Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

261–270 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#261
post #145
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Even though even moderate background checking can filter these candidates out, it's quite time consuming and with the rise of generative AI... Good. I hope the whole hiring process gets blown up. The root cause of this is transactional hiring. Companies treat applicants like commodities, and now bad actors have found out how to game…

> I hope the whole hiring process gets blown up.

I can't see how the fake-candidate epidemic blows the hiring process up in anything but a candidate-hostile direction.

With the open hiring market becoming more inefficient, companies will move more towards hiring through networking and vetted sources (select college job boards etc.) rather than the open market. In situations where they evaluate candidates from open market listings, companies will now have invasive proof-of-identity red tape earlier and earlier in the funnel (for example, background checks prior to application rather than offer in places where that's legal). Plus, look forward to overly clever hiring panels introducing annoying "trap" questions and weird hoops like this article alluded to - I hope you're ready to review local restaurants and pick up random stuff in the room during your interview!

Re: We identified a North Korean hacker who tried to get a job

#262
post #69

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

Today’s bad startup idea:

Firm that looks like it is hiring for remote jobs, but is actually a honeypot that harvests credentials and identifiers that will enable our clients tondetect scam applicants.

Re: We identified a North Korean hacker who tried to get a job

#263

Earlier quoted context omitted.

Well they claim the final interview involved asking the candidate very specific questions about the town they claimed to be living in, and hold up government issued ID to the camera. My assumption based on this was they weren't certain it was someone malicious and they were double checking their own conclusion. If not it makes no sense to tip the candidate off that you're suspicious about them. At that point I'd say…

> Name 5 restaurants not on Google maps in the town you live in". I'm definitely a US based human and no way I get this right.

Not to mention that, as another commenter mentions, most serious candidates would get a question like this and nope out of the interview.

Re: We identified a North Korean hacker who tried to get a job

#264
> From the outset, something felt off about this candidate. During their initial call with our recruiter, they joined under a different name from the one on their resume, and quickly changed it. Even more suspicious, the candidate occasionally switched between voices, indicating that they were being coached through the interview in real time.

> Before this interview, industry partners had tipped us off that North Korean hackers were actively applying for jobs at crypto companies. We received a list of email addresses linked to the hacker group, and one of them matched the email the candidate used to apply to Kraken.

Unless you were working in conjunction with law enforcement (with some guarantee re: the security of customer assets), it should have ended there. Going further may have piqued your interest, but...

> Instead of tipping off the applicant, our security and recruitment teams strategically advanced them through our rigorous recruitment process – not to hire, but to study their approach.

... you likely gave them more actionable data than they gave you.

This behavior was reckless, amateurish and I'd be pulling out my assets right away if someone acting as a custodian to my finances acted like this.

Re: We identified a North Korean hacker who tried to get a job

#265

Earlier quoted context omitted.

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

> Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person?? You're dating yourself with that question. (yes, and they have been for a while)

The funniest interview I had, in a similar sneaky question, were the HR guy asked "so you wrote city X, I am also living here, whereabouts do you live?" and I turned the laptop and showed through my window a very unique skyscraper and a super marker right across my flat, and the guy recognized my building because his gf lived in the same building (had more than 100 flats), and we both had a laugh about it. (I got the job later but after having 2-3 more rounds of domain-specific interviews) Those days the "AI" was not around so I wouldn't be able to fake that even if I wanted.

EDIT: I also had interviews with Credit Suisse some years back (decade or so), they wanted me to speak to some people in the US and London, but didn't allow the video conference from home, but they asked me which major city in Europe I was in, so they book some meeting room in their own offices or some WeWork facility in case I was somewhere where they wouldn't have offices.

Re: We identified a North Korean hacker who tried to get a job

#267

Earlier quoted context omitted.

> Obviously you need documentation to work Elephant in the room, someone who can't produce photo ID to vote also can't produce it to work. So obviously you don't always need it to work (even if that's technically illegal). So long as the systemic issues remain I don't see an issue with that. Actually come to think of it the low skill jobs I had when I was younger never asked for ID. Just my social, full legal name, a…

Actually, that isn't the case with the SAVE act. If I produce a social security card and any government ID, that is typically enough to work (in the US). It won't be enough to vote under the proposed act. In many cases, what will be required is a birth certificate that exactly matches other ID. If your name has changed, unspecified documentation will be required beyond a marriage license or court approved name change…

Well that is even more ridiculous. I have a passport but I think I've lost track of my birth certificate. My state ID isn't even REAL ID compliant (and I am very happy about that fact - it's blatant federal overreach that badly needs to be snubbed).

But the point remains - you often (in practice) don't need ID for low skill jobs whereas high skill ones generally carefully vet you. Thus hand wringing about requiring applicants for a high end fully remote tech job to fork over ID is a bit silly.

Re: We identified a North Korean hacker who tried to get a job

#268
post #164

Earlier quoted context omitted.

80% of our recruiter's time is spent trying to figure out which candidates are real and which are fake. It's really, really bad. We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create We're extremely vigilant about th…

> We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create To me, what you call "red flags" rather looks like a description of often outstanding programmers who are quite privacy-conscious (think into the direction of "…

It can be both. Due to how much time the fake applications take throwing out privacy conscious candidates seems like a worthy sacrifice to make.

Re: We identified a North Korean hacker who tried to get a job

#269
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

>>Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person??

Yeah, absolutely. The company I work for is in a different country, seeing anyone else would require flying over there, I interviewed and got the job without meeting anyone in person.

Re: We identified a North Korean hacker who tried to get a job

#270

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.

People tend to only interact either the process when they're looking for work, so rarely. The north Koreans do it everyday and optimize the process. It's like captchas where the bots have surpassed human skill.
Post reply on HN