Live data from Hacker News

We identified a North Korean hacker who tried to get a job

blog.kraken.com

291–300 of 309 posts

Re: We identified a North Korean hacker who tried to get a job

#291
post #50

Earlier quoted context omitted.

The fake people are sometimes backed by entire teams (the article alludes to this). It’s easier to do well in your job when you’re supported by a team of people, maintaining the fiction that you’re one person. This isn’t happening left and right. It’s an attack against specific industries, like crypto and finance. It’s one part of a broader pattern of attacks.

last years falcon (crowdstrike specific conference) they for the first time every showed live the interviews of 3 north koreans trying to get a job in software engineering positions at some forture 500 companies. i was baffled at every 'security' question to validate the person is actually in the US gets glossed over like: "my ID is at my home right now, and im in my office so i don't have that with me".

As long as the speech pattern matches, the defenses are down. Just look at the formulaic responses of Russian bots/trolls.

"As a [role,gender,national ] posting from [country, city]..

[I agree with parent] *2 sentences .

[Actual opinion\story to push]

[Reminder on connting nationality/location ] "Thats my two Eurocents on that, take it or leave it ."

Its hyper fake, formulaic responses topic tugboats, but people go and engage in good faith all the time .

Re: We identified a North Korean hacker who tried to get a job

#292

Earlier quoted context omitted.

Actually, that isn't the case with the SAVE act. If I produce a social security card and any government ID, that is typically enough to work (in the US). It won't be enough to vote under the proposed act. In many cases, what will be required is a birth certificate that exactly matches other ID. If your name has changed, unspecified documentation will be required beyond a marriage license or court approved name change…

Well that is even more ridiculous. I have a passport but I think I've lost track of my birth certificate. My state ID isn't even REAL ID compliant (and I am very happy about that fact - it's blatant federal overreach that badly needs to be snubbed). But the point remains - you often (in practice) don't need ID for low skill jobs whereas high skill ones generally carefully vet you. Thus hand wringing about requiring a…

Well, that last doesn't bother me at all. If a person is doing something valuable, dilligence is due.

The blatant voter suppression efforts aiming at stopping a problem that results in less than a basis point of error in voting counts bothers me a lot, though.

Re: We identified a North Korean hacker who tried to get a job

#294
post #134

Earlier quoted context omitted.

Do you not have regular calls with teammates? Sure I guess someone could physically turned up to an office to collect a laptop, be onboarded, get ID checked, then dial in to a few hours of meetings a week, muddle through any questions, rely on the team back at base helping, turn up in person to team get togethers every few months and manage to bluff their way through. It's not unprecedented - Frank Abagnale was runni…

Those regular calls is what limits how many places you can work for. You full time job becomes holding those calls, plus knowing just enough about the problem to sound intelligent. You can probably work 4 jobs this way.

Not just planned calls, random unplanned "jump on a huddle for a few minutes" ones at 11:42.

If you're working in another company and on a team meeting there, you're going to get caught pretty quick.

Re: We identified a North Korean hacker who tried to get a job

#295
post #204

Earlier quoted context omitted.

> I find some people's attitude to NK hackers slightly schizophrenic: either they are a credible threat or they are amateurs. Which one is it? I have no clue whether the proposed approach works, but there's a pretty coherent model that explains how it could , no schizophrenia needed: They are competent people in a cult. Being unable/unwilling to diss Dear Leader even when it's advantageous to do so is very typical cu…

So you're saying NK agents are completely different to, say, Soviet era agents, who could and would say anything as long as it furthered their mission? Ok, fair enough. In common perception of NK, they do seem bizarre, not like the Soviets during the Cold War. I think it's unwise to dismiss them as lunatics incapable of deceit. If I were a NK agent, I'd work towards this notion, "NK are incapable of lying if it would…

I'm just guessing but comparing the NK hacker to a late Cold War era Soviet professional spy is the wrong comparison. Maybe the closer comparison is asking a Soviet party member belonging to the professional middle class with a bit of spy training during the Great Purges to talk negatively about Stalin out of the blue.

Re: We identified a North Korean hacker who tried to get a job

#296
post #279

Earlier quoted context omitted.

The point is that someone gave a specific example of the much more general concept of probing for mental model by way of detailed explanation of a process he ought to be familiar with. You objected to the specific details - knowledge of HTTP. That's not an indictment of the general approach. That said ML models have gotten to the point where I'd have to disagree with OP that this approach will necessarily filter thei…

It was a stupid example.

[deleted]

Re: We identified a North Korean hacker who tried to get a job

#297

Earlier quoted context omitted.

their strategy honestly says a lot of crazy things about their worldview

What do you mean by this (genuinely curious).

i'm scared to explain it, you could be north korean

Re: We identified a North Korean hacker who tried to get a job

#298

Earlier quoted context omitted.

And similarly forbid them from using AIs while they code on that work laptop in person? Are employees forbidden from using AIs for work? If not, why require that during evaluation? If it's not required during evaluation in person, why require it remotely? (I don't know the answers to how to interview in this brave new world, but I'm increasingly skeptical of forbidding tools that people will be using for the job.)

I think the best interview question, and really the only one you need to determine technical ability is ask someone to describe a http request in as much detail as possible. To write code (even with the benefit of AI) effectively you need a mental model of the systems you work with, reading the chatGPT response doesn't prove you have that.

The "what happens when I enter facebook.com in the browser and hit enter" is/was a well-known FAANG question a few years back so I would expect that all the LLMs are well versed in it, as will be NK infiltrators

Re: We identified a North Korean hacker who tried to get a job

#299

Earlier quoted context omitted.

The 1918 Pandemic is still around, too... A/H1N1

Different species, you can't generalize like that. It's pretty unclear what actually happened with H1N1. Scientists were able to resurrect the more virulent strain in the lab two decades ago and it was just as potent in lab animals... Two possibilities are that it did in fact mutate to become "milder" or those strains were already circulating. Either way, H1N1 killed so quickly it ran out of victims and the highly le…

I was under the impression that it mostly killed by causing cytokine storms.
Post reply on HN