🇰🇵 DPRK loves it when you:
- Save your seed phrase in a password manager.
- Use hot wallets instead of hardware wallets.
- Don't use antivirus, EDR or Lockdown mode in your devices.
- Download pirated stuff, install shady apps and play games in your work device.
- Accept calls from people without verifying them first.
- Use SMS for 2FA.
- Sync your passwords, google authenticator and passkeys to your Gmail account
- Install lots of browser extensions
- Don't update your Operating system and apps.
- Repeat passwords.
- Don't use a device exclusively for work
- Don't verify what you are signing
- Run npm install on a "coding challenge" from a recruiter you met on LinkedIn.
- Blindly add npm/PyPI packages without checking the publisher, download counts, or recent version history.
- Pin your dependencies to "latest" and hope for the best.
- Trust any GitHub repo with a slick README and a few stars.
- Reuse the same email for crypto, banking, and signing up to random newsletters.
- Click "Remind me later" on security updates for weeks.
- Disable Windows Defender because it "slows things down."
- Plug in random USB drives you found at conferences.
- Give every app full disk access without reading the prompt.
- Brag about your portfolio size on Twitter under your real name.
- Share your screen on Zoom with your main user logged in
- Connect your wallet to every airdrop site that promises free tokens.
- Approve unlimited token spending so you "don't have to do it again."
- Keep your recovery codes in a screenshot in your camera roll.
- Trust a Telegram admin who DMs you first.
- Run unsigned binaries because "the SHA matches the website.
Let's grow up as an industry and start treating security seriously.
STAY SAFE