Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

221–230 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#221

Earlier quoted context omitted.

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

Cryptocurrency is just a technology to give people the means to generate assets, and transfer them, themselves. Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. Regulation is just repression, rebranded.

> Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal.

I simply don't care anymore. Cryptocurrency's value is as a cultural shibboleth to identify individuals who deserve social interaction.

Re: We identified a North Korean hacker who tried to get a job

#222

Earlier quoted context omitted.

I can think of a few reasons, most obviously that it's a security nightmare - you've got a non-employee accessing and modifying your company's code and possibly having access to customer data. Some shops might not care about this, but it's ridiculously irresponsible in principle.

What if, instead, the guy was 100% honest and up front about it, and offered to enroll the Czech guy in all security checks that any other contractor would get, and treat them legally as any contractor would be treated? I wouldn't see anything wrong with this, but I would be willing to bet that 99% of companies would not go along with it--for reasons I'm not sure I understand.

If they were ok with doing the work to bring in the overseas person in the first place why should they hire their onshore cutout? To do it legally would be a whole mess of getting involved in business in a new country.

Re: We identified a North Korean hacker who tried to get a job

#223

Earlier quoted context omitted.

> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.

There's always that guy on X who posts about having n remote jobs at the same, waiting to be fired from each so that he can replace its slot with another. Then next year it's a different guy, same schtick.

I’ve also seen some claim that they will do that and simply sub-contract the work out to cheaper labor

If the employer is satisfied with the employees output, who is being harmed?

Re: We identified a North Korean hacker who tried to get a job

#224
"During their initial call with our recruiter, they joined under a different name from the one on their resume, and quickly changed it."

The article could have been this short.

This article also helps the Korean hackers by providing in depth commentary on how they were caught and how to improve.

Re: We identified a North Korean hacker who tried to get a job

#225
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

Yes, I am in a hybrid role, went through 5 interviews and several more check-ins, and the first time anyone saw me in person was on the first day when I picked up my laptop at the local office (which wasn't even required, I had the option of having it shipped at my home address)

Re: We identified a North Korean hacker who tried to get a job

#226
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

If your position is remote, and the coat of every in person interview includes two way flights, per diem and a hotel room, it's very tempting to skip the in person step, especially if you expect to fail a lot of in person candidates. Imagine paying that much when your interview to offer rate is 25%, and offer to hire is 50%. That $8k $10k extra per hire, on top of the normal cost of the funnel

Re: We identified a North Korean hacker who tried to get a job

#227

Earlier quoted context omitted.

Why has asking for photo ID become politicized. ID for voting and job interviews seems like some of the most reasonable usage for an official ID.

The reason it is political for voting is that the rules needed to get a qualified ID are often impossible (or hard enough to suppress voting) for many legit voters. These rules have become weaponized in a culture war, such as the requirement that an ID match the name on the birth record, meaning women whose last names changed during marriage require additional paperwork, often crossing state lines and in person visit…

> Obviously you need documentation to work

Elephant in the room, someone who can't produce photo ID to vote also can't produce it to work. So obviously you don't always need it to work (even if that's technically illegal). So long as the systemic issues remain I don't see an issue with that.

Actually come to think of it the low skill jobs I had when I was younger never asked for ID. Just my social, full legal name, and date of birth for their tax paperwork. Whereas the higher skill ones I had later demanded multiple forms of ID - I generally furnished them with both my passport and driver's license, which they took copies of and independently verified.

None of that is relevant for a high skill 100% remote job though. Not only does that demographic generally have easy access to ID, those rules really should be strictly enforced for remote positions since the internet is global.

Re: We identified a North Korean hacker who tried to get a job

#228

Earlier quoted context omitted.

Even at small startups, posting engineering jobs will get you hundreds of applications a day. There's simply no way for employers to fairly go through them. LinkedIn et al make everything worse by making the application process so easy. If you're a small company, the fix is to outsource the top of your funnel to a recruiting company you trust. If you're a medium or large company, the fix is to require on-site work.

This isn't really a new problem. I remember back during a previous tech downturn, the small-ish (~200 people) no-name company I worked for also got hundreds of applications a day. Yes, today, fake candidates and AI make it worse, but fundamentally the "huge number of people in the top of the funnel" problem has been a thing for a long time.

I was mostly replying to this bit:

> employers just don't want to go through the effort into finding great candidate

The notion that employers can put in the effort to give every candidate a totally fair shot so they can find the best ones is, I think, wrong, let alone the notion that they could but choose not to.

At my last company, we would have needed more people doing application reviews and interviews than we actually had employees if we wanted to do that.

Hell, I remember in college applying for a stock job at the local liquor store. When I went to hand in the application, I was told to put it on the pile- a stack of filled out applications thicker than several of my textbooks put together, suspiciously placed at the edge of a desk right next to a trash can.

Re: We identified a North Korean hacker who tried to get a job

#229
post #105

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken. It IS "broken" by design as employers just don't want to go through the effort into finding great candidates (even if they are truly exceptional) and now it is even easier for candidates to cheat it thanks t…

I wouldn't necessarily say that employers don't want to put in the effort. They put in a lot of effort, but employers direct the effort towards the process rather than the results.

I've been through multiple rounds of interviews with some companies with no end in sight, as many people have. I refer to the endless number of interview rounds as an obsession with process because employers tend to think that the more they evaluate people, the better result they get, regardless of how useful the processes they subject applicants to are. I've generally found people to be going through motions more than anything else, and the additional process is just more work that is not particularly useful to evaluate the candidates. It's still a lot of effort for both the employer and applicants.

That said, I do agree wholeheartedly that they should direct their efforts more towards the result of hiring a good candidate rather than just falling back to blind devotion to some series of processes to weed people out. They should focus on getting the most meaningful bit of information at each round to eliminate the most candidates possible, kinda like a form of optimal experimental design [1] if you are familiar with that term.

[1] https://en.wikipedia.org/wiki/Optimal_experimental_design

Re: We identified a North Korean hacker who tried to get a job

#230

Earlier quoted context omitted.

Cryptocurrency is just a technology to give people the means to generate assets, and transfer them, themselves. Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. Regulation is just repression, rebranded.

> Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. I simply don't care anymore. Cryptocurrency's value is as a cultural shibboleth to identify individuals who deserve social interaction.

This is really not a constructive comment to make. This is going to ignite a flame war.
Post reply on HN