Earlier quoted context omitted.
And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely? (I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)
I think the best interview question, and really the only one you need to determine technical ability is ask someone to describe a http request in as much detail as possible. To write code (even with the benefit of AI) effectively you need a mental model of the systems you work with, reading the chatGPT response doesn't prove you have that.
We identified a North Korean hacker who tried to get a job
171–180 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#172Earlier quoted context omitted.
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly
Ha if I got asked that during an interview, I'd think either I went to the wrong interview or the interview is a red flag.
Re: We identified a North Korean hacker who tried to get a job
#173Earlier quoted context omitted.
I'm not sure I'm really against this! --IF-- the company is happy with the results and code being delivered, and the compensation they are paying for that code, what is the actual, meaningful business difference between whether your colleague wrote it or the Czech guy wrote it? I'm not asking what the moral or ethical difference is. They're paying for engineering output, and if they are getting that output, why does…
I can think of a few reasons, most obviously that it's a security nightmare - you've got a non-employee accessing and modifying your company's code and possibly having access to customer data. Some shops might not care about this, but it's ridiculously irresponsible in principle.
I wouldn't see anything wrong with this, but I would be willing to bet that 99% of companies would not go along with it--for reasons I'm not sure I understand.
Re: We identified a North Korean hacker who tried to get a job
#174Earlier quoted context omitted.
Some people did this with in-office too I think, some years ago. Some people actually had two jobs, both sort of in-office. It's still possible to pull the tricks.
The rate of this happening has got to be so low it's negligible.
Re: We identified a North Korean hacker who tried to get a job
#175Earlier quoted context omitted.
I’m not sure I know what you mean—I’m not sure I’d want to discuss the specifics of my living environment here though. Would you have any examples handy?
If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE. It's just like the bar scene in Inglorious Bastards, with the fingers…
I lived in NYC for a year and I have no clue. My answer would be probably something along the line of "Haha! Yeah. Traffic is terrible in the city... or so do my friends with cars say. I for one take the subway everywhere, so no clue what you are talking about. But sounds like a pain! Hope you were not delayed too long."
> It's just like the bar scene in Inglorious Bastards, with the fingers.
The problem is that's a work of fiction. These shibboleth tests work great in fiction where the author has full control over the whole universe. Work less well in reality where "universal" signals turn out to be a lot less universal. You will have a ton of false positives and a ton of false negatives.
Re: We identified a North Korean hacker who tried to get a job
#176Commenting on the events, CSO Nick Percoco, said: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or U.S. corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.” It's funny to see the CSO of a c…
I wonder what crypto-currency looked like before the digital age...
Edit: added -currency suffix to crypto :p
Re: We identified a North Korean hacker who tried to get a job
#177Earlier quoted context omitted.
They're getting interviews left and right https://www.theregister.com/2025/04/29/north_korea_worker_in... According to Crowdstrike (the company that wiped out most of global technology last year) at least > My favorite interview question, because we've interviewed quite a few of these folks, is something to the effect of 'How fat is Kim Jong Un?' They terminate the call instantly
> How fat is Kim Jong Un Ha if I got asked that during an interview, I'd think either I went to the wrong interview or the interview is a red flag.
Re: We identified a North Korean hacker who tried to get a job
#178Earlier quoted context omitted.
You can't AI if in person.
they just out source the in person parts > It turns out there is a burgeoning sub-industry of college-aged males of Asian ancestry who cannot wait to get paid for participating in these schemes. There are Discord channels all around the world just for this. They make a few hundred to a few thousand dollars for allowing their identity to be misused or participating in the scheme. That way, they can interview in person…
Re: We identified a North Korean hacker who tried to get a job
#179Re: We identified a North Korean hacker who tried to get a job
#180Earlier quoted context omitted.
> Do you want to the industry to go back to hiring from the top ~20 schools and by word-of-mouth networking? This never stopped and is still the case for "good" jobs btw.
Depends on what your definition of "good jobs" is but I know plenty of people from no name unis in third world countries who landed well paying jobs in FAANG thanks to the current process.