Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

141–150 of 331 posts

Re: A backdoor in a LinkedIn job offer

#141
post #21

I've been getting some job offers on LinkedIn, all of them are shady af. Apply using a platform. Apply recording a video of yourself. Apply by resolving a calibration code test (behind a code platform)...

My brother had been unemployed for a long time due to illness, and finally got a "job offer" on LinkedIn that seemed legit to him. They asked for him to write a check to make a deposit for his company laptop (which seems pretty insane on the face of it), but he was desperate and really happy to finally have a job offer. People who've been unemployed for a long time are often desperate enough to overlook serious red f…

A long time ago, I worked for an ISP that sent out the famous "we'll never ask for your passwords" email. Then, about 3 weeks in, they sent out emails asking people for their passwords. If you told me that this was a happy ending, he sent in a check and they sent a laptop and after 2 paychecks released his deposit, I wouldn't be shocked. Some companies are run by idiots. I even know that most companies could probably cover scammed hardware with business insurance, but then I wonder how many flying-by-the-seat-of-their-pants outfits don't have the insurance.

Hoping he wasn't scammed.

Re: A backdoor in a LinkedIn job offer

#143
post #56

Earlier quoted context omitted.

LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…

>I finally got it solved by buying drinks for a buddy of mine that works for LinkedIn I'd like people to understand that this is a form of corruption. We've normalized many like it. LI knows that the only way to force them to fix the issue is to go through a drawn-out legal process, save a spate of bad press (RIP 60 Minutes), so of course they won't.

I agree with you. I used to work for an ISP that sold kind-of overpriced 1Gbps connections and always wondered why customers bought it. Probably helping things was that we took them out to "events", floor seats at basketball, etc. The company just has a fixed expense, but the people making the decision get free stuff that makes them feel important, and it was kind of a way of transferring the company's money (by not buying the $29/month Internet connection) to themselves. I never felt good about it, but if you say that out loud, everyone will look at you like you're crazy.

AWS did this for us at the time but the 3 people in the company that used AWS services never got to go to these things. So I doubly don't get it.

Re: A backdoor in a LinkedIn job offer

#144
post #53

Earlier quoted context omitted.

>It would be trivial to eradicate them almost completely Absolutely true, but droning their data centers might have some policy repercussions.

A majority of people would enthusiastically support drone strikes on scam callers and their infrastructure.

Wasn’t that sort of the premise of The Beekeeper?

Re: A backdoor in a LinkedIn job offer

#145
post #16

> a recruiter at a small crypto startup [...] she described a broken proof-of-concept they needed a lead engineer for, and then sent me a public GitHub repo to review. Specifically, she asked me to “check out the deprecated Node modules issue.” > ...buried between walls of commented-out tests, the payload runs anything the server sends back to your machine. > npm runs prepare automatically after npm install, so just…

surprise is unwarranted as linkedin enshittifies. This type of thing is exactly what happens when neither the user of the service, nor the third party commercial interests are being served by the commercial enterprise. It's a vacuum that scams enter into.

LinkedIn is unusually resistant to enshitification; it started that way.

Re: A backdoor in a LinkedIn job offer

#146
post #83

This is uncomfortably close to a normal interview task now. Someone sends you a repo, says the install is broken, and asks you to take a look. A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.

The interview context makes it worse. You’re trying not to look slow, so you skip the part where you ask whether you should run it at all.

At least now there is a blog post that you can link to and say "Sorry, but I don't run npm install locally because of the risk of phishing attacks."

Re: A backdoor in a LinkedIn job offer

#147
I don't have a LinkedIn profile.

~50% of jobs listed on who is hiring every month require a LinkedIn profile to submit a job application.

In order to find a job, one must bend the knee to LinkedIn first and subjugate themselves to the political (all sides) propaganda on the feed.

Re: A backdoor in a LinkedIn job offer

#148

I don't have a LinkedIn profile. ~50% of jobs listed on who is hiring every month require a LinkedIn profile to submit a job application. In order to find a job, one must bend the knee to LinkedIn first and subjugate themselves to the political (all sides) propaganda on the feed.

I have a profile, but you couldn't pay me to look at the feed.

Re: A backdoor in a LinkedIn job offer

#149

I don't have a LinkedIn profile. ~50% of jobs listed on who is hiring every month require a LinkedIn profile to submit a job application. In order to find a job, one must bend the knee to LinkedIn first and subjugate themselves to the political (all sides) propaganda on the feed.

I use a Firefox extension to block the feed
Post reply on HN