Earlier quoted context omitted.
It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. Then you talk about "discovered and revealed vulnerabilities". But, your first sentence talks about "discovered vulnerabilities not revealed". What you may be wanting is a honeypot, where a pentest client intentionally puts some vulnerabilities of various exploit difficulty into the clone environment…
> It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. How so? Presumably most pen testers are working in good faith. But, if there is a malicious actor in their midst, that individual would not disclose any vulnerabilities they intend to exploit, no. What would be the point? That's just a really good way to get caught. > Then you talk about "discovered…
Ask HN: Any felons successfully found IT work post-release?
231–240 of 402 posts
Re: Ask HN: Any felons successfully found IT work post-release?
#232I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
He was out of prison for a similar thing.
Guess what? There was no background check for the hire nor any vetting of the company.
Guess who found him out?
Re: Ask HN: Any felons successfully found IT work post-release?
#233Earlier quoted context omitted.
When I was involved in hiring I was told we couldn’t do any online research on potential candidates, like LinkedIn or Facebook, as it might give us information on them being part of a protected class. It’s easier to justify not picking someone based on merit when there is no knowledge of those things.
When I was looking for a job a few months ago, every single application required answering multiple questions about whether I'm Hispanic, and if not, which race I am. Additionally, some employers demand to know my sexual identity AND orientation, which I consider ludicrous and obscene. "Before we can consider your application, we must know who you like to have sex with!" Ostensibly this is for some kind of reporting…
Re: Ask HN: Any felons successfully found IT work post-release?
#234I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
An assault charge is likely relevant for most positions. If I hire a convicted felon with a track record of assault and they end up assaulting another employee or customer, I’d feel responsible. The victim would probably hold me legally responsible. I’d feel more comfortable hiring someone with a 100% track record of never having been convicted of assault. If you disagree, is there any number of assault convictions t…
I won't say that it's almost tautological, but it's pretty close.
If you can surpass conviction and probation, you are remarkably self-disciplined. Probation conditions are much more problematic than an actual job, and the penalty for failure is going back to jail.
A person who can pass that kind of environment is absolutely the kind of person you want working for you.
Re: Ask HN: Any felons successfully found IT work post-release?
#235I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
You’d be surprised at how many jobs felons can’t have.
Most jobs that need licensing (e.g.,electrician, plumber, even bartender, and many more).
As well as security, jobs which relate to firearms and many more.
EDIT: for clarity, legally - there are many jobs felons are prohibited from being employed as. So employers have the burden to ensure they only hire legally eligible employees (not hire a felon when not allowed). As such, background checks are how they ensure this.
Re: Ask HN: Any felons successfully found IT work post-release?
#236Earlier quoted context omitted.
> It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. How so? Presumably most pen testers are working in good faith. But, if there is a malicious actor in their midst, that individual would not disclose any vulnerabilities they intend to exploit, no. What would be the point? That's just a really good way to get caught. > Then you talk about "discovered…
The app and api are on the internet anyway, so you don't need to be a pentester to test it w/ no intention of reporting.
1. You get to test the flaws in an environment where nobody will raise an eyebrow. If you go straight for the production system, it is likely your early attempts will visibly show up in the logs.
2. You get paid to carry out malicious deeds. That's a double win.
It would be kind of silly not to.
Re: Ask HN: Any felons successfully found IT work post-release?
#237I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
The better, faster and easier solution is a path to quick expungement, this also has the added bonus of offering people an incentive to no re-offend.
IMO once you have completed all active punishment (ie you are no longer on parole or probation) your record should be sealed.
>>If we're so concerned about employers hiring bad employees then state should instead build a centralised database of bad employees and their reason for termination at previous places of work
That would actually be illegal under most state laws as most State's have Anti-Black List laws to prohibit such lists from being created.
Re: Ask HN: Any felons successfully found IT work post-release?
#238Earlier quoted context omitted.
Of course, that only works if the vulnerability is reported. There is no reason for the malicious actor to report the vulnerability they have chosen to exploit. What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?
> What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers? Zero because we patch them as soon as we are notified. Generally at the end of the test / before the retest, but if they found something serious they would notify immediately,
Re: Ask HN: Any felons successfully found IT work post-release?
#239There are a lot of small companies out there that don't do background checks, and some slightly larger companies who will overlook your past.
Re: Ask HN: Any felons successfully found IT work post-release?
#240I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…
> ” I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role” You’d be surprised at how many jobs felons can’t have. Most jobs that need licensing (e.g.,electrician, plumber, even bartender, and many more). As well as security, jobs which relate to firearms and many more. EDIT: for clarity, legally - there are many jobs felons are prohibit…
How is that relevant?