43 comments

  • drnick1 a day ago ago

    This underscores a major issue with commercial software like Steam and games obtained therein. You cannot trust that software not to maliciously scan your device for secrets such as crypto wallets or other information. Ideally, you want to run apps like Steam, Discord, Zoom and whatever else does not come from a trusted distribution repo as a separate user. This is not always convenient however, and the compromise I adopted on my gaming PC is to bubblewrap Steam. Do not mount things like /home and devices games should not be using in the sandbox.

    • wps 17 hours ago ago

      Agreed. I’ve always disliked having anything to do with gaming on my primary OS, always choosing to compartmentalize that stuff away from anything sensitive. The only exception is DRM free standalone games like Factorio, which has pretty safe mods compared to something like Minecraft.

    • techjamie 21 hours ago ago

      In theory you could change the steam command line fpr each game and have them launch in bubblewrap. Though I'm not sure how well that would play with graphics drivers. It might be friendly with AMD, but my experience is that NVIDIA is a pain to have play nice with containers.

      • drnick1 21 hours ago ago

        I sandbox Steam itself for simplicity. My experience with Nvidia and Wayland has been good. I simply exposed /dev/nvidia*, a few networking-related files in /etc and system binaries like /usr.

        • jallasprit 17 hours ago ago

          How are you doing the sandboxing?

          • drnick1 16 hours ago ago

            Bubblewrap.

    • kibwen a day ago ago

      This is what my Steam Deck is for. There's no gap like air gap.

      • drnick1 21 hours ago ago

        Dedicated hardware is definitely the most secure option, but realistically it is even less convenient than a separate user. You can't realistically play graphically intensive games on a Deck, and separate workstations are very unaffordable at the moment.

    • akimbostrawman 14 hours ago ago

      flatpak is the most convenient way to securely run steam on linux

    • charcircuit 21 hours ago ago

      Android solves this problem by making it impossible for an app to access the storage of another app. No matter how much the Steam app wants to see your crypto wallet's key it is not possible (assuming no Linux exploit).

      • drnick1 21 hours ago ago

        That's nice, but a cell phone isn't a viable gaming platform for anything but very basic games. And Android, at least in its typical Googled form, has its own set of problems; it's a privacy nightmare.

        • charcircuit 18 hours ago ago

          And despite what you claim it is the most profitable gaming platform. There are lessons you can learn from them.

          • xboxnolifes 17 hours ago ago

            Skinner boxes of MTX in peoples' pockets is a good business model. The lessons were learned, and gacha games are huge on PC.

  • Cider9986 a day ago ago

    Criminals should have used Monero.

    Victims should have not keep crypto on desktops. They are much less secure than Mobile.

    • LoganDark a day ago ago

      Modern macOS devices have a secure element just as good as iOS devices. Almost nobody makes use of it, though.

      (I haven't seen anything yet that uses the secure element to control access to a wallet. Are there any technical obstacles to keeping the keys out of main memory?)

    • fsflover a day ago ago

      > Victims should have not keep crypto on desktops. They are much less secure than Mobile.

      Unless it's Qubes OS.

  • LoganDark a day ago ago

    I heard Monero can help against blockchain analysis (though less so if you buy from adversaries). Unfortunately it looks like blockchain analysis was not the attack vector here, but rather buying gift cards through an incompetent intermediary.

    • HDBaseT a day ago ago

      Not really an "incompetent intermediary", Bitrefill, the company used for buying gift cards with Bitcoin received legal requests to identify the user. Bitrefill doesn't proclaim insane privacy protections, they are based out of Sweden but aren't immune to being requested to provide the information.

      Monero could of helped, although its not easy to transfer BTC to Monero without P2P trades, as effectively every exchange requires KYC. Those source and destination wallet addresses are tainted, you wouldn't be able to deposit on any mainstream exchange and if they do, its for a honey pot purpose.

