Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

141–150 of 534 posts

Re: I almost got hacked by a 'job interview'

#141
post #43

Earlier quoted context omitted.

How am I supposed to become a real, trustable person on LinkedIn if I'm not already there?

Create an account and let it age. Seasoned accounts are a positive heuristic in many domains, not just LinkedIn. For example, I some times use web.archive.org to check a company's domain to see how far back they've been on the web. Even here on HN, young accounts (green text) are more likely to be griefing, trolling, or spreading misinformation at a higher rate than someone who has been here for years.

Account can be stolen

Re: I almost got hacked by a 'job interview'

#142

Earlier quoted context omitted.

I think it's a real company. https://search.sunbiz.org/Inquiry/CorporationSearch/SearchRe... ~~Scammers probably got access to the guy's account.~~ (how to make strikethrough...) He changed his LinkedIn to a different company. I guess check verifications when you get messages from "recruiters."

> (how to make strikethrough...) Unfortunately(?) you can't: https://news.ycombinator.com/formatdoc

You can use special a Unicode strikethrough glyphs such as available in https://efck-chat-keyboard.github.io

Re: I almost got hacked by a 'job interview'

#143
> I was 30 seconds away from running malware on my machine.

> The attack vector? A fake coding interview from a "legitimate" blockchain company.

Well that was a short article. Kudos to them, obviously candidates interested in a "blockchain company" are already very prone to getting scammed.

Re: I almost got hacked by a 'job interview'

#144
post #35
post #4

I’ve grown to depend on little snitch for this sort of thing. Always run in either Alert or Deny mode. It is a little wild how many things expect to communicate with the internet, even if you tell them not to. Example: the Cline plugin for vscode has an option to turn off telemetry, but even then it tries to talk to a server on every prompt, even when using local ollama.

I agree, it's very valuable in these situations, although it can only minimize damage. For Littlesnitch/OpenSnitch users: avoid allow rules that apply to all apps. Malware can and has used even trusted websites like Github Gists to expose secrets extracted. In any case, even if your firewall protects you, you'll still have to treat the machine as compromised.

specially interpreters: python, perl, npm, etc.

https://github.com/evilsocket/opensnitch/wiki/Rules#best-pra...

Re: I almost got hacked by a 'job interview'

#145

Earlier quoted context omitted.

Of course. A malware-infected dependency has motivation to pay for GitHub stars and fake repo activity. I would never trust any metric that measures public "user activity". It can all be bought by bad actors.

Then what do you do instead?

Skim through the code? Sure it's likely to miss something, but it still catches low-effort and if enough people do it someone will see it.

Re: I almost got hacked by a 'job interview'

#147
Is it reasonable to wonder if they set up this attack to target OP specifically, the whole thing was customized for OP? Rather than a broad phishing of lots of developers or what have you.

Although now that makes me wonder -- can you have AI set up an entire fake universe of phishing (create the linked in profiles, etc) customized specifically for a given target.... en masse for many given targets. If not yet, very soon. Exciting.

Re: I almost got hacked by a 'job interview'

#150
post #16

The pseudonym "Mykola Yanchii" on LinkedIn [1] doesn't look real at all. Click "More" button -> "About this profile", RED FLAGS ALL OVER. -> Joined May 2025 -> Contact information Updated less than 6 months ago -> Profile photo Updated less than 6 months ago Funny things, this profile has the LinkedIn Verified Checkmark and was verified by Persona ?!?! -> This might be a red flag for Persona service itself as it migh…

> This might be a red flag for Persona service itself as it might contain serious flaws and security vulnerabilities that Cyber criminals are relying on

Persona seems to rely solely on NFC with a national passport/ID, so simply stolen documents would work for a certain duration ...

Post reply on HN