Earlier quoted context omitted.
I assume they're suggesting create a false identity, and pose as a foreign national illegally living in the United States. It's a rather ...unconventional suggestion, that clearly was not thought out. There is a high risk someone doing that ends up stateless, i.e., with no documentation or paperwork establishing citizenship in any country. The US may arrest such a person at the border - and then imprison them - and t…
U.S. Customs and Border Protection will happily reply to emails explaining exactly what I said is what in fact happens. You don't have to travel to Arizona or Texas to see it first-hand. Rather than constructing an imaginary straw man detached from reality, please try to reply to the comment and the facts with external links to refute the information. I'm more than happy to provide further counter-factual information…
Ask HN: Any felons successfully found IT work post-release?
191–200 of 402 posts
Re: Ask HN: Any felons successfully found IT work post-release?
#192I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
The elephant in the room is legal liability. If something happens with a criminal employee then the question is raised "what precautions did you take from letting this dangerous person into your workplace".
Re: Ask HN: Any felons successfully found IT work post-release?
#193Earlier quoted context omitted.
Of course, that only works if the vulnerability is reported. There is no reason for the malicious actor to report the vulnerability they have chosen to exploit. What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?
It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. Then you talk about "discovered and revealed vulnerabilities". But, your first sentence talks about "discovered vulnerabilities not revealed". What you may be wanting is a honeypot, where a pentest client intentionally puts some vulnerabilities of various exploit difficulty into the clone environment…
How so? Presumably most pen testers are working in good faith. But, if there is a malicious actor in their midst, that individual would not disclose any vulnerabilities they intend to exploit, no. What would be the point? That's just a really good way to get caught.
> Then you talk about "discovered and revealed vulnerabilities".
Yes, that's right. While it is theoretically possible for all your pen testers to be working together maliciously, if you are careful in your employment practices you can make this highly unlikely.
As such, if your data shows that 100% of all known vulnerabilities were independently discovered by multiple testers, then there is reasonable confidence that any malicious actor's failure to disclose a vulnerability will still be reported by someone else.
But if that figure is less than 100%, and especially if it is considerably less than 100%, then there is much more doubt cast on another pen tester in your organization's ability to find the same vulnerability. Here you have a problem.
Re: Ask HN: Any felons successfully found IT work post-release?
#194(Throw away account for obvious reasons) I experienced this. Due to various undiagnosed mental health issues I ended up with a serious record in the UK - a total of 15 charges, all computer related. Due to the clear lack of malicious intent I didn't serve any time, but did get shackled with: 12 months suspended for 12 months; 10 years on the sex offenders register; 7 years sexual harm prevention order; and 5 years of…
> Due to the clear lack of malicious intent I didn't serve any time, but did get shackled with: 12 months suspended for 12 months; 10 years on the sex offenders register; 7 years sexual harm prevention order; and 5 years of something else I can't remember. What did you actually do, and what did they get you for? > 5 years of something else I can't remember. Just speaking for myself, I feel like I'd remember something…
That much drama for a sentence the state doesn't consider worth serving stinks of CSAM.
Re: Ask HN: Any felons successfully found IT work post-release?
#195Earlier quoted context omitted.
> [edit: after reading felonintexas let me update this. If someone point blank asks, tell them. Don’t volunteer this information. There is nothing to be gained] My Fraternity's cook, when I was in college, was a former fellon. He worked for us for a few years before he told me about his background. I don't remember the details, but we had a conversation where he mentioned he had experience in IT. Eventually he very b…
> the super-illegal (but "grey morality") thing he did I'm curious to know what he did given your description. I can think of examples of the reverse: quasi-illegal, but quite immoral.
Re: Ask HN: Any felons successfully found IT work post-release?
#196I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
If I hire a convicted felon with a track record of assault and they end up assaulting another employee or customer, I’d feel responsible.
The victim would probably hold me legally responsible.
I’d feel more comfortable hiring someone with a 100% track record of never having been convicted of assault.
If you disagree, is there any number of assault convictions that would change your mind? Or do you mentally wipe the slate clean no matter what?
Re: Ask HN: Any felons successfully found IT work post-release?
#197I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
The elephant in the room is legal liability. If something happens with a criminal employee then the question is raised "what precautions did you take from letting this dangerous person into your workplace".
If, as I understand is the case in the USA, employers are allowed to retrieve the potential criminal record of prospective employees after they have served their sentence, that's where one could argue the employer could be criminally liable for future wrongdoing by their employee.
Re: Ask HN: Any felons successfully found IT work post-release?
#198So you could narrow your searches down using "Fair chance"
Others like Glassdoor just use "People with a criminal record are encouraged to apply"
Now, whether those employers really mean it, or if it's a legal requirement they check that box, I'm not sure.
Re: Ask HN: Any felons successfully found IT work post-release?
#199Earlier quoted context omitted.
> [edit: after reading felonintexas let me update this. If someone point blank asks, tell them. Don’t volunteer this information. There is nothing to be gained] My Fraternity's cook, when I was in college, was a former fellon. He worked for us for a few years before he told me about his background. I don't remember the details, but we had a conversation where he mentioned he had experience in IT. Eventually he very b…
Why did you let the conversation drift around to “if you were making big bucks why are you cooking for us now”? That’s a remarkably rude thing to ask for absolutely no reason other than ego.
First, the commenter could have been paraphrasing a longer conversation that led to that question.
Second, the "I used to be somebody" conversation is more common than you think. Asking "If you were somebody, what happened?" is usually the question that is being invited to be asked if someone brings up this topic.
Re: Ask HN: Any felons successfully found IT work post-release?
#200Earlier quoted context omitted.
Of course, that only works if the vulnerability is reported. There is no reason for the malicious actor to report the vulnerability they have chosen to exploit. What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?
>What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers? I'd warrant nearly all of them, though it may take a while. If you have ever submitted or worked with a bug bounty program you will run into dozens of duplicates. I've personally performed and overseen assessments in which the company had already done a complete blackbox pentest and wanted a second whitebox review…
Why guess when the other commenter has the actual data...?