Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

251–260 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#251
post #205

Earlier quoted context omitted.

If I don't assist NK then I'm tacitly assisting the crypto industry. We're in trolley problem territory now.

Is multi-track drifting an option?

Is that so that you can take out all of the people in the problem at once?

Re: We identified a North Korean hacker who tried to get a job

#252

Earlier quoted context omitted.

> Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. I simply don't care anymore. Cryptocurrency's value is as a cultural shibboleth to identify individuals who deserve social interaction.

This is really not a constructive comment to make. This is going to ignite a flame war.

They're in control and responsible for their responses. Blaming someone else for one's anger or overreaction is indicative of abuse. "You made me lash out," is simply not a mature way to live one's life.

Re: We identified a North Korean hacker who tried to get a job

#253

Earlier quoted context omitted.

Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…

COVID isn't in the past, just no one doing anything about it. :)

The 1918 Pandemic is still around, too... A/H1N1

Re: We identified a North Korean hacker who tried to get a job

#254

Earlier quoted context omitted.

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

If your position is remote, and the coat of every in person interview includes two way flights, per diem and a hotel room, it's very tempting to skip the in person step, especially if you expect to fail a lot of in person candidates. Imagine paying that much when your interview to offer rate is 25%, and offer to hire is 50%. That $8k $10k extra per hire, on top of the normal cost of the funnel

You could do the expensive bit as a last step before making an offer.

Re: We identified a North Korean hacker who tried to get a job

#255
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

> Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person??

You're dating yourself with that question. (yes, and they have been for a while)

Re: We identified a North Korean hacker who tried to get a job

#256
post #164

Earlier quoted context omitted.

80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…

Don't you have to ask for ID at the end anyway? So the only question is avoiding behavior that makes it look like you're a fake job listing harvesting PII or something. Is the issue skilled candidates that are misrepresenting where they live, unqualified candidates with fake resumes trying to land the position anyway, or something else? What have you tried? If they trip enough red flags and it's an international issu…

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#257

Earlier quoted context omitted.

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

If your position is remote, and the coat of every in person interview includes two way flights, per diem and a hotel room, it's very tempting to skip the in person step, especially if you expect to fail a lot of in person candidates. Imagine paying that much when your interview to offer rate is 25%, and offer to hire is 50%. That $8k $10k extra per hire, on top of the normal cost of the funnel

the co[s]t of every in person interview includes two way flights, per diem and a hotel room

So… you mean the way it's been done for the last hundred years?

If your company is so small that you can't afford to bring someone in, then you hire locally.

Also, $8-10k per hire is too much for an interview. We do ours for under $1,000 with round-trip airfare, hotel, and meals. It's always the last step before signing.

Personally, I wouldn't feel comfortable working for a company that didn't bring me in for an in-person interview, even for a remote job. It's just as important for me to evaluate the company as it is for them to evaluate me.

Re: We identified a North Korean hacker who tried to get a job

#258

Earlier quoted context omitted.

I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.

I'm not sure I'm really against this! --IF-- the company is happy with the results and code being delivered, and the compensation they are paying for that code, what is the actual, meaningful business difference between whether your colleague wrote it or the Czech guy wrote it? I'm not asking what the moral or ethical difference is. They're paying for engineering output, and if they are getting that output, why does…

Typically, employers expect more in return for your salary than engineering output - they pay for employees to be engaged with the business, learn it, become subject matter experts, so that their value over time increases and they deliver more than just the engineering. When all your need is engineering output, you hire contractors.

At the same time, you are correct that it doesn't matter who is typing it. One of my favorite setups I've worked under is where throwing it over the fence is explicit - where a small team of employees each has their own small team of contractors. The management doesn't care who does what, as long as the work gets done, so we were free to parcel work out to our contractors as we saw fit, and that the institutional knowledge stayed baked into our heads.

Re: We identified a North Korean hacker who tried to get a job

#259

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

>Something in the industry as a whole is quite broken.

More like the whole system...

Re: We identified a North Korean hacker who tried to get a job

#260

Earlier quoted context omitted.

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

> Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person?? You're dating yourself with that question. (yes, and they have been for a while)

it's not even a new thing, certain companies were doing it before the pandemic. for a long time. I took my first offer at a remote company in 2012 -- I only met any of those people by chance, years later.
Post reply on HN