Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

481–490 of 534 posts

Re: I almost got hacked by a 'job interview'

#481

Earlier quoted context omitted.

I dont buy it can tell if something sounds ai. Multiple times i have given it direct ai slop writing and it could not tell it was ai written. As a matter of fact, it would insist it wasnt. This flow sounds like what an intern did in pr reviews and it made me want to throw something out a window. Please just use your own words. They are good words and much better words than you may think.

https://chatgpt.com/share/68f065f4-f5ac-8010-81c1-faf4218e5c... https://chatgpt.com/share/68f0666a-2bf0-8010-9d35-2ac4bdc870... This article was dated as being written in 2020 https://chatgpt.com/share/68f06775-c570-8010-af7b-29531a22fd... Original article https://www.yourmembership.com/blog/tips-effective-board-mee... I can’t share links from Gemini or Grok. But they both immediately flagged the first one as AI gene…

Could I tell if the last one is AI? Absolutely. Throwing a few "damns" in there didn't convince me. And all the reworking you've done, while it makes it a little more passable, has made it arguably worse in quality. The point of the final article is so muddy. It has no central point and sprawls on and on about random nonsense.

Re: I almost got hacked by a 'job interview'

#482
post #261

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

I think it only really has that feel if you use GPT. I mean, all AIs produce output that sounds kinda like it was written by an AI. But I think GPT is the most notorious on that front. It's like ten times worse. So really the feeling I get when I run into "obviously AI" writing isn't even, "I wish they had written this manually", but "dang, they couldn't even be bothered to use Claude!" (I think the actual solution i…

I mean, they are different, but there is only a subset of like 3 big model providers. And we see hundreds of thousands+ of words of generated content from each, probably. It is easy to become very familiar with each output.

Claude vs GPT both sound like AI to me. While GPT is cheery Claude is more informative. But both of them have "artifacts" due to them trying to transform language from a limited initial prompt.

Re: I almost got hacked by a 'job interview'

#483
post #481

Earlier quoted context omitted.

https://chatgpt.com/share/68f065f4-f5ac-8010-81c1-faf4218e5c... https://chatgpt.com/share/68f0666a-2bf0-8010-9d35-2ac4bdc870... This article was dated as being written in 2020 https://chatgpt.com/share/68f06775-c570-8010-af7b-29531a22fd... Original article https://www.yourmembership.com/blog/tips-effective-board-mee... I can’t share links from Gemini or Grok. But they both immediately flagged the first one as AI gene…

Could I tell if the last one is AI? Absolutely. Throwing a few "damns" in there didn't convince me. And all the reworking you've done, while it makes it a little more passable, has made it arguably worse in quality. The point of the final article is so muddy. It has no central point and sprawls on and on about random nonsense.

I agree and I said as much

With some human editing to make it sound less douchery or better prompting, do you think you could tell?

In other words - I did no human editing or even played with the prompt.

For instance, I would have definitely reworded this “a solid meeting isn’t just about not screwing up the logistics. It’s a snapshot of how your team actually operate”

The “it isn’t just $x. It is $y” is something that Ai loves to do.

The larger point is AI is really good at detecting its own slop. Gemini is really good at detecting first pass AI Slop from another LLM and out of curiosity I put a few other articles I knew was written before 2022 to see if it gave false positives.

Re: I almost got hacked by a 'job interview'

#484
post #47

Earlier quoted context omitted.

Is there a market for a distributed audit infra with attestations? If I can have ChatGPT audit a file (content hash) with a known-good prompt, and then share the link as proof of the full conversation, would this be useful evidence to de-risk? If each developer can audit some portion of their dep tree and reuse prior cached audits, maybe it’s tractable to actually get “eyeballs” on every bit of code? Not as good as h…

> If I can have ChatGPT audit a file You can't, end of story. ChatGPT is nothing more than an unreliable sniff test even if there were no other problems with this idea. Secondly, if you re-analyzed the same malicious script over and over again it would eventually pass inspection, and it only needs to pass once.

> Secondly, if you re-analyzed the same malicious script over and over again it would eventually pass inspection, and it only needs to pass once

You’d need some probabilistic signal rather than a binary one. Eg if some user with zero reputation submits a single session saying “all good”, this would be a very weak signal.

If one of the Python contributors submits a batch of 100 reasoning traces all showing green, you’d be more inclined to trust that. And of course you would prefer to see multiple scans from different package managers, infra providers, and OS distributions.

