Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

261–270 of 534 posts

Re: I almost got hacked by a 'job interview'

#261

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

I think it only really has that feel if you use GPT. I mean, all AIs produce output that sounds kinda like it was written by an AI. But I think GPT is the most notorious on that front. It's like ten times worse.

So really the feeling I get when I run into "obviously AI" writing isn't even, "I wish they had written this manually", but "dang, they couldn't even be bothered to use Claude!"

(I think the actual solution is base text models, which exist before the problem of mode collapse... But that's kind of a separate conversation.)

Re: I almost got hacked by a 'job interview'

#263
post #255

Earlier quoted context omitted.

Maybe I should implement this as a weed out question during interviews. If the applicant is willing to download something without questioning it, then the interview can be ended there. Don't need someone working with me that will just blindly install anything just because.

Bad idea. Competent candidates might also disqualify you as employer right there. Plus you'll be part of normalizing hazardous behavior.

strong disagree. it's very similar to anti-phishing training/tests. also, being tagged as a company that cares that its potential new hires are not lazy programmers that just copy&paste because someone told them too would more than likely be taken as a positive not a negative.

Re: I almost got hacked by a 'job interview'

#265
post #225

Earlier quoted context omitted.

I think it's a real company. https://search.sunbiz.org/Inquiry/CorporationSearch/SearchRe... ~~Scammers probably got access to the guy's account.~~ (how to make strikethrough...) He changed his LinkedIn to a different company. I guess check verifications when you get messages from "recruiters."

On LinkedIn can’t you create an account and claim to be an employee of any company? They don’t do email verification to make you prove employment do they?

They do if you want it to be “verified” (at least at bigger places) but I don’t know about smaller places or how people even check that.

Re: I almost got hacked by a 'job interview'

#266
post #255

Earlier quoted context omitted.

Bad idea. Competent candidates might also disqualify you as employer right there. Plus you'll be part of normalizing hazardous behavior.

strong disagree. it's very similar to anti-phishing training/tests. also, being tagged as a company that cares that its potential new hires are not lazy programmers that just copy&paste because someone told them too would more than likely be taken as a positive not a negative.

It's also a disingenious shit test which doesn't reflect well on team culture. Pass.

> it's very similar to anti-phishing training/tests

With the crucial difference that the candidate is someone external who never consented to or was informed of this activity.

Re: I almost got hacked by a 'job interview'

#267

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?” “Not fancy security tools. Not expensive antivirus software. Just asking my coding assistant…” I actually feel like AI articles are becoming easier to spot. Maybe we’re all just collectively noticing the patterns.

It's also exactly the type of writing you see on LinkedIn (yuck), so this article really goes full circle!

Re: I almost got hacked by a 'job interview'

#268
post #266

Earlier quoted context omitted.

strong disagree. it's very similar to anti-phishing training/tests. also, being tagged as a company that cares that its potential new hires are not lazy programmers that just copy&paste because someone told them too would more than likely be taken as a positive not a negative.

It's also a disingenious shit test which doesn't reflect well on team culture. Pass. > it's very similar to anti-phishing training/tests With the crucial difference that the candidate is someone external who never consented to or was informed of this activity.

it's much better than asking why a soap bubble is round

Re: I almost got hacked by a 'job interview'

#269

Earlier quoted context omitted.

It’s not like there aren‘t dozens of companies with real funding that try to „tokenize real estate“. I mean if that’s a good idea idk, but that means there IS real money to be made working at such companies.

Eh, it would be nice if there was a public title database in the US. Ideally government administered, but if we can't have that then maybe a distributed ledger would do the trick. It's hilarious that title searches and title insurance exist. And even more ridiculous that there is just no way, period, to actually verify that a would-be landlord is actually authorized to lease you a place to live.

It’s that funny intersection where abstractions meet the real world. We assume that the guy with the keys collecting the rent checks is authorized to lease it out because it’s just too expensive to assume otherwise. But sometimes that assumption is wrong and man, what a mess that turns out to be.

Similarly, it’s like if I get back to my house tonight and someone has changed the locks on the front door, I’m pretty sure I could ultimately verify that, yes, I’m the owner, but I sure am glad that due to social norms or inertia or the sheer hassle of being a squatter that is not something I have to deal with on a regular basis.

Re: I almost got hacked by a 'job interview'

#270
post #258
post #251

Earlier quoted context omitted.

I just spin up an EC2 instance for the interview

That's the right approach. On the other hand, do you even want to participate in a scam interview?

Even for legit interviews I don’t want all the random NPM dependencies they’re using running on my computer
Post reply on HN