Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

101–110 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#101

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Unless you're in a regulated industry, you might just have a new cost reduction strategy presented to you.

Re: We identified a North Korean hacker who tried to get a job

#102
post #70

Earlier quoted context omitted.

Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly? If AI does it, it’s the best thing since sliced bread. I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.

An arrangement like that is probably violating data protection rules that everybody agreed on. In my company, customer data must not leave company systems, let alone the country.

I get the security issues, but let’s be honest. It’s not about that.

The poster included a sneer about “work”. This is about something else.

Re: We identified a North Korean hacker who tried to get a job

#103

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

My suspicion is that it's purely monetary and driven by the finance people.

a) Don't have to pay to fly candidates out, pay for their hotel, etc.

b) Don't have to pay relocation

c) Get access to a larger pool of candidates, so can price the wages lower than local wages would require

My last company there was a top down directive that in-person interviews were straight up not allowed, everything had to be over Zoom. Even for local candidates, for a job that was supposed to be in-person! Completely crazy IMO.

Re: We identified a North Korean hacker who tried to get a job

#105

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken.

It IS "broken" by design as employers just don't want to go through the effort into finding great candidates (even if they are truly exceptional) and now it is even easier for candidates to cheat it thanks to AI.

The ones claiming to "fix" it aren't fixing anything and are making it worse for both the interviewer and the candidate and are just extracting money from the process.

The reality is, there is no fix.

Re: We identified a North Korean hacker who tried to get a job

#106

Earlier quoted context omitted.

What can you do during the hiring process to know that this amazing person, who aces every part of the interview, will farm out their work to cheap subcontractors?

The thing I'm always curious about with this is: What is the actual bad thing happening here? Is the subcontracted work not good enough? Well, then the problem is that the work is not good enough. Is the person not contributing in other ways that you want them to contribute because they have other jobs? (eg. chat conversations, meetings, team building, etc.) Well, then the problem is that they aren't making those con…

Where I work, it would be sharing of credentials and lying (or at least being dishonest) about who did the work.

Re: We identified a North Korean hacker who tried to get a job

#107

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely?

(I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)

Re: We identified a North Korean hacker who tried to get a job

#108

I don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA". > Their resume was linked to a GitHub profile containing an email address exposed in a past data breach. How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.

100%. There is a bragging tone that felt completely unwarranted. Like being on a date with someone who is really insecure.

Re: We identified a North Korean hacker who tried to get a job

#109
post #86

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

I know some folks good folks who work in the security industry. It seems like there's a very WIDE range of quality people / companies, and an awful lot of compete FRAUDS. For whatever reason "security" seems to have attracted a lot of carpetbaggers. The good folks are very sensitive about it.

Absolutely! It's probably 90/10.

Nothing gives someone away as a poser as much as bragging about OSINT as if it's some sort of tradecraft meanwhile they're executing the same skills your average wine aunt does stalking her ex-boyfriend on Facebook.

Re: We identified a North Korean hacker who tried to get a job

#110

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

If you want to work as a clerk at Target, the video is not even an interview, it’s a one-way audition you record to be judged anonymously.
Post reply on HN