Earlier quoted context omitted.
If I don't assist NK then I'm tacitly assisting the crypto industry. We're in trolley problem territory now.
Is multi-track drifting an option?
We identified a North Korean hacker who tried to get a job
251–260 of 309 posts
Re: We identified a North Korean hacker who tried to get a job
#252Earlier quoted context omitted.
> Advocating that the state's monopoly on violence be employed to prohibit people from using this technology is incredibly illiberal. I simply don't care anymore. Cryptocurrency's value is as a cultural shibboleth to identify individuals who deserve social interaction.
This is really not a constructive comment to make. This is going to ignite a flame war.
Re: We identified a North Korean hacker who tried to get a job
#253Earlier quoted context omitted.
Yep. It started with COVID where understandably 100% of interviews were remote. But now with COVID a thing of the past, for "fairness" reasons (DEI?) we still do 100% remote interviews, but now have the ludicrous situation where we're asking interviewers to do absurd things like look for the reflections in the candidates' eyes/glasses to see if they're using ChatGPT, ask the candidate to swing the webcam around to ma…
COVID isn't in the past, just no one doing anything about it. :)
Re: We identified a North Korean hacker who tried to get a job
#254Earlier quoted context omitted.
> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…
If your position is remote, and the coat of every in person interview includes two way flights, per diem and a hotel room, it's very tempting to skip the in person step, especially if you expect to fail a lot of in person candidates. Imagine paying that much when your interview to offer rate is 25%, and offer to hire is 50%. That $8k $10k extra per hire, on top of the normal cost of the funnel
Re: We identified a North Korean hacker who tried to get a job
#255Earlier quoted context omitted.
> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…
> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…
You're dating yourself with that question. (yes, and they have been for a while)
Re: We identified a North Korean hacker who tried to get a job
#256Earlier quoted context omitted.
80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…
Don't you have to ask for ID at the end anyway? So the only question is avoiding behavior that makes it look like you're a fake job listing harvesting PII or something. Is the issue skilled candidates that are misrepresenting where they live, unqualified candidates with fake resumes trying to land the position anyway, or something else? What have you tried? If they trip enough red flags and it's an international issu…
Re: We identified a North Korean hacker who tried to get a job
#257Earlier quoted context omitted.
> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…
If your position is remote, and the coat of every in person interview includes two way flights, per diem and a hotel room, it's very tempting to skip the in person step, especially if you expect to fail a lot of in person candidates. Imagine paying that much when your interview to offer rate is 25%, and offer to hire is 50%. That $8k $10k extra per hire, on top of the normal cost of the funnel
So… you mean the way it's been done for the last hundred years?
If your company is so small that you can't afford to bring someone in, then you hire locally.
Also, $8-10k per hire is too much for an interview. We do ours for under $1,000 with round-trip airfare, hotel, and meals. It's always the last step before signing.
Personally, I wouldn't feel comfortable working for a company that didn't bring me in for an in-person interview, even for a remote job. It's just as important for me to evaluate the company as it is for them to evaluate me.
Re: We identified a North Korean hacker who tried to get a job
#258Earlier quoted context omitted.
I had a colleague doing this in 2006, and he wasn't remote. He would just sit playing games on his phone all day yet he would check in code. I could never figure it out, so I just asked him and he showed me the chat window to his friend back in the Czech Republic that he paid 25% of his wages to each month.
I'm not sure I'm really against this! --IF-- the company is happy with the results and code being delivered, and the compensation they are paying for that code, what is the actual, meaningful business difference between whether your colleague wrote it or the Czech guy wrote it? I'm not asking what the moral or ethical difference is. They're paying for engineering output, and if they are getting that output, why does…
At the same time, you are correct that it doesn't matter who is typing it. One of my favorite setups I've worked under is where throwing it over the fence is explicit - where a small team of employees each has their own small team of contractors. The management doesn't care who does what, as long as the work gets done, so we were free to parcel work out to our contractors as we saw fit, and that the institutional knowledge stayed baked into our heads.
Re: We identified a North Korean hacker who tried to get a job
#259They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…
More like the whole system...
Re: We identified a North Korean hacker who tried to get a job
#260Earlier quoted context omitted.
> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…
> Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person?? You're dating yourself with that question. (yes, and they have been for a while)