeks later. Wasn't even much of a negotiation when I asked for it. 1. Be willing to accept non-cash comp. Stock of various forms, etc. This works with later stage companies better for obvious reasons. 2. Go into all negotiations ready to explain to the other side what they are buying. Remain calm if not slightly bored. Repeat your ask as if the other side has forgotten them (that sort of bored, calm tone). Do not argue. 3. Actually deliver business value. None of this "Well that's not my job". If I need to fly to a datacenter and run a power off test, I will. If I need to mop the floor and wipe down the breakroom, I'll do that too. Own problems, not positions. | | |
| ▲ | zuzululu 6 minutes ago | parent [-] | | This is the right mindset although I'd have to caution on those comps, very low probability of it turning beyond 4 figure best case or 5 figures in fantastic case, might as well buy a lotto for 6 figure expectation. It's as good as monopoly money and I always ask for cash or time. Time is good for me since I work 3 remote jobs so whatever one is willing to give up I can do better balancing acts. #2 and #3 are excellent. I also might add : "Be willing to walk". Desperation signals compromises that they will exploit. Know exactly what you are offering to the business and walk when they say "thats too much , impossible, bad engineers ask for money like you". 100% those roles have high turn over, stress, and managerial issues. Bad managers penny pinch because they can't use resources efficiently. Good managers pay more for talent because they are competent at managing resources. |
|
| |
| ▲ | xboxnolifes 16 hours ago | parent | prev [-] | | Are you 21 like the person in the Article, or did you start multiple decades ago? |
|
| |
| ▲ | fhdkweig 21 hours ago | parent | prev | next [-] | | > He was smart/determined enough to risk it all. Desperate people are willing to risk it all, and usually smart people aren't desperate. | |
| ▲ | HDBaseT 21 hours ago | parent | prev | next [-] | | It is honestly much easier to spread malware or hack companies than it is to make 200k/year from a company. Now with AI, you can accelerate this so much. The only thing holding back thousands of new threat actors from doing the same is Opsec, its hard. | | |
| ▲ | techjamie 21 hours ago | parent [-] | | A silver lining is that at least a lot of these AI generated malware and phishing scams are easy to disrupt with mild white hat skills. Often the people behind them lack the knowledge on how to prevent themselves from being disrupted by said white hats. The most laughable I've seen was a scam that put a captcha on the frontend to stop me from flooding their free email system on the backend and rate limit them. However, the captcha was clientside only, so I didn't even notice until I looked to see if they rotated emails, but also the captcha was a textbox with the code set as the placeholder. Truly the pinnacle of vibecoding a scam. |
| |
| ▲ | 21 hours ago | parent | prev | next [-] | | [deleted] | |
| ▲ | r_lee 21 hours ago | parent | prev | next [-] | | > didn't he just try find a job that pays $200k/year ? you really think it's that easy? | | |
| ▲ | zuzululu 14 minutes ago | parent | next [-] | | If you expect it to be easy like a handout then thats the wrong attitude because then everybody would be doing it so already this points to lack of context and self awareness. If you are getting paid $200k/year, you have to be willing to see it from the other side of the table, what are you offering really? It's also not as hard or dire as you think it is but without knowing more about your situation or what you tried, its pointless because I suspect that its going to just turn into a moping session. I am working on 3 remote jobs that pay over 200k/year, it takes time and effort, and yes it was relatively easy for me but not in the way that you think it should be. | |
| ▲ | choilive 21 hours ago | parent | prev [-] | | Claude get me a job that pays $200k/yr. Make no mistakes. | | |
| ▲ | pfych 21 hours ago | parent [-] | | Claude get me a job that pays $200k/yr. Make a breakthrough. |
|
| |
| ▲ | idiotsecant 21 hours ago | parent | prev | next [-] | | Yeah, clearly risking it all wasn't the smart play here, as evidenced by the fact he got caught. A lot of people are willing to tolerate risk, that hardly makes them useful. Frequently the opposite. | |
| ▲ | akimbostrawman 13 hours ago | parent | prev [-] | | being smart and using btc are mutually exclusive |
|