Live data from Hacker News

I Inspected My Take-Home Interview Project. It Was a Whole Operation

citizendot.github.io

71–80 of 135 posts

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#71

Wow, after reading this article, I figured out I was hacked, but with a way more sophisticated attack. A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he expl…

I just checked my calendar, and it was a 45-minute interview scheduled on Calendly. HR person sent me a link to Calendly so I could schedule an interview with the CTO. I actually talked with someone pretending to be the CTO for 45 minutes.

I checked other similar threads on HN, but they don't mention an actual Google Meet call with a scammer.

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#73
post #70

Nice read, but having your home page play music is incredible rude.

Oh that was way more common in the Wild Wacky West days.

Thankfully all my browsers are now configured to mute all sound from all sites until I grant express permission to play sound. Nips it in the bud, every time!

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#74
I once received a suspiciously too good to be true job offer, and at the last minute they surprised me by insisting I use a specific laptop they insisted on mailing me. One they would possess prior to me, and "configure" as superuser, before giving to me to use while working for them.

I declined, as diplomatically as I could. I should not have to spell out in precise detail how dangerous to me their proposal was. In the eyes of an adversary/APT predator: ignorant --> naive --> gullible --> prey --> profit. Rinse, repeat, scale up.

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#76
post #36

Are these kinds of tests still relevant in the AI age? Genuine question, I have not interviewed for a very long time. They seem as useful as take home college exams.

Although the questions sometimes trigger useful hallucinations (we were able to instantly disqualify tons from our last hiring batch due to a hallucinated Go stdlib call, their code didn't even compile), the other thing is that you can ask the candidate to talk about their code during an interview. I've seen plenty that submitted good answers but couldn't answer even basic questions about the code they wrote ("what does a sync.Waitgroup do?")

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#77

I once received a suspiciously too good to be true job offer, and at the last minute they surprised me by insisting I use a specific laptop they insisted on mailing me. One they would possess prior to me, and "configure" as superuser, before giving to me to use while working for them. I declined, as diplomatically as I could. I should not have to spell out in precise detail how dangerous to me their proposal was. In…

Isn’t this how most tech companies, if not most companies in general, operate? Ive only had one BYOD job in 15 years. Even if you’re a contractor this is common.

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#78

Wow, after reading this article, I figured out I was hacked, but with a way more sophisticated attack. A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he expl…

wow

> I maintained a very popular NPM package with 43+M weekly downloads

makes sense why they targetted you, good that you have 2FA enabled.

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#79
Recently there seems to be an uptick in North-Korean attacks against developers. In addition to this type of attack, which has been going on for years, I recently get ~1 email a week from North Korean hackers. It's always a "Hello, I found your profile, want to collaborate?" e-mail.

Discord communities I am in for programming are similar. People show up and within a few days either ask for a job or suggest cooperation. Sure, you could argue these Discord people may actually be out of a job (in this economy, very likely), but the volume and similarity of the messages say otherwise. You can also tell people show up in... _weird places_ to ask for jobs. An example being the Discord community for a not-really-used Python library with ~0 actual activity - either this person is very bad at finding good places to jobhunt or some attacker is just crawling a list of Discord communities and attacking them all.

It's a shame but there are a _lot_ of attacks that abuse our trust in each other nowadays. A good reminder to, like mom and dad said, never trust strangers on the internet

Re: I Inspected My Take-Home Interview Project. It Was a Whole Operation

#80

I once received a suspiciously too good to be true job offer, and at the last minute they surprised me by insisting I use a specific laptop they insisted on mailing me. One they would possess prior to me, and "configure" as superuser, before giving to me to use while working for them. I declined, as diplomatically as I could. I should not have to spell out in precise detail how dangerous to me their proposal was. In…

hmm, i don't understand why you think this is suspicious. doing their stuff on their machine is ... fine i guess?
Post reply on HN