This is an interesting article, but doesn't this: > our Red Team launched an investigation using Open-Source Intelligence gathering (OSINT) methods. basically mean "some guys in the company googled him"?
We identified a North Korean hacker who tried to get a job
11–20 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#12Whereas, I've been looking for quite a while, with very few bites. And nobody so far on HN Who's hiring responds, except for a place that seems to want 60h/week and pay for 40h/week.
Being genuine and truthful in the age of generative AI, LLMs, quiet quitting, /r/overemployed (on the sly working multiple 40h week jobs).... Being honest in this environment seems to be a losing endeavor.
Re: We identified a North Korean hacker who tried to get a job
#13Re: We identified a North Korean hacker who tried to get a job
#14This is an interesting article, but doesn't this: > our Red Team launched an investigation using Open-Source Intelligence gathering (OSINT) methods. basically mean "some guys in the company googled him"?
You can go further. Reach out to data brokers and see whether they've got any information from ad tracking / leaks.
Re: We identified a North Korean hacker who tried to get a job
#15Re: We identified a North Korean hacker who tried to get a job
#16Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Re: We identified a North Korean hacker who tried to get a job
#17They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
Hate to be that person, but what are you reading that makes you think this is true?
Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
Re: We identified a North Korean hacker who tried to get a job
#18Re: We identified a North Korean hacker who tried to get a job
#19Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Despite all the weird crazy dog and pony show and jumping through hoops that most companies do now, most companies are abysmal at hiring.
Re: We identified a North Korean hacker who tried to get a job
#20From somewhere in the depths of an old reddit thread, someone recommended asking candidates "How fat is Kim Jong Un?" Instant hang-up.
If hackers have access to the outside world (something they would need to be effective), they'd know the world thinks Kim is fat.
"He's very fat, haha!", end of story.
Edit: wait, or better yet: "how on earth would I know, and why are you asking this in a job interview? Is this because I'm Korean? I'd like to file a complaint with HR, what was your name again?"