Live data from Hacker News

A backdoor in a LinkedIn job offer

roman.pt

281–290 of 331 posts

Re: A backdoor in a LinkedIn job offer

#281

Earlier quoted context omitted.

Number spoofing is not a solved problem because some carriers, which appear legitimate in all other respects, make a business out of routing your traffic over TDM trunks that don't support caller ID verification, and will claim it's extremely expensive to upgrade these to VOIP.

I'd be 100% happy to block those carriers from calling me. Their users should just get a message that calling my number is not supported and they should try calling me from another device.

Not allowed. The same government rules that stop Google from refusing calls from Apple devices also stop them from refusing calls from whoever is doing this. The government would have to update the rules. They could mandate number verification for all calls, even those passing over TDM trunks, and make it the network's problem to figure out how to do that. The rules currently say that all calls which don't pass through legacy equipment must have verified numbers, so there's a market for making calls take stupid legacy routes on purpose.

Re: A backdoor in a LinkedIn job offer

#284
post #282

I can not imagine a situation where some random person messages me on linkedin asking me to solve a coding challenge, and I do anything other than block them.

I'm guessing you've never experienced the enormous pressure of needing to find a job to buy food and clothes for your family. That's good, I'm glad that you don't know that feeling. But if you did, you'd know how easy it could be for a person to start feeling more and more desperate for any kind of lifeline.

Re: A backdoor in a LinkedIn job offer

#285
post #260

This is a common one. I've had at least half a dozen of them. If I'm bored, I play along, and then play difficult and dumb and see how long it takes until they give up. Some of these will happily get on "interview" calls etc. For some reason, most (but not all) of them have the same telltale signs of looking for someone to work on a web3/crypto gaming project.

All they want is to get your keys and empty your wallet

Re: A backdoor in a LinkedIn job offer

#286
post #264

Been through this 3 times in the last 6 months. They're getting better. Very credible LI profiles, code looks OK if you only take a glance... The bell start ringing when they insist you to run locally their sh*t

The big red flag should be giving github access before signing any contracts.

They mostly use public repositories though.

Re: A backdoor in a LinkedIn job offer

#289
post #285
post #260

This is a common one. I've had at least half a dozen of them. If I'm bored, I play along, and then play difficult and dumb and see how long it takes until they give up. Some of these will happily get on "interview" calls etc. For some reason, most (but not all) of them have the same telltale signs of looking for someone to work on a web3/crypto gaming project.

All they want is to get your keys and empty your wallet

I guess that might be a reason to use the web3/crypto angle to get people who are unlikely to have crypto wallets to self-select out...

Re: A backdoor in a LinkedIn job offer

#290
this happened to me too. few things about the process made me suspicious. i downloaded the repo and told claude to "find the malware". took about 15 seconds. remote code execution that would have run upon npm install, iirc. many layers of obfuscation. in implementation, a little different to the op's situation but there are similarities. it was a "crypto startup". maybe they think people in crypto world are more forgiving of idiosyncrasies in the recruiting process? i reported the recruiter's profile to linkedin, with extensive details. they said they wouldn't look into it unless i opened a ticket in some other part of their site, lol. however it seems they got onto it, or someone else complained, because i can't find the recruiter "alice kenny" anymore. but the "company" she was recruiting for is still live:

https://www.linkedin.com/company/blockchainaustraliasolution...

Post reply on HN