Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

211–220 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#211
post #182
post #164

Earlier quoted context omitted.

80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…

maybe leave the photo id ask for when there's suspicion only is fine

Why has asking for photo ID become politicized. ID for voting and job interviews seems like some of the most reasonable usage for an official ID.

Re: We identified a North Korean hacker who tried to get a job

#213

Earlier quoted context omitted.

And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely? (I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)

Because job interviews don't test real-world programming skills, which is a whole other issue.

The closer you can get to doing so, the better.

Re: We identified a North Korean hacker who tried to get a job

#214
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

Yes, my fully remote company has been hiring for the past 3 months, I've conducted at least 70 first-round interviews, and we hire without in-person meetings.

Re: We identified a North Korean hacker who tried to get a job

#215
post #145
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI... Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game…

Hate to say it but jobs are commodities for the employee too. Why would it be any different the other way around?

So many roles are basically interchangeable and I’ll choose whichever one looks best on my resume or gives me some other tangible benefit. And I am prepared to bounce as soon as my vesting schedule drops. We all game this system too.

The days of us loyally working at any firm for 20 years, singing the corporate cheer songs and retiring with a pension are stuff of a different age.

Re: We identified a North Korean hacker who tried to get a job

#216
post #164

Earlier quoted context omitted.

> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.

80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…

Thank you for posting this. It definitely gives a lot of perspective about what is going on right now.

Re: We identified a North Korean hacker who tried to get a job

#217
This level of applicant checking at a financial institution does not inspire confidence.

At a previous remote job for a financial institution, they required a full background check with fingerprinting, reference checking, past employment verification, drug testing and in-person verification of identity and employment authorization. This was done for everyone, not just people they found "suspicious."

Frankly, the laws against applicant discrimination also makes having different processes or demanding different information from candidates because of national origin/ancestry/accent/etc. legally questionable.

Re: We identified a North Korean hacker who tried to get a job

#218
post #151
post #139

Earlier quoted context omitted.

I’m not sure I know what you mean—I’m not sure I’d want to discuss the specifics of my living environment here though. Would you have any examples handy?

If your resume says you live in NYC for example, and I do something like "Man, I went to NYC once and got stuck in traffic on that stupid highway that goes up and down the coast of Brooklyn, what was the name of that thing?" and they respond with I-278, that would raise red flags. I have never heard of anyone calling the I-278 anything but the BQE. It's just like the bar scene in Inglorious Bastards, with the fingers…

I had a candidate who said he lived in San Francisco, so I asked him what neighborhood, and he responded "Uh, by the Golden Gate Bridge." Cool.

Later I looked more closely at the resume and saw some more red flags, like, he had a degree from "CA State University" -- like, which of the 23 CSUs bro?

We did have a couple fake people make it to the final round, the last one was cheating and still bombing -- I sent a picture to the guy who did the second-round interview like "is this the Jason Smith you interviewed?" and he said "Lol, no"

Re: We identified a North Korean hacker who tried to get a job

#219
post #168

Earlier quoted context omitted.

A very easy way to verify a remote candidate's identity is to buy them a plane ticket to an in person interview. If they cannot board a plane using their claimed identity from their claimed city of origin, you can stop there.

Easy, but expensive way. Are you really going to do this for all candidates that make it to the final round of interview? Are you also going to compensate the time for the candidate if he doesn't get selected? Unless what you're proposing is more a formality, and that unless the person doesn't show up he's guaranteed to get the job.

By the time someone gets to the on-site interview, the job should be "theirs to lose." You wouldn't be spending the cost of an on-site trip for every candidate that shows some promise during the distance interviews--you'd do it for those very few you're ready to give offers to already, but just want to double check a few in-person soft-skills things (and now, want to double check that he is who he says he is).

Re: We identified a North Korean hacker who tried to get a job

#220
post #182

Earlier quoted context omitted.

maybe leave the photo id ask for when there's suspicion only is fine

Why has asking for photo ID become politicized. ID for voting and job interviews seems like some of the most reasonable usage for an official ID.

The reason it is political for voting is that the rules needed to get a qualified ID are often impossible (or hard enough to suppress voting) for many legit voters.

These rules have become weaponized in a culture war, such as the requirement that an ID match the name on the birth record, meaning women whose last names changed during marriage require additional paperwork, often crossing state lines and in person visits. Bingo, disenfranchised a large population of women.

Personally I think voting should be mandatory as some countries have done, and verification should be easy.

Obviously you need documentation to work, and it’s fair to gather that documentation as early in the process as is reasonable (as in when an application is submitted)

Post reply on HN