Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

51–60 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#52

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

So that's probably a sign that your team culture and management isn't the best... Healthy teams communicate a lot and really get to know each other, whether in person or remote. Ideally with regular in-person meetups to reinforce those working relationships.

If you're just throwing work over the fence and it takes network analysis to figure out who's doing it...then maybe you should just be hiring a contractor anyway.

Re: We identified a North Korean hacker who tried to get a job

#54

Its quite saying, that in order to get interviews, you have to basically lie your way with various generative AI. Whereas, I've been looking for quite a while, with very few bites. And nobody so far on HN Who's hiring responds, except for a place that seems to want 60h/week and pay for 40h/week. Being genuine and truthful in the age of generative AI, LLMs, quiet quitting, /r/overemployed (on the sly working multiple…

I’m a little skeptical that generative AI is an effective way to land a job. It doesn’t really seem like it helps that much in résumé generation. Are people applying to enough hundreds of jobs that generative AI helps you keep up with the sheer volume of text you need to send? Some people are … but these aren’t people who know what good résumés look like, because those people write their own résumés, and these people…

> confirming the signal chat leaks were real

To the degree I skim resumes for anything nowadays, it’s AI slop. Automatic bin.

Re: We identified a North Korean hacker who tried to get a job

#55

Before this interview, industry partners had tipped us off that North Korean hackers were actively applying for jobs at crypto companies. We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken. This doesn't sound so impressive? This single red flag should invalidate the candidate immediately, end of story.

The article explains why they didn't invalidate the candidate immediately. They wanted to learn how they operate.

Re: We identified a North Korean hacker who tried to get a job

#56

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly?

If AI does it, it’s the best thing since sliced bread.

I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.

Re: We identified a North Korean hacker who tried to get a job

#57

I fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan. They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know. Asking the candidate to justify the inconsiste…

> our security and recruitment teams strategically advanced them through our rigorous recruitment process – not to hire, but to study their approach.

Re: We identified a North Korean hacker who tried to get a job

#58

Earlier quoted context omitted.

How do weekly 1:1 meetings with a manager not catch this very quickly? Okay, maybe the original suave interviewer comes back for those… Still feels like a good EM would pick up on discrepancies between work done and how the suave person talks about it. It depresses me, but you’re probably right about in-office work being the only guarantee against this type of scam. I wish we could just have nice things.

I also can’t imagine this not getting caught if not in the interview process surely during every day work. Maybe this says more about their work culture and not actually connecting with co workers. Perhaps the manager was just garbage who knows.

On their first day, they will get a lot of accounts, if they syphon data and m set up backdoors quickly, one day could be enough to cause a good chunk of the damage.

Saddens me a bit. I like to trust hires and give them pretty wide access to everything. For my own company, I've so far only hired people I worked with in the past, but when hiring strangers remotely, I'll probably have to rethink my trust-first model.

Re: We identified a North Korean hacker who tried to get a job

#59
post #20

Earlier quoted context omitted.

Why would this work? Spies are trained to behave like the host country would expect, why wouldn't hackers? If hackers have access to the outside world (something they would need to be effective), they'd know the world thinks Kim is fat. "He's very fat, haha!", end of story. Edit: wait, or better yet: "how on earth would I know, and why are you asking this in a job interview? Is this because I'm Korean? I'd like to fi…

Not sure some rank and file 50ct army "hacker" wants to take the risk to insult their god-dictator.

If he's acting under NK command, this wouldn't be insulting, it's just doing a hacker's work.

Besides, you cannot have it both ways: either North Korean hackers are a "50ct army" or they are a credible threat. Most seem to be arguing they are a credible threat.

Also, he can always take the second option: "why are you asking about this in a job interview?", something many legitimate Korean candidates could ask.

Re: We identified a North Korean hacker who tried to get a job

#60

I fail to understand the whole "advancing the candidate through the interview to learn more about how they do this" plan. They already knew the candidate's name, email, and GitHub were all part of past beaches. I could understand if they were fishing for more information to contribute to a shared list, but it seems like they knew virtually everything they needed to know. Asking the candidate to justify the inconsiste…

Dollars to donuts the NK team is reading this article and adapting their strategies. IMO, rather than ask candidates to justify inconsistencies, you should forward the information to law enforcement and tell the candidate you’re hiring somebody else.

Right, so if you have a tell-tale sign, you concoct a story around other things instead. Parallel construction. They fix all the silly things but you still have the tell-tale.
Post reply on HN