Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

141–150 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#141
post #69

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately.

Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person??

Also, the in-person step is usually at the end, which means yes, you can waste a lot of time phone- and Zoom-chatting with fake candidates, but that is equally true for in-office vs. remote roles. Nobody starts with the in-person, on-site interview.

Re: We identified a North Korean hacker who tried to get a job

#142
post #105

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken. It IS "broken" by design as employers just don't want to go through the effort into finding great candidates (even if they are truly exceptional) and now it is even easier for candidates to cheat it thanks t…

Even at small startups, posting engineering jobs will get you hundreds of applications a day. There's simply no way for employers to fairly go through them.

LinkedIn et al make everything worse by making the application process so easy.

If you're a small company, the fix is to outsource the top of your funnel to a recruiting company you trust.

If you're a medium or large company, the fix is to require on-site work.

Re: We identified a North Korean hacker who tried to get a job

#143

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

You really have to just ask dumb interview questions. Testing them on answering questions while putting their hand over their face or their hands covering their eyes now. It's really dumbi-fied our interview processes (see https://datastream.substack.com/p/my-foolproof-interview-que...)

Re: We identified a North Korean hacker who tried to get a job

#144

Earlier quoted context omitted.

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

If I don't assist NK then I'm tacitly assisting the crypto industry. We're in trolley problem territory now.

You’re on a roll.

Re: We identified a North Korean hacker who tried to get a job

#145
post #69

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

  I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI...
Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game it.

Re: We identified a North Korean hacker who tried to get a job

#146

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.

Re: We identified a North Korean hacker who tried to get a job

#147

I don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA". > Their resume was linked to a GitHub profile containing an email address exposed in a past data breach. How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.

> Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.

Which is why everyone needs to switch to passkeys. It's crazy that we still use passwords for authentication

Re: We identified a North Korean hacker who tried to get a job

#148

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

I don't think this has anything to do with remote vs. onsite work. It has more to do with remote vs. onsite interviews. A thorough onsite interview should catch all of these fake candidates. Companies should be doing at least one onsite interview regardless of whether the role itself is remote or onsite.

Re: We identified a North Korean hacker who tried to get a job

#149

Earlier quoted context omitted.

I've heard through the grapevine of some designers (one who worked at Shopify) getting caught using Fiverr (or something similar) to farm out all of their work. Despite all the weird crazy dog and pony show and jumping through hoops that most companies do now, most companies are abysmal at hiring.

What can you do during the hiring process to know that this amazing person, who aces every part of the interview, will farm out their work to cheap subcontractors?

It's hard. I mentioned in another comment I had a work colleague in 2006 who farmed out all his work. He was capable of doing the job, but it was simply more enjoyable for him to play video games all day while someone else did the work for 25% of his salary.

Re: We identified a North Korean hacker who tried to get a job

#150

Commenting on the events, CSO Nick Percoco, said: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or U.S. corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.” It's funny to see the CSO of a c…

Apart from that, he is running a crypto exchange which is completely against the whole ideology of bitcoin and other notable crypto. The guy is a fucking joke. Every crypto exchange has been extremely shady, from coinbase to binance to tether. Kraken is no different
Post reply on HN