Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

241–250 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#241

Earlier quoted context omitted.

“These people (crypto industry) are bad people so it is justified to ignore the rule of law when hurting them” is a classic bad take. What you can do is regulate crypto into oblivion and make people feel bad about working in crypto. If you assist NK, then you’re hurting crypto but you’re funding NK operations (e.g. NK soldiers assisting Russia against Ukraine).

Cryptocurrency is just a technology to give people the means to generate assets, and transfer them, themselves. Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. Regulation is just repression, rebranded.

I was with you until that final sentence. Regulation can be used for repression but it's also an essential part of any large scale real world system.

Re: We identified a North Korean hacker who tried to get a job

#242

Earlier quoted context omitted.

I can think of a few reasons, most obviously that it's a security nightmare - you've got a non-employee accessing and modifying your company's code and possibly having access to customer data. Some shops might not care about this, but it's ridiculously irresponsible in principle.

What if, instead, the guy was 100% honest and up front about it, and offered to enroll the Czech guy in all security checks that any other contractor would get, and treat them legally as any contractor would be treated? I wouldn't see anything wrong with this, but I would be willing to bet that 99% of companies would not go along with it--for reasons I'm not sure I understand.

The main problem is at that point the US guy is operating outside the model of being a direct employee of the company. He's operating as a contracting vendor.

There's legal aspects to the employer-employee relationship that are different than the company-vendor relationship.

Even reporting the pay to the IRS as personal income would probably be legally problematic, because from a legal aspect a vendor is being paid for a service not an individual receiving income from an employer.

Re: We identified a North Korean hacker who tried to get a job

#243
post #200

Earlier quoted context omitted.

I don't consider screenshots evidence of anything, so I'll completely disregard that bit. I'm curious about your personal experience though. Did you try this tactic, and did it work? And how sure are you these weren't random hackers or trolls, but actual NK agents? > many are amateurs So basically this would only get rid of the amateurs, low hanging fruit that would have been caught soon enough anyway, and do a "natu…

> And how sure are you these weren't random hackers or trolls, but actual NK agents? "Agents" is way too big of a word. Just cogs in a corporate theft machine. There's a lot of reasons I'm sure, but the biggest is because before a hack they asked for help doing something simple with a crypto address that was later used to test run the 50 million dollar theft that was North Korea. And also trying to drop North Korean…

Thanks for the reply, I'll take a look!

Do you think asking them to say something offensive about Kim Jong Un would have outed them?

Re: We identified a North Korean hacker who tried to get a job

#244
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

I did not get hired without in-person interview, but a number of my team members (certainly people I interviewed and recommended for hire) did.

Re: We identified a North Korean hacker who tried to get a job

#246
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

Last company that hired me did everything remotely. This was in a company that only hired people living in countries where it had offices and no b2b contract so there are a number of things that needed to be local: - local ID or work permit - physical address in the country - bank account in same country - social security number

Stuff can be forged but that needs local spy level of skills to make it work.

They were also hiring a company specialized in background checks, I literally had to fill up a form with the 14 places I had been living in all my life with dates of entry and exit, super annpying given the UI was slow as hell and that I had low recollection of addresses and date of my early years, I had to ask my parents. I may have been able to cheat probably but I didn't try.

I am also seeking a new position and I have realized that most b2b / work from anywhere jobs you could apply for were for cryptocurrencied / blockchain related companies so they surely make it easier for malicious remote applicants. I think it means they are kind of desperate / have difficulty to find talents. In other areas most companies only hire people who live in same juridiction they have an office and hr department.

Re: We identified a North Korean hacker who tried to get a job

#247
post #171

Earlier quoted context omitted.

I think the best interview question, and really the only one you need to determine technical ability is ask someone to describe a http request in as much detail as possible. To write code (even with the benefit of AI) effectively you need a mental model of the systems you work with, reading the chatGPT response doesn't prove you have that.

That's a stupid interview question for the vast majority of software jobs. Many people don't work with HTTP or web software at all.

So replace it with something from the relevant field.

Re: We identified a North Korean hacker who tried to get a job

#248

Earlier quoted context omitted.

The reason it is political for voting is that the rules needed to get a qualified ID are often impossible (or hard enough to suppress voting) for many legit voters. These rules have become weaponized in a culture war, such as the requirement that an ID match the name on the birth record, meaning women whose last names changed during marriage require additional paperwork, often crossing state lines and in person visit…

> Obviously you need documentation to work Elephant in the room, someone who can't produce photo ID to vote also can't produce it to work. So obviously you don't always need it to work (even if that's technically illegal). So long as the systemic issues remain I don't see an issue with that. Actually come to think of it the low skill jobs I had when I was younger never asked for ID. Just my social, full legal name, a…

Actually, that isn't the case with the SAVE act.

If I produce a social security card and any government ID, that is typically enough to work (in the US).

It won't be enough to vote under the proposed act. In many cases, what will be required is a birth certificate that exactly matches other ID. If your name has changed, unspecified documentation will be required beyond a marriage license or court approved name change. A government issued ID such as military or REAL ID will not suffice.

Re: We identified a North Korean hacker who tried to get a job

#249

In 2024 i’ve conducted a lot of interviews to recruit some frontend and backend engineers in full remote roles. And at one point i was getting a lot of candidates with european names, no picture, good resume. And when I met them over a call it was very strange: they were all asian(with really typical nordic names), they were like clones in the way they talked and answered questions exactly the same. They also claimed…

their strategy honestly says a lot of crazy things about their worldview

What do you mean by this (genuinely curious).

Re: We identified a North Korean hacker who tried to get a job

#250

Earlier quoted context omitted.

There's always that guy on X who posts about having n remote jobs at the same, waiting to be fired from each so that he can replace its slot with another. Then next year it's a different guy, same schtick.

I’ve also seen some claim that they will do that and simply sub-contract the work out to cheaper labor If the employer is satisfied with the employees output, who is being harmed?

A company that is indemnifying their customers for security lapses perhaps?

Or a company that is handling HIPAA, GDPR or other sensitive data and is certifying that they are following policies around employee training, data sovereignty and document handling?

Post reply on HN