Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

1–10 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#2
> Not all attackers break in, some try to walk through the front door.

Now made even easier for fraudsters and including state actors thanks to Generative AI. Also:

> Generative AI is making deception easier, but isn’t foolproof. Attackers can trick parts of the hiring process, like a technical assessment, but genuine candidates will usually pass real-time, unprompted verification tests.

This is why Leetcode / Hackerrank and other (online assessments) OA in the technical interview is unfit for use in the age of AI.

> In the modern era, it’s an organizational mindset.

Security is a way of life for this company, but it would have easily fooled a less security-oriented company and it will just only get worse.

Re: We identified a North Korean hacker who tried to get a job

#4
They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post.

On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring.

I don't think I've ever worked anywhere that could accidentally hire a North Korean without uncovering it somewhere in the hiring process, and all my jobs have been especially uninteresting.

What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken.

Re: We identified a North Korean hacker who tried to get a job

#6
post #2

> Not all attackers break in, some try to walk through the front door. Now made even easier for fraudsters and including state actors thanks to Generative AI. Also: > Generative AI is making deception easier, but isn’t foolproof. Attackers can trick parts of the hiring process, like a technical assessment, but genuine candidates will usually pass real-time, unprompted verification tests. This is why Leetcode / Hacker…

> genuine candidates will usually pass real-time, unprompted verification tests.

I wonder these are similar to the "tests" in Suits, where they (somewhat inadvertently) check whether someone went to Harvard by asking about the food places students typically went to.

Re: We identified a North Korean hacker who tried to get a job

#7
Here's a heretical thought: Remote hiring is a massive achilles heel.

I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many.

Remote work has amazing upsides and tremendous security implications.

Re: We identified a North Korean hacker who tried to get a job

#8

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

And yet: do the same thing with AI and you're a cutting edge genius.

Re: We identified a North Korean hacker who tried to get a job

#9
If people are hiring this sort of applicant I'm of the opinion they kind of deserve to be "pwned". The most basic of process should have weeded this dude out instantly at any modern company.

I'm sure this wasn't a case of the most advanced/sophisticated attempt from North Korea and other bad actors, and probably just a case of them casting a wide net. But regardless based off of this writeup and the video shown dude should have never been given the time of day.

Re: We identified a North Korean hacker who tried to get a job

#10

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Some people did this with in-office too I think, some years ago. Some people actually had two jobs, both sort of in-office. It's still possible to pull the tricks.
Post reply on HN