Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

71–80 of 331 posts

Re: A backdoor in a LinkedIn job offer

#71
post #56
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

[deleted]

Re: A backdoor in a LinkedIn job offer

#73

Maybe Mac will finally get decent virtualization framework. Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast. Remember to use protection when meeting random people, and putting their junk deep inside your computer!

>Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast.

It's ok, the guy with glasses from the Daily Show said it's ok.

Re: A backdoor in a LinkedIn job offer

#74
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

I've had people phish for my email then hit that with some bullshitpowershellladendoucument.pdf.docx crap, but sending it directly in the IM?

Bold strategy cotton, let's see if it pays off.

Re: A backdoor in a LinkedIn job offer

#75
post #62
post #44

Earlier quoted context omitted.

Hard disagree on the scam phone calls. It would be trivial to eradicate them almost completely if the phone operators did the bare minimum to fight against it. At any point in time, any given US phone number is handled by exactly one phone carrier. There is nothing stopping that carrier from requiring name and address to issue that phone number. They already do for 99.99% of their legitimate customers. It would be ve…

KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure. This is on par with being unable to open a bank account if the capability is matured. I'd advise that you think long and hard about the consequences of this system being applied against you maliciously before signing on the dotted line.

> KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure.

We have that in Europe and the world has not fallen apart. On top of that, we don't have even close to the scale of problems with scammers that the US has. I won't deny we don't have scammers because we absolutely have them, but they are far from the scourge they are in the US.

> This is on par with being unable to open a bank account if the capability is matured.

The secret is... we have constitutionally protected rights. Unless you do not pay your bills, your phone line will not get disconnected. And same for bank accounts - every European has the right to a basic banking account, even if you are a target of foreign sanctions [1].

[1] https://www.tagesschau.de/ausland/europa/konto-eugh-usa-sank...

Re: A backdoor in a LinkedIn job offer

#76

Maybe Mac will finally get decent virtualization framework. Downloading random unprotected scripts from internet, like it is 1995 is getting old pretty fast. Remember to use protection when meeting random people, and putting their junk deep inside your computer!

> Maybe Mac will finally get decent virtualization framework.

it already has, you can configure intellij to run npm commands in a Docker container.

Re: A backdoor in a LinkedIn job offer

#77
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

I see several comments like this implying nothing can be done. But that is far from the truth. First, an agency that actually answered the phone could coordinate directly with LinkedIn and other tech companies to quickly take down these fake accounts and minimize harm to others. We all know how incredibly hard it is to contact a tech company. Second, an agency that answers the phone could help less technical people find what may have been compromised and push people towards support services if needed. And finally, maybe, they could do the hard job of combining leads and working with appropriate agencies to maybe find and prevent these things over time.

Re: A backdoor in a LinkedIn job offer

#78
This is uncomfortably close to a normal interview task now.

Someone sends you a repo, says the install is broken, and asks you to take a look.

A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.

Re: A backdoor in a LinkedIn job offer

#79
post #8

So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.

The scammers are in a different whole uncooperative country.

Or they may be in this country, but uses proxies, virtual machines, hostings from uncooperative country.

Re: A backdoor in a LinkedIn job offer

#80
post #32

Earlier quoted context omitted.

Friends don't let friends use NPM. At this point it is so wildly crazy watching people get owned, I don't understand how anyone uses it when they could use e.g. PNMPM and block one if the most obvious and frequently exploited holes. These tools with arbitrary code execution when trying to download some code have got to stop. Edit: typos

> Friends don't let friends ise NPM or linkedin

I don't have friends, therefore I must use LinkedIn to get a job. Hooray!
Post reply on HN