Live data from Hacker News

Ask HN: Any felons successfully found IT work post-release?

news.ycombinator.com

171–180 of 402 posts

Re: Ask HN: Any felons successfully found IT work post-release?

#171
post #158

I worked at 70 Million Jobs (YC) to help people with records get jobs. Here's my advice FWIW. Your experience in security operations is in demand, so that's a big plus for you. Seek work that you can do via external environments, meaning you don't need to be on-site, and don't need to have internal access. Ideally you can create an LLC so you can work for yourself. A few examples... 1. Doing compliance-oriented secur…

Was going to suggest looking into an LLC. I ran a security consulting company for about ten years and the only customers that asked for background checks were banks and some federal agencies.

Re: Ask HN: Any felons successfully found IT work post-release?

#172

I have a felony dui from 2010. No deaths, injuries or crashes or anything like that just found myself over the limit a few times in the days before lyft/uber. I had to focus on jobs with small companies that did no checks. There were so many times I declined jobs when I saw the background check just to avoid the shame. It's a waiting game until it falls off the threshold of places caring. Eventually I got a job as a…

> Ps some states have laws against asking if you're a felon. Cali and Colo might be If you've been convicted of anything in the last 10-15 years, every script-kiddie docket scraper will attribute the conviction to you. This is only useful to people willing/able to compartmentalize their past under a deadname. Then applicants can mislead the employer into running background checks on a synthetic identity that comes ba…

When I changed my name, the court required extensive proof I had no convictions, no major debts, etc. etc. This was quite a while ago. Are you saying requirements have been loosened?

Re: Ask HN: Any felons successfully found IT work post-release?

#173
post #121

Earlier quoted context omitted.

Fight with HR? No, they are breaking the law. You should talk to an employment lawyer. You could potentially get a cash settlement, force them to consider your application, or an injunction that would force them to treat future applicants better. Could also file a complaint with the state and they will investigate on your behalf. Good lawyer can advise you of options though.

I tried. they wanted money up front I couldn't afford. The job was a relocation to boston, mass. and they had the check the box laws and all that. It didn't matter. They did it in writing, too. every step of the way. from the job offer, to the acceptance, to the background check after, to notifying me of adverse information being found, they gave me a chance to explain, and I'm like, you said you wouldn't look back f…

Maybe you need a better lawyer. Good lawyer should talk to you for free to explain the process and see if you have a case worth pursuing.

Also this is definitely free and they can decide to bring a lawsuit on your behalf https://calcivilrights.ca.gov/complaintprocess/?content=file...

Re: Ask HN: Any felons successfully found IT work post-release?

#174
post #77

Earlier quoted context omitted.

We log all accesses and flows. So eg if our pentesters found a vulnerability in an endpoint, we can retrieve every post against that endpoint and (1) verify the pentesters didn't exploit it against prod, and (2) verify that it hasn't been exploited by anyone else.

Of course, that only works if the vulnerability is reported. There is no reason for the malicious actor to report the vulnerability they have chosen to exploit. What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?

>What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?

I'd warrant nearly all of them, though it may take a while.

If you have ever submitted or worked with a bug bounty program you will run into dozens of duplicates.

I've personally performed and overseen assessments in which the company had already done a complete blackbox pentest and wanted a second whitebox review to make sure the first company knew their stuff and validate they found the same bugs. Also did a few of the honeypot assessments in which companies put purposely vulnerable code in to make sure 'we are doing our job', I hate those most.

Depending on the testers speciality of course, the reports often found the same or similar issues.

Source: 15 years as a pentester, offensive security engineer, and now security architect.

Re: Ask HN: Any felons successfully found IT work post-release?

#175
post #163

Earlier quoted context omitted.

could you explain this further? what benefit would there be?

I assume they're suggesting create a false identity, and pose as a foreign national illegally living in the United States. It's a rather ...unconventional suggestion, that clearly was not thought out. There is a high risk someone doing that ends up stateless, i.e., with no documentation or paperwork establishing citizenship in any country. The US may arrest such a person at the border - and then imprison them - and t…

U.S. Customs and Border Protection will happily reply to emails explaining exactly what I said is what in fact happens. You don't have to travel to Arizona or Texas to see it first-hand.

Rather than constructing an imaginary straw man detached from reality, please try to reply to the comment and the facts with external links to refute the information. I'm more than happy to provide further counter-factual information to whatever hifalutin nonsense is offered, as if this isn't a statement of fact.

What I'm describing is what actually happens today for the overwhelming majority of border crossings. :)

Re: Ask HN: Any felons successfully found IT work post-release?

#176

Earlier quoted context omitted.

No, they don't do this. It's not even clear how they would; the closest thing would be merging based on IP or fingerprinting, but both are extremely noisy.

You can easily demonstrate to yourself that they do. And the situation here is that felon_in_texas visits HN in his usual manner, views a topic he wants to comment on, creates an account on the spot, and leaves his comment. How noisy do you think the IP identification can be?

Extremely, if they’re on CGNAT. Or live in a house with more than one person.

Please be precise about how I can demonstrate this to myself.

Re: Ask HN: Any felons successfully found IT work post-release?

#177
post #169

Earlier quoted context omitted.

> [edit: after reading felonintexas let me update this. If someone point blank asks, tell them. Don’t volunteer this information. There is nothing to be gained] My Fraternity's cook, when I was in college, was a former fellon. He worked for us for a few years before he told me about his background. I don't remember the details, but we had a conversation where he mentioned he had experience in IT. Eventually he very b…

Why did you let the conversation drift around to “if you were making big bucks why are you cooking for us now”? That’s a remarkably rude thing to ask for absolutely no reason other than ego.

You’ve never chatted up a bartender where they end up telling you personal things after years? Maybe after they’ve served you food and beverage for a long time, you bond over X (sports, politics, whatever) and end up feeling like friends?

I hafta say, it seems like you’re the one with the ego.

Edit: if I had to guess, the cook probably said something like “I made a lot more money before I worked here.” And was then asked why.

Re: Ask HN: Any felons successfully found IT work post-release?

#179
post #169

Earlier quoted context omitted.

> [edit: after reading felonintexas let me update this. If someone point blank asks, tell them. Don’t volunteer this information. There is nothing to be gained] My Fraternity's cook, when I was in college, was a former fellon. He worked for us for a few years before he told me about his background. I don't remember the details, but we had a conversation where he mentioned he had experience in IT. Eventually he very b…

Why did you let the conversation drift around to “if you were making big bucks why are you cooking for us now”? That’s a remarkably rude thing to ask for absolutely no reason other than ego.

Seems normal to me

Re: Ask HN: Any felons successfully found IT work post-release?

#180
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

I mostly agree with that, but I think it should be more along the lines of standardization WRT job responsibilities. I.e. any job would be categorized similarly to how you put it, with categories like "handles money" or "access to children" or whatever.

Then, to do a background check, you just input those job categories and an applicants ID info and get back a "no adverse events" result, or otherwise get back info on only crimes relevant to the categories specified. My understanding is that is basically how some EU countries do it.

I think companies would welcome this sort of standardization (including how many years it would take for different adverse events to fall off your record) as it would help insulate them from claims of bias.

Post reply on HN