Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

81–90 of 331 posts

Re: A backdoor in a LinkedIn job offer

#82
post #68

Earlier quoted context omitted.

Yes. But the perps are in North Korea.

[flagged]

> simply for being one of the last communist countries

Well, that plus their 50 nuclear warheads and continued ICBM development, amongst other things.

Re: A backdoor in a LinkedIn job offer

#83

This is uncomfortably close to a normal interview task now. Someone sends you a repo, says the install is broken, and asks you to take a look. A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.

The interview context makes it worse. You’re trying not to look slow, so you skip the part where you ask whether you should run it at all.

Re: A backdoor in a LinkedIn job offer

#85
post #44
post #20

Earlier quoted context omitted.

To put it bluntly and perhaps a bit cynically, on the tree of bad things that people do to other people, this is pretty high-hanging fruit. Right up there next to scam phone calls that prey on the elderly while claiming to be from Microsoft support. It's basically impossible to catch suspects because they are either smart enough to cover their tracks very well, or (more often) live in countries whose governments don'…

Hard disagree on the scam phone calls. It would be trivial to eradicate them almost completely if the phone operators did the bare minimum to fight against it. At any point in time, any given US phone number is handled by exactly one phone carrier. There is nothing stopping that carrier from requiring name and address to issue that phone number. They already do for 99.99% of their legitimate customers. It would be ve…

Number spoofing is not a solved problem because some carriers, which appear legitimate in all other respects, make a business out of routing your traffic over TDM trunks that don't support caller ID verification, and will claim it's extremely expensive to upgrade these to VOIP.

Re: A backdoor in a LinkedIn job offer

#86
post #56
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

>I finally got it solved by buying drinks for a buddy of mine that works for LinkedIn

I'd like people to understand that this is a form of corruption. We've normalized many like it. LI knows that the only way to force them to fix the issue is to go through a drawn-out legal process, save a spate of bad press (RIP 60 Minutes), so of course they won't.

Re: A backdoor in a LinkedIn job offer

#87
post #68

Earlier quoted context omitted.

[flagged]

> simply for being one of the last communist countries Well, that plus their 50 nuclear warheads and continued ICBM development, amongst other things.

I read the other day they are making quite a turnaround in GDP by selling munitions to our enemies.

Re: A backdoor in a LinkedIn job offer

#90
post #56

Earlier quoted context omitted.

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

My last 2 companies, LinkedIn asked me to add an email address associated with the said company and actually confirm via said email in order to add them to my profile. So, if I worked for FooCompany, I had to have a @FooCompany.com email which is setup by someone at the company itself. Does this not cover what you're talking about?

According to my research, LinkedIn only does this for executive and now recruiter-like titles, but not broadly. You may be able to in order to get "verified on LinkedIn" but it's not a requirement for showing association with a company.

https://www.theverge.com/news/771210/linkedin-recruiter-exec...

Post reply on HN