Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

151–160 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#151
post #139
post #132

Earlier quoted context omitted.

I mean you see that here on HN right? People claiming that any arbitrary question is something they have no idea about, like the color of their front door.

I’m not sure I know what you mean—I’m not sure I’d want to discuss the specifics of my living environment here though. Would you have any examples handy?

If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE.

It's just like the bar scene in Inglorious Bastards, with the fingers. There are so many obvious tells you can have people divulge if they aren't actually telling the truth.

Re: We identified a North Korean hacker who tried to get a job

#152
post #145
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI... Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game…

Do you want the industry to go back to only hiring from the top ~20 schools and by word-of-mouth networking? Coz that's the only viable alternative to the current interview process.

Re: We identified a North Korean hacker who tried to get a job

#153

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.

I'm not sure I'm really against this! --IF-- the company is happy with the results and code being delivered, and the compensation they are paying for that code, what is the actual, meaningful business difference between whether your colleague wrote it or the Czech guy wrote it?

I'm not asking what the moral or ethical difference is. They're paying for engineering output, and if they are getting that output, why does it really matter whose fingers are typing it in?

Re: We identified a North Korean hacker who tried to get a job

#154

Earlier quoted context omitted.

Yeah I similarly find this baffling. This very flatly would not work in any job I've had, whether in person or remote.

I have worked in places where this would work...all terrible places that usually had someone with a "maverick" view of how organizations worked derived from reading Warhammer books or something.

> with a "maverick" view of how organizations worked derived from reading Warhammer books or something

Did they want to serve the god emperor of SAAS?

Re: We identified a North Korean hacker who tried to get a job

#155
This is happening with high value crypto companies with large security teams. Imagine what happens when OSS maintainers are asked to work on GitHub repositories with malicious code as part of fake job interviews?

If its not insider access then might as well hack an OSS maintainer and publish malicious open source package that everyone depends on to reach your target organization.

Re: We identified a North Korean hacker who tried to get a job

#156

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

COVID isn't in the past, just no one doing anything about it. :)

Re: We identified a North Korean hacker who tried to get a job

#157

Earlier quoted context omitted.

I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.

I'm not sure I'm really against this! --IF-- the company is happy with the results and code being delivered, and the compensation they are paying for that code, what is the actual, meaningful business difference between whether your colleague wrote it or the Czech guy wrote it? I'm not asking what the moral or ethical difference is. They're paying for engineering output, and if they are getting that output, why does…

I can think of a few reasons, most obviously that it's a security nightmare - you've got a non-employee accessing and modifying your company's code and possibly having access to customer data. Some shops might not care about this, but it's ridiculously irresponsible in principle.

Re: We identified a North Korean hacker who tried to get a job

#158
post #105

Earlier quoted context omitted.

> What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken. It IS "broken" by design as employers just don't want to go through the effort into finding great candidates (even if they are truly exceptional) and now it is even easier for candidates to cheat it thanks t…

Even at small startups, posting engineering jobs will get you hundreds of applications a day. There's simply no way for employers to fairly go through them. LinkedIn et al make everything worse by making the application process so easy. If you're a small company, the fix is to outsource the top of your funnel to a recruiting company you trust. If you're a medium or large company, the fix is to require on-site work.

This isn't really a new problem. I remember back during a previous tech downturn, the small-ish (~200 people) no-name company I worked for also got hundreds of applications a day. Yes, today, fake candidates and AI make it worse, but fundamentally the "huge number of people in the top of the funnel" problem has been a thing for a long time.

Re: We identified a North Korean hacker who tried to get a job

#159
post #145

Earlier quoted context omitted.

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI... Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game…

Do you want the industry to go back to only hiring from the top ~20 schools and by word-of-mouth networking? Coz that's the only viable alternative to the current interview process.

> Do you want to the industry to go back to hiring from the top ~20 schools and by word-of-mouth networking?

This never stopped and is still the case for "good" jobs btw.

Re: We identified a North Korean hacker who tried to get a job

#160

Earlier quoted context omitted.

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

It used to be only against specific industries, but now it's evolving. Now they have groups just going after remote IT jobs regardless of industry.

Beyond just the salary, once they have access to the corporate network they can execute other attacks to steal from company accounts and infiltrate connected business partners. Most organizations still have very weak protection against insider threats.
Post reply on HN