Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

81–90 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#83
Commenting on the events, CSO Nick Percoco, said:

“Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or U.S. corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.”

It's funny to see the CSO of a crypto firm say this. It's the opposite of the whole way crypto works. In crypto, the transaction is processed (trusted) if all the credentials and keys are correct, regardless of who's behind it.

Re: We identified a North Korean hacker who tried to get a job

#84
post #65

Earlier quoted context omitted.

These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job. The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses ever…

I find this answer highly implausible, not the least because maintaining cover doesn't count as dissing ("I infiltrated the org by telling them the lies they wanted to hear" is hacking 101). Also, North Koreans aren't dumb. I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? > Dissing Kim is something that is not currently widely…

I am saying they are both a credible threat and many are amateurs. Those are not mutually exclusive.

You are talking about North Korea attackers from a theoretical point of view. For many people dealing with them is just a normal part of work. It's not an unknown that needs to be worked out logically from an armchair.

I'm saying this as someone who personally chatted with a North Korea persona that later tried to drop exploits on people, and the persona belonged to hacking group with at least one 50 million dollar heist. I've also seen the screenshots on many chats with North Koreans.

Re: We identified a North Korean hacker who tried to get a job

#85
I don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA".

> Their resume was linked to a GitHub profile containing an email address exposed in a past data breach.

How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.

Re: We identified a North Korean hacker who tried to get a job

#86

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

I know some folks good folks who work in the security industry.

It seems like there's a very WIDE range of quality people / companies, and an awful lot of compete FRAUDS.

For whatever reason "security" seems to have attracted a lot of carpetbaggers.

The good folks are very sensitive about it.

Re: We identified a North Korean hacker who tried to get a job

#87

Earlier quoted context omitted.

Dollars to donuts the NK team is reading this article and adapting their strategies. IMO, rather than ask candidates to justify inconsistencies, you should forward the information to law enforcement and tell the candidate you’re hiring somebody else.

Well they claim the final interview involved asking the candidate very specific questions about the town they claimed to be living in, and hold up government issued ID to the camera. My assumption based on this was they weren't certain it was someone malicious and they were double checking their own conclusion. If not it makes no sense to tip the candidate off that you're suspicious about them. At that point I'd say…

    > Name 5 restaurants not on Google maps in the town you live in".
I'm definitely a US based human and no way I get this right.

Re: We identified a North Korean hacker who tried to get a job

#88
We had similar earlier on at Graphistry. It was pretty obvious, especially by the time of video screens. We are still unsure if whether a hacker or just someone avoiding their history/nationality

- online history was sparse and somewhat mismatching, and weird profile image reuse

- unexpectedly strong accent in calls, does not show video

- background reference checks a mess

Re: We identified a North Korean hacker who tried to get a job

#89
post #52

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

So that's probably a sign that your team culture and management isn't the best... Healthy teams communicate a lot and really get to know each other, whether in person or remote. Ideally with regular in-person meetups to reinforce those working relationships. If you're just throwing work over the fence and it takes network analysis to figure out who's doing it...then maybe you should just be hiring a contractor anyway…

Yeah I similarly find this baffling. This very flatly would not work in any job I've had, whether in person or remote.

Re: We identified a North Korean hacker who tried to get a job

#90
post #69

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

I think its useful to test as to what questions they are and aren't prepared for. In the future you won't necessarily know they were an imposter, so it's good to devise and test certain captcha like questions to tease out the fake from the real candidates.
Post reply on HN