      • tancop 5 hours ago ago

        thats why btc/monero is not as great as a lot of people think.

        ethereum has stablecoins and dex swaps so you dont have to do p2p once you have any tokens in the ecosystem, all you need is some eth to pay gas fees. and its the only crypto project i trust completely.

        for privacy theres railgun and aztec, both have canonical bridges back to layer 1 and enough users to give you correlation resistance. tornado cash has compromised governance but i dont think the core contracts are broken so you can use that too, just be careful when you deal with americans because its illegal there.

        kinda ironic that bitcoin is designed to be as trustless as possible but you need to trust third parties with you money a lot of the time because the core protocol is too simple for its own good.

      • Cider9986 20 hours ago ago

        >Monero could of helped, although its not easy to transfer BTC to Monero without P2P

        It's really not hard but it probably gets much harder to transfer tainted Bitcoin. Trocador.app aggregates various no-KYC CEX swaps and is regarded well in the Monero community.

        As we can see from the various Monero pumps, which often stemmed from cleaning coins. Thieves don't want to sit on the Bitcoin so they drive up the price of Monero selling it fast.

        Yeah P2P is more technical. Hopefully with Serai we can get a good UX decentralized exchange.

        Swapping into fiat is a different beast.

      • LoganDark 21 hours ago ago

        Making it possible to identify a user is incompetence, exactly because of legal issues like this. You don't run a service that accepts crypto for gift cards and then keep information on file that identifies the buyer personally, that's just stupid. But then again, you don't illegally obtain crypto and then give out your info when you go to use the illegal funds, that's just stupid as well.

        Is P2P that big a deal? I swap coins on Bisq all the time. It's super easy to pick up and use if you already have the BTC. The biggest obstacle is obtaining some BTC in the first place when you don't have any yet. Once you have enough for the security deposit, you can buy/sell or swap thousands of dollars in funds at a time.

  • zuzululu a day ago ago

    He was smart/determined enough to risk it all. Why didn't he just try find a job that pays $200k/year ? Why play into the stereotypes ?

    • tancop 6 hours ago ago

      job market is insane today. its hard to find a job in retail in some places, software is way more competitive. retraining to some in demand trade takes money you might not have and its still not guaranteed success. and even if you get hired for a stable job theres no guarantee your company will let you work your way up to 200k when they know you cant afford to quit.

      the uncertainty of crime is better than endless waiting for an offer that might never come. if you take 10 scammers or drug dealers one of them will get rich, 3 will go to prison and the rest have a relatively normal life. that might be genuinely better odds than a mainstream career for some.

      • zuzululu 4 hours ago ago

        crime has short term certainty with long term uncertainty. a legitimate job has short term uncertainty with long term certainty. its stupid silly and dangerous way to view it as an escape from your current job situation.

        I don't know why people keep whining about job markets. I'm currently working 3 different remote jobs each past 200k/yr point

        my total salary is close to 800k. if one of them fires me i can easily hop to another job. I've been doing this for well over a year now and everybody is happy.

        there's really no need to justify criminal behavior when legitimate options are in front of you and you are too lazy, weak willed to see the upside.

    • robotnikman a day ago ago

      >Why didn't he just try find a job that pays $200k/year ?

      Probably was not able to get into MIT or another prestigious school that many of those companies look for on a resume.

      • vorpalhex a day ago ago

        None of my peers went to any school of note, nor did I. A fair bit of community college, some lower ranked state unis, and one guy did a bootcamp.

        All well above 200k.

        • Obscurity4340 4 hours ago ago

          Is it worth enrolling in a local public college for programming? I think its a 2-3 year course but would it have good bridges to actually getting experience and emplpyed in software?

          Might have to do it part time but id still be into getting out of my current job which i cant see myself lasting long-term in. I need something with more latitude and definitely better pay, prospects. Im at a dead end and nughtmare i cant wake up from if i stand still any longer

        • darksim905 21 hours ago ago

          What do they do, _exactly_? Because in the real world out of YC, the rest of us can barely top $200,000 a year unless we move into management or Executive level roles.

