Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

441–450 of 534 posts

Re: I almost got hacked by a 'job interview'

#441
post #9

This article was written by an LLM. I get that the author might be self-conscious about his English writing skills, but I would still much rather read the original prompt that the author put into ChatGPT, instead of the slop that came out. The story - if true - is very interesting of course. Big bummer therefore that the author decided to sloppify it. David, could you share as a response to this comment the original…

thanks for the feedback. just fyi - this went though 11 different versions before reaching this point. so I am not able to share the full chat because i used Claude with google docs integration. but hears the google doc i started with https://docs.google.com/document/d/1of_uWXw-CppnFtWoehIrr1ir... this and the following prompt ``` 'help me turn this into a blog post. keep things interesting, also make sure you take a…

Fwiw the google doc there is great. And the actual blog post is a waste of my time. I also have other stuff going on in my life and don't appreciate the LLM output wasting my time at all.

But the google doc is genuinely good stuff.

Re: I almost got hacked by a 'job interview'

#442

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

Totally written by AI. There’s too many embellishments like “LinkedIn legitimacy” and short summarizations. AI loves to wordsmith.

Re: I almost got hacked by a 'job interview'

#443

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

The important part for me is that the experience is legitimate, and secondarily that it's well written. The problem for me with LLM-written texts are that they're rarely very well written, and sometimes unauthentic.

If we had really good AI writing, I wouldn't mind if poor authors used that to improve how they communicate. But today's crop of AI are not that good writers.

Re: I almost got hacked by a 'job interview'

#444

> sandbox everything. Docker containers Docker is not a sandbox. How many times does this needs to be repeated? If you are lazy, I would highly suggest to use incus for spinning up headless VMs in a matter of seconds

Perhaps the reason people keep repeating it is that someone makes the statement without any reasons, provides an alternative again without any reasons. "Why are you not using docker to sandbox your code?" "Umm.. someone on HN told me docker is not a sandbox, to use randomtool instead"

incus is not a random tool. It's a fork of LXD and maintained under linuxcontainers.org

Re: I almost got hacked by a 'job interview'

#445
post #443

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

The important part for me is that the experience is legitimate, and secondarily that it's well written. The problem for me with LLM-written texts are that they're rarely very well written, and sometimes unauthentic. If we had really good AI writing, I wouldn't mind if poor authors used that to improve how they communicate. But today's crop of AI are not that good writers.

That’s what I’m actually doubting in one of the screenshots, it says “Hi Arun,” but the author’s name is David.

Re: I almost got hacked by a 'job interview'

#447

Earlier quoted context omitted.

I'm regularly asked by coworkers why I don't run my writing through AI tools to clean it up and instead spend a time iterating over it, re-reading, perhaps with a basic spell checker and maybe grammar check. That's because, from what I've seen to date, it'd take away my voice. And my voice -- the style in which I write -- is my value. It's the same as with art... Yes, AI tools can produce passable art, but it feels s…

I consider myself to be an above average writer and a great editor. I will just throw my random thoughts about something that happened at work, ask ChatGPT to keep digging deeper in my question, I will give it my opinion of what I should do. Ask it to give me the “devil’s advocate” and the “steel man opinion” and then ask it to write a blog post [1]. I then edit it for tone, get rid of some of the obvious AI tells. M…

If you're a great editor, why do you let multiple LLMs edit for you?

Re: I almost got hacked by a 'job interview'

#449

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

Yeah my reaction was:

- The class of threat is interesting and worth taking seriously. I don't regret spending a few minutes thinking about it.

- The idea of specifically targeting people looking for Crypto jobs from sketchy companies for your crypto theft malware seems clever.

- The text is written by AI. The whole story is a bit weird, so it's plausible this is a made up story written by someone paid to market Cursor.

- The core claim, that using LLMs protect you from this class of threat seems flat wrong. For one thing, in the story, the person had to specifically ask the LLM about this specific risk. For another, a well-done attack of this form would (1) be tested against popular LLMs, (2) perhaps work by tricking Cursor and similar tools into installing the malware, without the user running anything themselves, or (3) Hide the shellcode in an `npm` dependency, so that the attack isn't even in the code available to the LLM until it's been installed, the payload delivered, and presumably the tracks of the attack hidden.

Re: I almost got hacked by a 'job interview'

#450

Earlier quoted context omitted.

Unless they pay for it and then they can see everyone who clicks on your profile again.

I don't think this is accurate. I believe if you go into your privacy settings, you can put yourself into a semi-private or a private mode so that your views aren't shown even when you click to view someone who is a LinkedIn Premium member. However, the big disadvantage is that when you put yourself in a private mode, if you are a non-subscribed user, you will not have access to these analytics for your own profile a…

I think what they meant is that you can't see who clicked your profile if you're browsing (semi?) anonymously unless you pay for premium.

You can browse anonymously for free.

To see all the folks who've visited your profile, you need to pay.

Post reply on HN