They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
We identified a North Korean hacker who tried to get a job
121–130 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#122Earlier quoted context omitted.
“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).
If I don't assist NK then I'm tacitly assisting the crypto industry. We're in trolley problem territory now.
Re: We identified a North Korean hacker who tried to get a job
#123They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
Then next year it's a different guy, same schtick.
Re: We identified a North Korean hacker who tried to get a job
#124> asking the candidate to verify their location, hold up a government-issued ID, and even recommend some local restaurants in the city they claimed to be in. I don't know, if I run into these questions in a job interview, especially with a small, less known company, I would be having serious questions about what this company is doing
"yeah, could you just hold up that ID please... Thanks, also a few more questions..Who was your favorite teacher, and what was the first car you owned ?"
Re: We identified a North Korean hacker who tried to get a job
#125Earlier quoted context omitted.
My suspicion is that it's purely monetary and driven by the finance people. a) Don't have to pay to fly candidates out, pay for their hotel, etc. b) Don't have to pay relocation c) Get access to a larger pool of candidates, so can price the wages lower than local wages would require My last company there was a top down directive that in-person interviews were straight up not allowed, everything had to be over Zoom. E…
The advantage of a larger pool of candidates is not mostly a financial benefit, IMO. The benefit is mostly the ability to hire from a larger pool of people especially with a specialized skillset, and also to have less of an echo chamber. But yes, that directive to interview local candidates over zoom does seem very silly.
Opening up the wider pool without the in person interview is where things hit the wall since the filtering criteria everyone learned over their careers went out the door thanks to the online interview process. And the online interview process is much more subject to cheating--not exactly a huge concern in-person.
Re: We identified a North Korean hacker who tried to get a job
#126They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
Dude you ain't kidding. Security is all SaaS sales now and chasing corporate buzzwords, it's not security they're selling, it's insurance and the ability to outsource blame when you get popped. Get a new CISO? You'll probably be buying the software from the last company he worked with and spending the next 3 years installing it all over just in time for them to declare mission accomplished you are secure and move on…
If you have a system that is down for 12 hours 3 times a year, it's fine - as long as a lot of other companies are also down. If you have one that's down for 2 hours once every 3 years, but you're the only one affected, that's terrible. Not because you're "losing sales", but because you can't bemoan a common supplier, point to "it's a global problem", and then get taken for a nice apology lunch by the account manager when your bill goes up 10% next year.
Re: We identified a North Korean hacker who tried to get a job
#127Earlier quoted context omitted.
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely? (I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)
To write code (even with the benefit of AI) effectively you need a mental model of the systems you work with, reading the chatGPT response doesn't prove you have that.
Re: We identified a North Korean hacker who tried to get a job
#128Re: We identified a North Korean hacker who tried to get a job
#129I don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA". > Their resume was linked to a GitHub profile containing an email address exposed in a past data breach. How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.
> We received a list of email addresses linked to the [North Korean] hacker group, and one of them matched the email the candidate used to apply to Kraken.
Re: We identified a North Korean hacker who tried to get a job
#130Someone said that North Koreas are trying to get jobs. Ok Then they had a candidate who was trying to cheat the systemeat How did they establish and verify that the candidate was North Korean? Are North Koreans the only ones who try to remote work byt lying about their whereabouts? Not at all. If you live in a country outside of the US and you see the money software poeple make in the US it is mighty tempting to land…
> We received a list of email addresses linked to the [North Korean] hacker group, and one of them matched the email the candidate used to apply to Kraken.