Live data from Hacker News

Ask HN: Any felons successfully found IT work post-release?

news.ycombinator.com

231–240 of 402 posts

Re: Ask HN: Any felons successfully found IT work post-release?

#231

Earlier quoted context omitted.

It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. Then you talk about "discovered and revealed vulnerabilities". But, your first sentence talks about "discovered vulnerabilities not revealed". What you may be wanting is a honeypot, where a pentest client intentionally puts some vulnerabilities of various exploit difficulty into the clone environment…

> It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. How so? Presumably most pen testers are working in good faith. But, if there is a malicious actor in their midst, that individual would not disclose any vulnerabilities they intend to exploit, no. What would be the point? That's just a really good way to get caught. > Then you talk about "discovered…

The app and api are on the internet anyway, so you don't need to be a pentester to test it w/ no intention of reporting.

Re: Ask HN: Any felons successfully found IT work post-release?

#232
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

We hired a guy who later billed for critical services through a shadow company. He used someone else’s name, resume and identity.

He was out of prison for a similar thing.

Guess what? There was no background check for the hire nor any vetting of the company.

Guess who found him out?

Re: Ask HN: Any felons successfully found IT work post-release?

#233

Earlier quoted context omitted.

When I was involved in hiring I was told we couldn’t do any online research on potential candidates, like LinkedIn or Facebook, as it might give us information on them being part of a protected class. It’s easier to justify not picking someone based on merit when there is no knowledge of those things.

When I was looking for a job a few months ago, every single application required answering multiple questions about whether I'm Hispanic, and if not, which race I am. Additionally, some employers demand to know my sexual identity AND orientation, which I consider ludicrous and obscene. "Before we can consider your application, we must know who you like to have sex with!" Ostensibly this is for some kind of reporting…

Yeah I find it very obscene that they ask so so many obtrusive questions for "statistics"

Re: Ask HN: Any felons successfully found IT work post-release?

#234
post #196
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

An assault charge is likely relevant for most positions. If I hire a convicted felon with a track record of assault and they end up assaulting another employee or customer, I’d feel responsible. The victim would probably hold me legally responsible. I’d feel more comfortable hiring someone with a 100% track record of never having been convicted of assault. If you disagree, is there any number of assault convictions t…

Criminals who don't reoffend (even for things like assault) within 5 years are almost always statistically a better risk than the public at large.

I won't say that it's almost tautological, but it's pretty close.

If you can surpass conviction and probation, you are remarkably self-disciplined. Probation conditions are much more problematic than an actual job, and the penalty for failure is going back to jail.

A person who can pass that kind of environment is absolutely the kind of person you want working for you.

Re: Ask HN: Any felons successfully found IT work post-release?

#235
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

> ” I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role”

You’d be surprised at how many jobs felons can’t have.

Most jobs that need licensing (e.g.,electrician, plumber, even bartender, and many more).

As well as security, jobs which relate to firearms and many more.

EDIT: for clarity, legally - there are many jobs felons are prohibited from being employed as. So employers have the burden to ensure they only hire legally eligible employees (not hire a felon when not allowed). As such, background checks are how they ensure this.

Re: Ask HN: Any felons successfully found IT work post-release?

#236
post #231

Earlier quoted context omitted.

> It sounds like you're suggesting that pen testers by default will not reveal discovered vulnerabilities with clients. How so? Presumably most pen testers are working in good faith. But, if there is a malicious actor in their midst, that individual would not disclose any vulnerabilities they intend to exploit, no. What would be the point? That's just a really good way to get caught. > Then you talk about "discovered…

The app and api are on the internet anyway, so you don't need to be a pentester to test it w/ no intention of reporting.

You don't need to be, but there are some big advantages:

1. You get to test the flaws in an environment where nobody will raise an eyebrow. If you go straight for the production system, it is likely your early attempts will visibly show up in the logs.

2. You get paid to carry out malicious deeds. That's a double win.

It would be kind of silly not to.

Re: Ask HN: Any felons successfully found IT work post-release?

#237
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

That would create a complex regulations where everyone if fighting over what is "required for the role"

The better, faster and easier solution is a path to quick expungement, this also has the added bonus of offering people an incentive to no re-offend.

IMO once you have completed all active punishment (ie you are no longer on parole or probation) your record should be sealed.

>>If we're so concerned about employers hiring bad employees then state should instead build a centralised database of bad employees and their reason for termination at previous places of work

That would actually be illegal under most state laws as most State's have Anti-Black List laws to prohibit such lists from being created.

Re: Ask HN: Any felons successfully found IT work post-release?

#238
post #209

Earlier quoted context omitted.

Of course, that only works if the vulnerability is reported. There is no reason for the malicious actor to report the vulnerability they have chosen to exploit. What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers?

> What percentage of the vulnerabilities discovered are independently discovered by multiple pen testers? Zero because we patch them as soon as we are notified. Generally at the end of the test / before the retest, but if they found something serious they would notify immediately,

Patch production, sure, but naturally you would leave them in the pen testing environment for some time in order to collect data. No data and you’re just guessing. That’s fine for amateur hour, but not business.

Re: Ask HN: Any felons successfully found IT work post-release?

#239
I am a felon working in IT. My pay is much less than others working in the industry, but I am grateful for the opportunity to work for an employer rather than scrounging for work behind a LLC or something.

There are a lot of small companies out there that don't do background checks, and some slightly larger companies who will overlook your past.

Re: Ask HN: Any felons successfully found IT work post-release?

#240
post #147

I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role (government work, access to children, etc) and where it is important for the role it should only return the criminal convictions that might be relevant to the role. If you were arrested for robbery when you were younger perhaps because you had a drug addiction then that person should…

> ” I know this is a controversial view, but I think employers should not be allowed to run background checks unless important for the role” You’d be surprised at how many jobs felons can’t have. Most jobs that need licensing (e.g.,electrician, plumber, even bartender, and many more). As well as security, jobs which relate to firearms and many more. EDIT: for clarity, legally - there are many jobs felons are prohibit…

>You’d be surprised at how many jobs felons canr have.

How is that relevant?

Post reply on HN