Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

281–290 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#281

Commenting on the events, CSO Nick Percoco, said: “Don’t trust, verify. This core crypto principle is more relevant than ever in the digital age. State-sponsored attacks aren’t just a crypto, or U.S. corporate, issue – they’re a global threat. Any individual or business handling value is a target, and resilience starts with operationally preparing to withstand these types of attacks.” It's funny to see the CSO of a c…

I mean if the credentials are correct than they transaction is by design verified and trusted.

Re: We identified a North Korean hacker who tried to get a job

#282

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

It's a marketing blog post. I guess they feel like this gives them "street cred" for being a security firm "targeted" by a north korean and how they "strategically interacted with" that person. It's not about the employment pipeline or basic vetting.

Re: We identified a North Korean hacker who tried to get a job

#284

Earlier quoted context omitted.

My experience is that yes it opens up the wider pool, but it makes the filtering process much more difficult in trade. Opening up the wider pool without the in person interview is where things hit the wall since the filtering criteria everyone learned over their careers went out the door thanks to the online interview process. And the online interview process is much more subject to cheating--not exactly a huge conce…

What is the local pool like? If you want a software engineer silicone valley you can stay all local. There are companies in remote small towns who need a software engineer - they have to open up to non-local candidates as there are zero people in town who could do the job that don't work for them. There is always someone from elsewhere excited to move to a small town, but finding those people is hard. (and for those…

I'm in a tech hub so the local pool is wide and deep. But I was flown up for an interview, and I've known other people who were flown out, were hired, and have become locals.

This didn't used to be a huge problem.

Re: We identified a North Korean hacker who tried to get a job

#285

Earlier quoted context omitted.

COVID isn't in the past, just no one doing anything about it. :)

The 1918 Pandemic is still around, too... A/H1N1

Different species, you can't generalize like that. It's pretty unclear what actually happened with H1N1. Scientists were able to resurrect the more virulent strain in the lab two decades ago and it was just as potent in lab animals...

Two possibilities are that it did in fact mutate to become "milder" or those strains were already circulating. Either way, H1N1 killed so quickly it ran out of victims and the highly lethal strain went extinct. Another notable aspect of H1N1 is that is mostly didn't kill directly, it made victims weaker to opportunistic lung infections and that's what killed them. Antibiotics have made this kind of attack vector much more difficult for viruses.

Omicron is only loosely analogous to the "flu fairy tale" as the major threat is Long COVID now and it is circulating at high levels. Other viruses have had vastly different natural histories, 1918 is only a single reference point, and a muddy one at that.

Re: We identified a North Korean hacker who tried to get a job

#286

They used their leet "OSINT" skillz to ask the most basic of questions and background checks that nearly any traditional interview process would immediately uncover, then think it's so novel it's worthy of a blog post. On the surface it seems the "security" industry is lacking in the most basic of security processes when hiring. I don't think I've ever worked anywhere that could accidentally hire a North Korean witho…

> yet fake people are getting hired left and right. Hate to be that person, but what are you reading that makes you think this is true? Agree that the article is pretty dumb though, especially the OSINT and Crypto “don’t trust, verify” comments. Feels like content marketing that didn’t really hit.

I did see two fakes hired at my old company, a 20 something "senior eng" who couldn't use git or python, and shockingly a VP who managed to fake it for nearly a year. He was unceremoniously fired on a Friday, but he was still paid lol.

I worked at an adtech company, he would give talks with powerpoints talking about internet of things which was absolutely wild. (We never sold or touched a single piece of hardware.)

Re: We identified a North Korean hacker who tried to get a job

#287

Here's a heretical thought: Remote hiring is a massive achilles heel. I've been duped simply by hiring a great engineering candidate who then farmed out the actual work to remote workers in Pakistan and India. We caught on fairly quickly thanks to one of them forgetting to login to one of our backend systems via vpn a few times. No idea how many companies he was "working for" but I'd bet we were one of many. Remote w…

Some people did this with in-office too I think, some years ago. Some people actually had two jobs, both sort of in-office. It's still possible to pull the tricks.

The common pattern of requiring three days a week of in-office time makes it much harder.

Re: We identified a North Korean hacker who tried to get a job

#288

Its quite saying, that in order to get interviews, you have to basically lie your way with various generative AI. Whereas, I've been looking for quite a while, with very few bites. And nobody so far on HN Who's hiring responds, except for a place that seems to want 60h/week and pay for 40h/week. Being genuine and truthful in the age of generative AI, LLMs, quiet quitting, /r/overemployed (on the sly working multiple…

I’m a little skeptical that generative AI is an effective way to land a job. It doesn’t really seem like it helps that much in résumé generation. Are people applying to enough hundreds of jobs that generative AI helps you keep up with the sheer volume of text you need to send? Some people are … but these aren’t people who know what good résumés look like, because those people write their own résumés, and these people…

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#289
post #276

Earlier quoted context omitted.

> Any actively used e-mail address that is older than a few years will be listed on haveibeenpwned. Which is why everyone needs to switch to passkeys. It's crazy that we still use passwords for authentication

Don't passkeys still have tons of vendor lock-in attached? A password I can put into any password manager I want and transfer it to a different password manager and neither the password manager company nor the company for which I made the account is any the wiser.

I was talking about a self-hosted OIDC provider to avoid a vendor lock in. You can transfer passkeys from vaultwarden to any other password managers

Re: We identified a North Korean hacker who tried to get a job

#290
post #130

Someone said that North Koreas are trying to get jobs. Ok Then they had a candidate who was trying to cheat the systemeat How did they establish and verify that the candidate was North Korean? Are North Koreans the only ones who try to remote work byt lying about their whereabouts? Not at all. If you live in a country outside of the US and you see the money software poeple make in the US it is mighty tempting to land…

The article notes the following as the establishing link: > We received a list of email addresses linked to the [North Korean] hacker group, and one of them matched the email the candidate used to apply to Kraken.

but how legit is the list?
Post reply on HN