Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

271–280 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#271
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

> Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single person in person?

Yes, I got multiple job offers like that back in 2022 at FAANG and similar places, and a lot of my friends who interviewed recently had plenty of processes that were fully remote as well. The first time I’ve actually met someone irl from the company I signed my offer with was at least a month after I already started working, and it was just an optional lunch meetup.

However, afaik, these days most serious companies like big tech or tech-centric finance (JS/Citadel/Jump/etc.) or top AI places (OpenAI/Anthropic/etc.) would have the final rounds in-person.

Re: We identified a North Korean hacker who tried to get a job

#273
post #171

Earlier quoted context omitted.

That's a stupid interview question for the vast majority of software jobs. Many people don't work with HTTP or web software at all.

So replace it with something from the relevant field.

Yes, technical interview questions should be relevant to the job field. What's your point?

The hard part is selecting good questions that act as reliable predictors of actual job performance. Very few hiring managers can do that reliably, although many fool themselves into believing that they can.

Re: We identified a North Korean hacker who tried to get a job

#274

Earlier quoted context omitted.

> We post a role, get 500 applicants, and nearly all of them are not legitimate. They all look amazing, really great resume, impressive LinkedIn, etc... but when you dig a little deeper, it's not that hard to find a bunch of red flags (LinkedIn profile create To me, what you call "red flags" rather looks like a description of often outstanding programmers who are quite privacy-conscious (think into the direction of "…

It can be both. Due to how much time the fake applications take throwing out privacy conscious candidates seems like a worthy sacrifice to make.

On the other hand, consider that in this particular case, if you throw out a false positive, it is very often a really good programmer (though not necessarily the kind of programmer that big tech companies are looking for). :-)

Re: We identified a North Korean hacker who tried to get a job

#275
post #273

Earlier quoted context omitted.

So replace it with something from the relevant field.

Yes, technical interview questions should be relevant to the job field. What's your point? The hard part is selecting good questions that act as reliable predictors of actual job performance. Very few hiring managers can do that reliably, although many fool themselves into believing that they can.

The point is that someone gave a specific example of the much more general concept of probing for mental model by way of detailed explanation of a process he ought to be familiar with. You objected to the specific details - knowledge of HTTP. That's not an indictment of the general approach.

That said ML models have gotten to the point where I'd have to disagree with OP that this approach will necessarily filter their use. However there are plenty of available mitigations, from latency of response to requiring a video feed that fully covers the candidate, his screen, and his keyboard.

Re: We identified a North Korean hacker who tried to get a job

#276

I don't see anything about the guy being North Korean in the article. It's pure clickbait full of bragging about "our DNA". > Their resume was linked to a GitHub profile containing an email address exposed in a past data breach. How is it an indicator of anything? Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned.

> Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned. Which is why everyone needs to switch to passkeys. It's crazy that we still use passwords for authentication

Don't passkeys still have tons of vendor lock-in attached? A password I can put into any password manager I want and transfer it to a different password manager and neither the password manager company nor the company for which I made the account is any the wiser.

Re: We identified a North Korean hacker who tried to get a job

#277

Earlier quoted context omitted.

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

10 years ago all interviews were in person. With the pandemic they all went 100% remote. We proved that 100% remote positions can work and so there is temptation to continue doing 100% remote interviews for people that will be working remote anyway. Though we have been burned by someone we believe (but cannot prove) was 100% remote and working two jobs at the same time (they were laid off in a recent downsizing befor…

Wow, I guess my experiences are way unusual! Very interesting. Companies are really playing with fire by expecting to hire (either for remote or onsite work) 100% over the phone and videoconferencing.

Re: We identified a North Korean hacker who tried to get a job

#278
post #69

Earlier quoted context omitted.

> On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. They found this person at the top of the funnel, before they even started the process, and then chose to go through with it out of curiosity / for advertising. I personally think it's silly (I don't think the advertising or learning about some comically basic TTP like "interview coaching" was worth their…

> I will say that hiring for remote jobs has gotten to be a gigantic time waste lately. Not sure why this would be any different for remote jobs. All job interview processes (remote and in-office) I've ever done have had an in-person step, and that should be enough to filter these fake candidates, no? Are companies really doing 100% remote interviews, as in: you sign the offer letter without even meeting a single per…

I went couple times through fully remote projects. No in-person interviews, no team gathering during the project work.

However, there was a background check done by third party agency. Basic check: criminal record, education and employment history (is it fake or real).

Re: We identified a North Korean hacker who tried to get a job

#279
post #273

Earlier quoted context omitted.

Yes, technical interview questions should be relevant to the job field. What's your point? The hard part is selecting good questions that act as reliable predictors of actual job performance. Very few hiring managers can do that reliably, although many fool themselves into believing that they can.

The point is that someone gave a specific example of the much more general concept of probing for mental model by way of detailed explanation of a process he ought to be familiar with. You objected to the specific details - knowledge of HTTP. That's not an indictment of the general approach. That said ML models have gotten to the point where I'd have to disagree with OP that this approach will necessarily filter thei…

It was a stupid example.

Re: We identified a North Korean hacker who tried to get a job

#280
post #276

Earlier quoted context omitted.

> Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned. Which is why everyone needs to switch to passkeys. It's crazy that we still use passwords for authentication

Don't passkeys still have tons of vendor lock-in attached? A password I can put into any password manager I want and transfer it to a different password manager and neither the password manager company nor the company for which I made the account is any the wiser.

Some PW managers can store a passkey, but when tied to a device, if the device is compromised then all of your accounts are unless you're also using a yubikey or third device 2fa
Post reply on HN