On a serious note, as a Kraken customer, I am very happy that they take security issues seriously. Reassuring.
We identified a North Korean hacker who tried to get a job
231–240 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#232Earlier quoted context omitted.
> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…
> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…
Re: We identified a North Korean hacker who tried to get a job
#233Earlier quoted context omitted.
> I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? I have no clue whether the proposed approach works, but there's a pretty coherent model that explains how it could , no schizophrenia needed: They are competent people in a cult. Being unable/unwilling to diss Dear Leader even when it's advantageous to do so is very typical cu…
So you're saying NK agents are completely different to, say, Soviet era agents, who could and would say anything as long as it furthered their mission? Ok, fair enough. In common perception of NK, they do seem bizarre, not like the Soviets during the Cold War. I think it's unwise to dismiss them as lunatics incapable of deceit. If I were a NK agent, I'd work towards this notion, "NK are incapable of lying if it would…
I mean, I totally agree that this should not be relayed as a working method to identify spies haha. Just that it’s not beyond believability it’d work in some circumstances.
Re: We identified a North Korean hacker who tried to get a job
#234Earlier quoted context omitted.
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…
Is the issue skilled candidates that are misrepresenting where they live, unqualified candidates with fake resumes trying to land the position anyway, or something else?
What have you tried?
If they trip enough red flags and it's an international issue, you could just be up front that you're suspicious (including why) and ask them to go outside and take a video of themselves in front of wherever they live. Then you check it against street view, scrutinize the vegetation, that sort of thing. Require the rest of the interview process to be via video call with a wide view of the room to ensure it's the same person. That solution is respectful of their time since it's quick and easy for them. They also presumably already shared their address with you so it's not particularly invasive.
Re: We identified a North Korean hacker who tried to get a job
#235They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
Re: We identified a North Korean hacker who tried to get a job
#236Earlier quoted context omitted.
I am saying they are both a credible threat and many are amateurs. Those are not mutually exclusive. You are talking about North Korea attackers from a theoretical point of view. For many people dealing with them is just a normal part of work. It's not an unknown that needs to be worked out logically from an armchair. I'm saying this as someone who personally chatted with a North Korea persona that later tried to dro…
I don't consider screenshots evidence of anything, so I'll completely disregard that bit. I'm curious about your personal experience though. Did you try this tactic, and did it work? And how sure are you these weren't random hackers or trolls, but actual NK agents? > many are amateurs So basically this would only get rid of the amateurs, low hanging fruit that would have been caught soon enough anyway, and do a "natu…
"Agents" is way too big of a word. Just cogs in a corporate theft machine.
There's a lot of reasons I'm sure, but the biggest is because before a hack they asked for help doing something simple with a crypto address that was later used to test run the 50 million dollar theft that was North Korea. And also trying to drop North Korean linked malware is another data point.
This also hits my point about both dangerous and amateurs. They pulled off pretty sophisticated heist but, had to ask for help, asked for help using a crypto address tied to the theft, and blew the cover on an identity they had been building up for a year.
Here's a twitter thread I put together of both my conversation and others with this particular account:
Re: We identified a North Korean hacker who tried to get a job
#237Earlier quoted context omitted.
> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.
80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…
Re: We identified a North Korean hacker who tried to get a job
#238They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
This sounds unnecessarily dismissive. It was a quick and interesting read, and there are some useful data points for every company that is hiring to improve their processes.
Re: We identified a North Korean hacker who tried to get a job
#239They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
Because I got no explanation the potential reasons for my rejection rolled over in my head. I finished the exam to the best of my ability - was my ability just not good enough? If I went to e.g. the library or something to hunt for a station with webcams in time would I have not come off so suspect?
Since then I've gotten no other interview offers elsewhere and feel like a moron for blowing my one chance last month over such a stupid coincidence, if it really was the case they rejected me for thinking I was some kind of corporate spy. It really was the definition of "too good to be true." I will now pay way more attention to how I appear to the interviewer from now on, and carry extra devices/webcams in case the worst happens.
Re: We identified a North Korean hacker who tried to get a job
#240Earlier quoted context omitted.
> What bothers me more is there are talented people sitting on unemployment right now that can't find a job, yet fake people are getting hired left and right. Something in the industry as a whole is quite broken. It IS "broken" by design as employers just don't want to go through the effort into finding great candidates (even if they are truly exceptional) and now it is even easier for candidates to cheat it thanks t…
Even at small startups, posting engineering jobs will get you hundreds of applications a day. There's simply no way for employers to fairly go through them. LinkedIn et al make everything worse by making the application process so easy. If you're a small company, the fix is to outsource the top of your funnel to a recruiting company you trust. If you're a medium or large company, the fix is to require on-site work.
Sure there is. Randomly sample N, filter down to M, go through preliminary interview stages. Depending on how many that leaves you with rinse and repeat.
The important thing here isn't fairness from the perspective of the applicant. It's a process that works reliably for the company and doesn't unfairly waste applicant's time.
If the very first stage (application plus resume) is no longer a reliable signal then accept that fact and rework the process to match.