Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

251–260 of 331 posts

Re: A backdoor in a LinkedIn job offer

#251
post #240

Earlier quoted context omitted.

Legally speaking, no - it would still be a criminal offence. Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it would probably depend on exactly what the situation was - there's a big of difference between targeted IRGC or defence systems and ransomwaring an Iranian hospital or scamming random cit…

What would happen if you honestly listed your earnings on your tax forms?

It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current diplomatic position (which changes by the hour), etc, etc. I don't think you can really get a simple answer for this kind of question.

Re: A backdoor in a LinkedIn job offer

#252
post #62

Earlier quoted context omitted.

KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure. This is on par with being unable to open a bank account if the capability is matured. I'd advise that you think long and hard about the consequences of this system being applied against you maliciously before signing on the dotted line.

> KYC just for a phone number opens the door for societal ostracization and essentially blacklisting of people from infrastructure. We have that in Europe and the world has not fallen apart. On top of that, we don't have even close to the scale of problems with scammers that the US has. I won't deny we don't have scammers because we absolutely have them, but they are far from the scourge they are in the US. > This is…

I'm in the US, I have two 20-year old phone numbers and 1 cell number, none ring through with span or scams.

I wonder why that is? I dont give the numbers out. That's why. Whenever a store says "do you gave a number with us" I say I don't have a cell phone. If they can plainly see I do have a cellphone, I add, "for that."

The second part is shopping at stores that dont tie prices to your having given them a number.

Re: A backdoor in a LinkedIn job offer

#253
post #208

Earlier quoted context omitted.

Unfortunately most evil cybercriminals know the "one weird trick" of "do your crimes in countries that don't care about the crimes"

Something I've always wondered, because I'm a bit of a contrarian and I wonder if we're really any different: Could an American citizen hack and steal from Iranians and Russians with impunity from America? The issues that prevent the US from extraditing Russians who hack us -- don't they work both ways?

As far as I know it has never happened. On the contrary, when Alejandro Caceres admitted to ddosing North Korea - taking down all their public websites for a week - he was questioned by the FBI who decided to take no further action.

https://www.wired.com/story/p4x-north-korea-internet-hacker-...

So hostile countries should be fair game for Americans who want a side-hustle. Plenty of Russian targets that could be profitable.

Re: A backdoor in a LinkedIn job offer

#254
Im not sure if anyone will read this, but I consider myself pretty savvy having been on the internet over decades however I nearly succumbed to a highly complex Linkedin "Interview with video call just to get me to install malware".

It was the most bizarely long roundabout way to get me to isntall malware I had ever witnessed I couldnt fathom it was real, I mean they interviewed me for half an hour. Now you might think Im paranoid however it was obvious, their camera was off ( personal preference they said) and well I allowed it... only for other eventual straws to breal the camels back, and I realised "oh uh oh this is just 2 strangers trying to get me to install crap on my laptop for wealth extraction".

I was flumoxed tbh I couldnt believe it, as the approach had been very organic, through Linkedin Dms, just that eventaully I realised I had succumbed to "yes men" ( the only thing that would get passed my already strict job filters ironically) to allow myself into such a comprimising situation.

The only question I had is how did they do such a smooth complex manouver and then I realised... oh they just used AI to come up with the plan and implementation.

Re: A backdoor in a LinkedIn job offer

#255
post #153

Earlier quoted context omitted.

> Don't stay honest to those don't value it. IMO you are either honest or you are not

If you are honest with people who don't want to hear the truth, you are going to be dishonest with people when they want the truth.

That doesn't follow.

Re: A backdoor in a LinkedIn job offer

#256

This type of attack has been happening a lot the past 2 years. I've seen one that was very well done...the GitHub account of a fairly well known security researcher had been compromised...their identity and code was being used as part of the recruitement. I reached out to the person...who was understandably embarrassed and told me they had reported this to LinkedIn + Github but saw no action. This is the part that re…

Call it a conspiracy theory, but I think a lot of these businesses actively avoid making serious efforts because even trying creates expectations. Ones that they don’t want to be on the hook for.

Like the Facebook problem. They were never in more trouble with people and legislators than when they were spending mountains of gold trying to police content.

It’s much easier to shrug and say, “Sorry folks, it’s the internet. Good luck.”

Re: A backdoor in a LinkedIn job offer

#257
post #44

Earlier quoted context omitted.

Hard disagree on the scam phone calls. It would be trivial to eradicate them almost completely if the phone operators did the bare minimum to fight against it. At any point in time, any given US phone number is handled by exactly one phone carrier. There is nothing stopping that carrier from requiring name and address to issue that phone number. They already do for 99.99% of their legitimate customers. It would be ve…

Number spoofing is not a solved problem because some carriers, which appear legitimate in all other respects, make a business out of routing your traffic over TDM trunks that don't support caller ID verification, and will claim it's extremely expensive to upgrade these to VOIP.

I'd be 100% happy to block those carriers from calling me. Their users should just get a message that calling my number is not supported and they should try calling me from another device.

Re: A backdoor in a LinkedIn job offer

#258

Earlier quoted context omitted.

I don't want to be cynical, but maybe spending hours every day using Claude has made some of us particularly attuned to picking this up. For some reason as soon as I read "The trap was in app/test/index.js," I instantly knew it was Claude. It's too bad, because there will obviously be some false positives, but it makes me immediately disregard the author.

I sometimes use the Claude app with text to speech enabled. It’s got a quite distinctive voice/tempo combo when it’s outputting speech. Whenever I see a typical Claude-tell in writing, my internal reading voice switches automatically from my internal monologue’s voice into Claude’s voice for the rest of the piece.

[dead]

Re: A backdoor in a LinkedIn job offer

#259
Hm, the url returns a png. Did he obscure the actual url? Couldn't get it to send me json or js...

Update: found a clone of the repo on github and got the payload, all you have to do is add a header `bearrtoken: logo`

It's obfuscated, I will feed it to qwen to see what can be gleaned.

Re: A backdoor in a LinkedIn job offer

#260
This is a common one. I've had at least half a dozen of them. If I'm bored, I play along, and then play difficult and dumb and see how long it takes until they give up.

Some of these will happily get on "interview" calls etc.

For some reason, most (but not all) of them have the same telltale signs of looking for someone to work on a web3/crypto gaming project.

Post reply on HN