this post was submitted on 21 Jul 2025
515 points (96.6% liked)

Games

40857 readers
1477 users here now

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Rules

1. Submissions have to be related to games

Video games, tabletop, or otherwise. Posts not related to games will be deleted.

This community is focused on games, of all kinds. Any news item or discussion should be related to gaming in some way.

2. No bigotry or harassment, be civil

No bigotry, hardline stance. Try not to get too heated when entering into a discussion or debate.

We are here to talk and discuss about one of our passions, not fight or be exposed to hate. Posts or responses that are hateful will be deleted to keep the atmosphere good. If repeatedly violated, not only will the comment be deleted but a ban will be handed out as well. We judge each case individually.

3. No excessive self-promotion

Try to keep it to 10% self-promotion / 90% other stuff in your post history.

This is to prevent people from posting for the sole purpose of promoting their own website or social media account.

4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

This community is mostly for discussion and news. Remember to search for the thing you're submitting before posting to see if it's already been posted.

We want to keep the quality of posts high. Therefore, memes, funny videos, low-effort posts and reposts are not allowed. We prohibit giveaways because we cannot be sure that the person holding the giveaway will actually do what they promise.

5. Mark Spoilers and NSFW

Make sure to mark your stuff or it may be removed.

No one wants to be spoiled. Therefore, always mark spoilers. Similarly mark NSFW, in case anyone is browsing in a public space or at work.

6. No linking to piracy

Don't share it here, there are other places to find it. Discussion of piracy is fine.

We don't want us moderators or the admins of lemmy.world to get in trouble for linking to piracy. Therefore, any link to piracy will be removed. Discussion of it is of course allowed.

Authorized Regular Threads

Related communities

PM a mod to add your own

Video games

Generic

Help and suggestions

By platform

By type

By games

Language specific

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] sugar_in_your_tea@sh.itjust.works 2 points 14 hours ago (1 children)

social engineering

It's also probably the most common type of breach. It's way easier to compromise tech support than find a vulnerability, so it makes a ton of sense for a company like Blizzard to have an auditing team to test the various attack vectors.

A lot of roles like QA and cyber security sound glamorous, but that's because people like glamorous titles. If you've spent even a tiny amount of time working in a relevant industry (in this case, anything touching computers), you should be able to read between the lines. That "sanitation engineer" is probably just a janitor or garbage truck driver, not the person in charge of the city water filtration services or something.

scavenger hunt badge

I haven't been, but yeah, that sounds likely. Things like that are to get people new to the industry excited, not to actually challenge hardcore hackers.

I've attended and even spoken at some tech conferences, and they're like 90% entry level stuff with a handful of interesting events and talks that actually break some new ground. I'm in senior level position now, and conferences are something I'd send my juniors to for networking and to get an idea of how they want to grow their career, but I don't really attend anymore. I imagine cyber security conferences are similar.

Ask him what SYN, SYN-ACK and ACK are

Lol, that's basic TCP stack stuff, I doubt he would've gone that low level at a company like Blizzard. You get to that level when you're looking for amplification attacks at a place like Cloudflare or the military.

At Blizzard, they most likely want to make sure they're up to date on security patches, their tech support is following the proper scripts, and IT isn't getting lazy reviewing reports and whatnot. Basically, liability coverage in case there's a real breach so their insurance can cover any losses.

But yeah, streamers like to appear like they know their stuff because that's what gets people to watch.

[–] sp3ctr4l@lemmy.dbzer0.com 1 points 4 hours ago (1 children)

It's also probably the most common type of breach. It's way easier to compromise tech support than find a vulnerability, so it makes a ton of sense for a company like Blizzard to have an auditing team to test the various attack vectors.

Yep, absolutely.

The uh, funniest one that sticks in my memory was the hack of basically an early build of GTA 6.

Somebody social engineered their way into someone at Rockstar who had some level of admin acces, I think via fake / intercepted and reformed 2FA auths to the target's phone, along with some spear phishing.

Then, they were proficient enough to exploit thier way throughout the intranet... but not smart enough to cover all their tracks.

A lot of roles like QA and cyber security sound glamorous, but that's because people like glamorous titles. If you've spent even a tiny amount of time working in a relevant industry (in this case, anything touching computers), you should be able to read between the lines.

You would think this, but everywhere I have worked in the industry... most people cannot infact read between the lines.

I've attended and even spoken at some tech conferences, and they're like 90% entry level stuff with a handful of interesting events and talks that actually break some new ground.

Impressive!

I've been to some, never spoken though... also, not DEFCON though.

I imagine cyber security conferences are similar. (mostly exist for networking)

I agree.

But yeah, streamers like to appear like they know their stuff because that's what gets people to watch.

Yeah, but Thor takes it to an uncommon point of basically being a conman, with his so much of his reputation built, by himself, on vastly overstated credentials.

Its like getting a 2 year nursing assistant degrer and then acting as if you can safely perform a brain surgery.

ve been to some, never spoken though… also, not DEFCON though.

Yeah, I've spoken at local JS and Go confs with several hundred to a couple thousand attendees (my sessions were small, like 30 people), and attended a couple others.

DEFCON is much larger, but looking at the schedule, it seems pretty similar, a mix of relatively entry level stuff and more advanced topics. So someone attending doesn't say much other than that they're interested in cyber security.

Its like getting a 2 year nursing assistant degrer and then acting as if you can safely perform a brain surgery.

Interesting. I haven't watched enough of his stuff to know what claims he's made.