          • vorpalhex 7 hours ago ago

            Software engineers. None of us work for YC, we are based in Texas. No oil/gas, nor defense, nothing like that.

            Years ago I had a recruiter that wanted to hawk me and I asked for 180k comp and he told me it was "impossible". Hung up, was hired at 185k a few weeks later. Wasn't even much of a negotiation when I asked for it.

            1. Be willing to accept non-cash comp. Stock of various forms, etc. This works with later stage companies better for obvious reasons.

            2. Go into all negotiations ready to explain to the other side what they are buying. Remain calm if not slightly bored. Repeat your ask as if the other side has forgotten them (that sort of bored, calm tone). Do not argue.

            3. Actually deliver business value. None of this "Well that's not my job". If I need to fly to a datacenter and run a power off test, I will. If I need to mop the floor and wipe down the breakroom, I'll do that too. Own problems, not positions.

            • zuzululu an hour ago ago

              This is the right mindset although I'd have to caution on those comps, very low probability of it turning beyond 4 figure best case or 5 figures in fantastic case, might as well buy a lotto for 6 figure expectation. It's as good as monopoly money and I always ask for cash or time. Time is good for me since I work 3 remote jobs so whatever one is willing to give up I can do better balancing acts.

              #2 and #3 are excellent. I also might add : "Be willing to walk". Desperation signals compromises that they will exploit. Know exactly what you are offering to the business and walk when they say "thats too much , impossible, bad engineers ask for money like you". 100% those roles have high turn over, stress, and managerial issues.

              Bad managers penny pinch because they can't use resources efficiently. Good managers pay more for talent because they are competent at managing resources.

        • xboxnolifes 17 hours ago ago

          Are you 21 like the person in the Article, or did you start multiple decades ago?

    • fhdkweig a day ago ago

      > He was smart/determined enough to risk it all.

      Desperate people are willing to risk it all, and usually smart people aren't desperate.

    • HDBaseT a day ago ago

      It is honestly much easier to spread malware or hack companies than it is to make 200k/year from a company.

      Now with AI, you can accelerate this so much. The only thing holding back thousands of new threat actors from doing the same is Opsec, its hard.

      • techjamie 21 hours ago ago

        A silver lining is that at least a lot of these AI generated malware and phishing scams are easy to disrupt with mild white hat skills. Often the people behind them lack the knowledge on how to prevent themselves from being disrupted by said white hats.

        The most laughable I've seen was a scam that put a captcha on the frontend to stop me from flooding their free email system on the backend and rate limit them. However, the captcha was clientside only, so I didn't even notice until I looked to see if they rotated emails, but also the captcha was a textbox with the code set as the placeholder.

        Truly the pinnacle of vibecoding a scam.

    • undefined a day ago ago
      [deleted]
    • r_lee a day ago ago

      > didn't he just try find a job that pays $200k/year ?

      you really think it's that easy?

      • zuzululu an hour ago ago

        If you expect it to be easy like a handout then thats the wrong attitude because then everybody would be doing it so already this points to lack of context and self awareness. If you are getting paid $200k/year, you have to be willing to see it from the other side of the table, what are you offering really?

        It's also not as hard or dire as you think it is but without knowing more about your situation or what you tried, its pointless because I suspect that its going to just turn into a moping session.

        I am working on 3 remote jobs that pay over 200k/year, it takes time and effort, and yes it was relatively easy for me but not in the way that you think it should be.

      • choilive a day ago ago

        Claude get me a job that pays $200k/yr. Make no mistakes.

        • pfych 21 hours ago ago

          Claude get me a job that pays $200k/yr. Make a breakthrough.

    • idiotsecant a day ago ago

      Yeah, clearly risking it all wasn't the smart play here, as evidenced by the fact he got caught.

      A lot of people are willing to tolerate risk, that hardly makes them useful. Frequently the opposite.

    • akimbostrawman 14 hours ago ago

      being smart and using btc are mutually exclusive