Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Some people did this with in-office too I think, some years ago. Some people actually had two jobs, both sort of in-office. It's still possible to pull the tricks.
We identified a North Korean hacker who tried to get a job
161–170 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#162Earlier quoted context omitted.
Do you want the industry to go back to only hiring from the top ~20 schools and by word-of-mouth networking? Coz that's the only viable alternative to the current interview process.
> Do you want to the industry to go back to hiring from the top ~20 schools and by word-of-mouth networking? This never stopped and is still the case for "good" jobs btw.
Re: We identified a North Korean hacker who tried to get a job
#163They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
> Something in the industry as a whole is quite broken. The problem is that it's very difficult to assess how good someone is in their job. The solution is to promote the best engineers into management so they can vet the candidates.
Re: We identified a North Korean hacker who tried to get a job
#164They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about this issue as a company, yet we've had people get through 2 or 3 rounds before someone realized something was off (some people are really, really good at faking it).
I feel bad for small companies trying to hire. For us, it got to the point where we literally couldn't open a role unless we had a full time recruiter to sift through all the international candidates pretending to live in the US.
Edit: We've been dealing with this for a couple years now, and there still isn't a great solution. Unfortunately the only surefire "solutions" we can think of are also things that would make the interview process less enjoyable for real candidates, which sucks. (One idea was to ask candidates to show us photo ID during the video interview, but something about making a candidate do that just doesn't feel good - although we have tried it, and it has effectively stopped a few fake people from getting through)
Re: We identified a North Korean hacker who tried to get a job
#165How can Kraken found this out based only on Videocall?
Re: We identified a North Korean hacker who tried to get a job
#166Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.
Re: We identified a North Korean hacker who tried to get a job
#167From somewhere in the depths of an old reddit thread, someone recommended asking candidates "How fat is Kim Jong Un?" Instant hang-up.
In the depths of an old reddit thread, OR in a different thread that happens to appear today, alongside this one, on HN front page! https://news.ycombinator.com/item?id=43853382
I don't believe they are earnestly identifying spies, even if they believe it. Not that they need spies to hack our system anyway, they managed to bring half the country to a halt by themselves.
Re: We identified a North Korean hacker who tried to get a job
#168Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
I don't think this has anything to do with remote vs. onsite work. It has more to do with remote vs. onsite interviews . A thorough onsite interview should catch all of these fake candidates. Companies should be doing at least one onsite interview regardless of whether the role itself is remote or onsite.
If they cannot board a plane using their claimed identity from their claimed city of origin, you can stop there.
Re: We identified a North Korean hacker who tried to get a job
#169Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…
Hate to be that guy, but.. what’s the problem? The work is getting done for the price you agreed on. You care how it’s done suddenly? If AI does it, it’s the best thing since sliced bread. I’m sorry but capitalists that want to have it both ways annoy me. Agree on what gets delivered for how much and get out of the way. The “employer” mindset doesn’t jive with capitalism ya’ll are so fond of.