Earlier quoted context omitted.
>I finally got it solved by buying drinks for a buddy of mine that works for LinkedIn I'd like people to understand that this is a form of corruption. We've normalized many like it. LI knows that the only way to force them to fix the issue is to go through a drawn-out legal process, save a spate of bad press (RIP 60 Minutes), so of course they won't.
I agree with you. I used to work for an ISP that sold kind-of overpriced 1Gbps connections and always wondered why customers bought it. Probably helping things was that we took them out to "events", floor seats at basketball, etc. The company just has a fixed expense, but the people making the decision get free stuff that makes them feel important, and it was kind of a way of transferring the company's money (by not…
A backdoor in a LinkedIn job offer
171–180 of 331 posts
Re: A backdoor in a LinkedIn job offer
#172So, this is a crime right? Why isn't there a well known '911' for cybercrime to report things like this to and get help? Society needs to catch up with the actual dangers out there and build support networks for this ASAP. This is organized crime and needs organized defense to deal with it.
To put it bluntly and perhaps a bit cynically, on the tree of bad things that people do to other people, this is pretty high-hanging fruit. Right up there next to scam phone calls that prey on the elderly while claiming to be from Microsoft support. It's basically impossible to catch suspects because they are either smart enough to cover their tracks very well, or (more often) live in countries whose governments don'…
US was so angry about "unfair" tariffs why are they not angry about criminals stealing from Americans?
Re: A backdoor in a LinkedIn job offer
#173Earlier quoted context omitted.
This is a real world trolley problem scenario. You can break workflows or you can let everyone get pwned by supply chain attacks. Which is the greater harm?
People will not adopt a safer version if it broke their workflows. Adoption is part of preventing supply chain attacks.
Re: A backdoor in a LinkedIn job offer
#174Earlier quoted context omitted.
LinkedIn offers no way for $company to disavow users who claim to work for $company - they will appear on the official company page as long as it's in their profile. We've had fake recruiters that claim to work for us running basically the same scam. These are great fake profiles: LinkedIn Premium, tons of relevant posts, etc... but they don't work for us, and we get angry messages from people saying our recruiter tr…
My last 2 companies, LinkedIn asked me to add an email address associated with the said company and actually confirm via said email in order to add them to my profile. So, if I worked for FooCompany, I had to have a @FooCompany.com email which is setup by someone at the company itself. Does this not cover what you're talking about?
How would LinkedIn validate that your email domain belongs to the company you claim to work for?
Re: A backdoor in a LinkedIn job offer
#175Re: A backdoor in a LinkedIn job offer
#176Earlier quoted context omitted.
According to my research, LinkedIn only does this for executive and now recruiter-like titles, but not broadly. You may be able to in order to get "verified on LinkedIn" but it's not a requirement for showing association with a company. https://www.theverge.com/news/771210/linkedin-recruiter-exec...
I'm bottom of the ladder but have seeing the option to do it for at least a year.
Re: A backdoor in a LinkedIn job offer
#177This is uncomfortably close to a normal interview task now. Someone sends you a repo, says the install is broken, and asks you to take a look. A lot of developers would run rpm install before thinking twice, especially if they were tired or looking for work.
The interview context makes it worse. You’re trying not to look slow, so you skip the part where you ask whether you should run it at all.
Re: A backdoor in a LinkedIn job offer
#178"Recruiters" are getting sophisticated. I spoke on the phone with "Singapore based recruiters" a couple of times who wanted my services as a consultant for "advanced applications for semiconductor devices." Turns out they were just fishing for inside information on my employer's end customer's applications.
Just a thought, but no call to action from me.
Re: A backdoor in a LinkedIn job offer
#179I'm working 3 remote jobs right now and I can tell you guys to really watch out. Often they are not malicious, just unsavory business practice where they want free consulting with no intention of hiring you. Another tell is the person is quick to jump to a take home screening project and they are quite good at getting at engineers heads that "leetcode is outdated/they dont believe in it" and whatever they want you to…
> Don't stay honest to those don't value it. IMO you are either honest or you are not
Re: A backdoor in a LinkedIn job offer
#180This is the part that really irks me: LinkedIn and Github know this is the end goal of many of the rampant supply chain attacks but they a) don't have a first class mechanism for reporting b) don't seem to be improving their systems or even warning people. I have been hit be this enough times that I follow along to get screenshots of the scammer. One might think with all the surveillance systems Microsoft/LinkedIn/Github/Google-Meet/Calendly have in place that a potential victim reporting it along with an actual picture of the scammer could get us somewhere.