Re: I almost got hacked by a 'job interview'

#485
post #400
post #99

Earlier quoted context omitted.

if you use simple c libraries that do one thing, yes, you don't have to go very far at all. whether you'd be able to find the backdoor in those or not, might depend on your skills as a security expert.

Could luck as a web dev with all those npm packages

there are many reasons I'm not a web dev, and npm is one of them.

Re: I almost got hacked by a 'job interview'

#486

Earlier quoted context omitted.

I manage an employee from another country and speaks English as a second language. The way they learned English gives them a distinct speaking style that I personally find convincing, precise and engaging. I started noticing their writing losing that voice, so I asked if they were using an LLM and they were. It was a tough conversation because as a native English speaker I have it easy, so I tried to frame my side of…

As a non-native English speaker living in AU, I can offer my opinion in case it's helpful. Of course I can't speak to the person you mentioned but if you said what you did with respect and courtesy then they probably would've appreciated it. I know I would have. To me, there's no problem speaking about and approaching these issues and even laughing about cultural issues, as long as it's done with respect. I once had…

This was a super helpful perspective, thanks a million.

Re: I almost got hacked by a 'job interview'

#487

>Blockchain company Is that no longer a red flag?

I've gotten plenty of emails from blockchain/crypto/web3 companies and I just delete them. It's entirely possible they are real, legitimate companies, and even if they are I'm not sure I'd want to work there.

Re: I almost got hacked by a 'job interview'

#488
post #438
post #273

Earlier quoted context omitted.

> This article is so incredibly interesting, but I can’t shake the feeling it was written by AI. The writing style has all the telltale signs. The sadder realization is that after enough AI slop around, real people will start talking like AI. This will just become the new standard communication style.

Chatgpt is just an aggregate of how the terminally online, talk, when they have to act professional. Chatgpt is hardcoded to not be rude (or German So when you say, "people will start talking like AI". They are already doing that in professional settings. They are the training data. As someone who writes with swear words and personality. I think this era is amazing for me. Before, I was seen as rude and unprofessiona…

> They are already doing that in professional settings. They are the training data.

It's a self-reinforcing cycle. AI sucks up and barfs back up the same bland style and eventually books, articles, news will all look even more bland and sound more AI like. That junk then will be sucked up by the next AI model, and regurgitate into some even more bland uniform format. If that's all the new generation hears and sees, that's how they'll perceive one should "talk" or "write".

> Authenticity is valued now. Swearing is in vogue.

Ha! That's a good point, I like that. Not that swearing is my style (unless I stub my toe), but I agree with the general authenticity point. Maybe until the interns at Google and OpenAI will figure out how to make their LLM sounds more "hip" and "authentic".

Re: I almost got hacked by a 'job interview'

#489
post #239

I had a light interview to get started with LLamaIndex from their Discord channel while I was waiting to connect with some of the real developers. The scammer attempted some nonsense in a similar way, but had no plausible reason why I would be accessing those packages or downloading those things. I was remote desktop streaming while messing with some of my own code. The repository is 100k+ lines of code and I was loo…

> I asked them the same questions I ask all scammers: How was this easier than just doing a normal job? Ostensibly more profitable? Dont forget there are a lot of places where even what would be minimum wage in a first world country would be a big deal to an individual.

A project manager gets paid more than minimum wage and those are actual skills that are in demand.

Going through hoops to have to cash out some of your money is a big red flag you're probably scamming yourself.

I think it works similar to most low-tier street crimes. If you zoom out and look at the vast majority of the "labor" they only make some of the pennies they keep. In the same way there are a few stand-out "high tier" drug dealers, etc. there are a few scammers collecting a decent check, but the vast majority are stepping over dollars to pick up pennies.

Re: I almost got hacked by a 'job interview'

#490
post #135

Earlier quoted context omitted.

Same in the UK (which is currenty a contentious issue again with Digital ID), because there is no concept of having a cryptographic signature tied to your identity in the way it is done in other EU countries. Instead you need: - five years of address history - a recent utility bill or a council tax bill that has your full address - maybe a bank statement - passport or driving license It just so happens that Experian,…

Wait what? In UK you don't have Qualified Certificate tied to person, which can be used to sign documents, communicate with banks etc. No way.

Nope.
Post reply on HN