Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

31–40 of 534 posts

Re: I almost got hacked by a 'job interview'

#31

>a "legitimate" blockchain company When you lie down with dogs, you get up with fleas.

I wonder if willingness to be involved with Bitcoin is a flag for scammers? It at least raises the chance you'll have a wallet or other program around and therefore more payoff for easy hacks

Re: I almost got hacked by a 'job interview'

#32

Earlier quoted context omitted.

You can click on the verification badge and see if the person has job verification. If not, that's a red flag. I never paid attention to this myself but I will in the future.

Interesting, I didn't know there is such thing on Li! Is this done by past employers?

You have to add it yourself and verify with your work email.

Re: I almost got hacked by a 'job interview'

#35
post #4

I’ve grown to depend on little snitch for this sort of thing. Always run in either Alert or Deny mode. It is a little wild how many things expect to communicate with the internet, even if you tell them not to. Example: the Cline plugin for vscode has an option to turn off telemetry, but even then it tries to talk to a server on every prompt, even when using local ollama.

I agree, it's very valuable in these situations, although it can only minimize damage. For Littlesnitch/OpenSnitch users: avoid allow rules that apply to all apps. Malware can and has used even trusted websites like Github Gists to expose secrets extracted.

In any case, even if your firewall protects you, you'll still have to treat the machine as compromised.

Re: I almost got hacked by a 'job interview'

#38

I had someone who was targeting junior developers posting on Who Wants to Be Hired threads here on Hacker news. They reached out saying they liked my projects and had something I might be interested in, then set up an interview where they tried to get me to install malware.

Name and shame. It's the only way to help others.

Re: I almost got hacked by a 'job interview'

#39

why is this website `daviddodda` while the linkedin message mentions `arun`. This might be the forth or fifth time I've seen this type of post this week, is this now a new form of engagement farming?

It looks like the LinkedIn account and site are really the same person to me, just keep in mind it's not uncommon for Indian IT workers to adopt an anglicized name in this kind of context.

> It looks like the LinkedIn account and site are really the same person to me, just keep in mind it's not uncommon for Indian IT workers to adopt an anglicized name in this kind of context.

I've never encountered an Indian IT worker who does that, but I'd say a majority of Chinese IT workers go by an English name.

Re: I almost got hacked by a 'job interview'

#40
post #2

I own a company and get contacted daily by tons of applicants who scammers took advantage of using fake similar domains and such. My opinion is that scammers, wherever they are in the world, should get bombed. Criminals only stop when the risks are higher than the rewards. And we need to stop victim blaming companies and individuals.

>> Criminals only stop when the risks are higher than the rewards.

I would say they just transition to something else where there is a lower risk with the same reward.

Post reply on HN