Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

201–210 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#201
post #168

Earlier quoted context omitted.

I don't think this has anything to do with remote vs. onsite work. It has more to do with remote vs. onsite interviews . A thorough onsite interview should catch all of these fake candidates. Companies should be doing at least one onsite interview regardless of whether the role itself is remote or onsite.

A very easy way to verify a remote candidate's identity is to buy them a plane ticket to an in person interview. If they cannot board a plane using their claimed identity from their claimed city of origin, you can stop there.

Easy, but expensive way.

Are you really going to do this for all candidates that make it to the final round of interview?

Are you also going to compensate the time for the candidate if he doesn't get selected?

Unless what you're proposing is more a formality, and that unless the person doesn't show up he's guaranteed to get the job.

Re: We identified a North Korean hacker who tried to get a job

#202

Earlier quoted context omitted.

The advantage of a larger pool of candidates is not mostly a financial benefit, IMO. The benefit is mostly the ability to hire from a larger pool of people especially with a specialized skillset, and also to have less of an echo chamber. But yes, that directive to interview local candidates over zoom does seem very silly.

My experience is that yes it opens up the wider pool, but it makes the filtering process much more difficult in trade. Opening up the wider pool without the in person interview is where things hit the wall since the filtering criteria everyone learned over their careers went out the door thanks to the online interview process. And the online interview process is much more subject to cheating--not exactly a huge conce…

What is the local pool like?

If you want a software engineer silicone valley you can stay all local. There are companies in remote small towns who need a software engineer - they have to open up to non-local candidates as there are zero people in town who could do the job that don't work for them. There is always someone from elsewhere excited to move to a small town, but finding those people is hard. (and for those people finding a company that wants them is hard)

Re: We identified a North Korean hacker who tried to get a job

#203
post #134

Earlier quoted context omitted.

This isn't necessarily the issue here -- this attempt seemed to be fairly motivated and had access to resources (AI, coaches, ...) to help them get through the process. IF they can get such a 'candidate' hired... whats to say they couldn't continue the sham. One could imagine a team of hackers could easily pass of work that a single IC could reasonably have produced. If their goal is exfiltration (or some other hack)…

Do you not have regular calls with teammates? Sure I guess someone could physically turned up to an office to collect a laptop, be onboarded, get ID checked, then dial in to a few hours of meetings a week, muddle through any questions, rely on the team back at base helping, turn up in person to team get togethers every few months and manage to bluff their way through. It's not unprecedented - Frank Abagnale was runni…

Those regular calls is what limits how many places you can work for. You full time job becomes holding those calls, plus knowing just enough about the problem to sound intelligent. You can probably work 4 jobs this way.

Re: We identified a North Korean hacker who tried to get a job

#204
post #65

Earlier quoted context omitted.

I find this answer highly implausible, not the least because maintaining cover doesn't count as dissing ("I infiltrated the org by telling them the lies they wanted to hear" is hacking 101). Also, North Koreans aren't dumb. I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? > Dissing Kim is something that is not currently widely…

> I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? I have no clue whether the proposed approach works, but there's a pretty coherent model that explains how it could , no schizophrenia needed: They are competent people in a cult. Being unable/unwilling to diss Dear Leader even when it's advantageous to do so is very typical cu…

So you're saying NK agents are completely different to, say, Soviet era agents, who could and would say anything as long as it furthered their mission?

Ok, fair enough. In common perception of NK, they do seem bizarre, not like the Soviets during the Cold War.

I think it's unwise to dismiss them as lunatics incapable of deceit. If I were a NK agent, I'd work towards this notion, "NK are incapable of lying if it would diss their leader, that's how we get them!". In fact, I would spread this notion in Reddit, like the OP mentioned.

By the way, this still leaves the easy way out of "why are you asking about Kim Jong Un in a job interview, is it because I'm Korean? I'd like to speak to your HR department please".

Re: We identified a North Korean hacker who tried to get a job

#205

Earlier quoted context omitted.

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

If I don't assist NK then I'm tacitly assisting the crypto industry. We're in trolley problem territory now.

Is multi-track drifting an option?

Re: We identified a North Korean hacker who tried to get a job

#206

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken.

An entire country has dedicated significant resources to getting some of their hackers hired. Those talented people you mention are likely trying to get hired by themselves. It’s not an industry problem so much as a coordinated attack.

Re: We identified a North Korean hacker who tried to get a job

#207

In 2024 i’ve conducted a lot of interviews to recruit some frontend and backend engineers in full remote roles. And at one point i was getting a lot of candidates with european names, no picture, good resume. And when I met them over a call it was very strange: they were all asian(with really typical nordic names), they were like clones in the way they talked and answered questions exactly the same. They also claimed…

their strategy honestly says a lot of crazy things about their worldview

Re: We identified a North Korean hacker who tried to get a job

#208
post #151
post #139

Earlier quoted context omitted.

I’m not sure I know what you mean—I’m not sure I’d want to discuss the specifics of my living environment here though. Would you have any examples handy?

If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE. It's just like the bar scene in Inglorious Bastards, with the fingers…

> If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE.

A counterstory: When my former boss started at the company, for the first years [!] he only "knew" very specific places (office, appartment, and one or two places associated with intensely practiced hobbies of him) in the city where the company is located, and basically lived inside the bubbles associated with these places and their surroundings.

Thus, to me it is very plausible that even if you lived in a city for many years, it is very easy to live in very isolated bubbles, and have barely any contact to people and their habits outside these bubbles.

Re: We identified a North Korean hacker who tried to get a job

#209

Earlier quoted context omitted.

If this harms the crypto industry even a little I'm not sure I'd feel even a twinge of sympathy. Is there anything I can do to assist NK in these affairs?

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

Cryptocurrency is just a technology to give people the means to generate assets, and transfer them, themselves. Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal.

Regulation is just repression, rebranded.

Re: We identified a North Korean hacker who tried to get a job

#210

Earlier quoted context omitted.

The advantage of a larger pool of candidates is not mostly a financial benefit, IMO. The benefit is mostly the ability to hire from a larger pool of people especially with a specialized skillset, and also to have less of an echo chamber. But yes, that directive to interview local candidates over zoom does seem very silly.

My experience is that yes it opens up the wider pool, but it makes the filtering process much more difficult in trade. Opening up the wider pool without the in person interview is where things hit the wall since the filtering criteria everyone learned over their careers went out the door thanks to the online interview process. And the online interview process is much more subject to cheating--not exactly a huge conce…

I agree that there's a trade-off in filtering, but I really just don't resonate with this "cheating" issue.

I haven't run into this thing where I'm talking to a video AI, but maybe I'll sing a different tune if that ever happens and is high fidelity enough to trick me.

If "cheating" just means using AI assistants to answer my interview questions, honestly I think I've done a poor job structuring the question and interview.

I do recognize this as a giant challenge right now, to structure interviews in a way that provides real signal, while allowing candidates to use the tools they'll actually be using for the job. But I don't think the challenge is significantly different between remote and in-person.

Post reply on HN