Live data from Hacker News

How not to hire a North Korean plant posing as a techie

theregister.com

61–70 of 134 posts

Re: How not to hire a North Korean plant posing as a techie

#61
post #58

Here is my opinion as someone who worked with alongside North Koreans (textile factory) and visited NK. I am from East Europe and have 10 years in IT. - NK secret service (or whatever you call it) is more sophisticated than this. They will act as proper company from Turkey, India, China or even EU countries... - if you actually manage to get some North Korean who escaped to West, they are 10x more dedicated than anyo…

Out of curiosity, how would a North Korean who escaped to the West even get money to relatives still there?

NK I knew had regular flights into EU, but that was 10 years ago.

Today there is most likely trade with China (I am not familiar with that). I would go through Russia, there is direct border and regular trade. NK building companies operate in captured parts of Ukraine for example.

Or just use bitcoin. NKs do have access to internet, it is good store of value (better than diamonds) and highly liquid asset!

Re: How not to hire a North Korean plant posing as a techie

#62
post #58

Here is my opinion as someone who worked with alongside North Koreans (textile factory) and visited NK. I am from East Europe and have 10 years in IT. - NK secret service (or whatever you call it) is more sophisticated than this. They will act as proper company from Turkey, India, China or even EU countries... - if you actually manage to get some North Korean who escaped to West, they are 10x more dedicated than anyo…

Out of curiosity, how would a North Korean who escaped to the West even get money to relatives still there?

This is how it works: https://blogs.worldbank.org/peoplemove/is-it-possible-to-sen...

Re: How not to hire a North Korean plant posing as a techie

#63
post #34

Earlier quoted context omitted.

unless you want to work for the gov.

This. If there is a government contract involved, even if you are not working directly on it, you will have to pee in a cup. But getting around that is stupid easy and simple, it is laughable.

> This. If there is a government contract involved, even if you are not working directly on it, you will have to pee in a cup.

This is not correct. When I held a clearance (which I don't anymore and won't again) the Department of Defense never made me take a drug test. I did, however, work for a publicly-traded government contractor that made me take one both times that they hired me as a matter of course. I worked for three other such defense contractors that were happy to have me without such a test.

I thought it was just a mild inconvenience until I developed a sinus infection and started taking pseudoephedrine and diphenhydramine two days before I was scheduled to take the test. Because these OTC drugs can cause false positives for methamphetamine and marijuana respectively (depending upon whether the test is reagent-based or GCMS) I had to quit taking them and suffer through two days of an upper respiratory infection to pass the test and placate some HR drone in Alabama.

I'm sure that there's a policy or exemption process for this situation but the same company also almost pushed my start date because their background verification service couldn't verify my past employment _at the same company_, i.e. their onboarding team was grossly incompetent. I decided not to chance it as I didn't want to go weeks without a paycheck while they sorted out a false positive. Needless to say I don't waste my time dealing with this class of employers any longer.

Re: How not to hire a North Korean plant posing as a techie

#64
post #53

Earlier quoted context omitted.

Because they're slaves kept in dorms in various South East Asian countries that can't leave, their handler wouldn't allow to go to an in person meeting or take a drug test. They're also usually lying about the city and country they're working from.

Ok... but if the job is remote anyway, why can't they work from North Korea itself and use VPN (as another commenter mentioned) to simulate being in another country? Or would that run into bandwidth/"Great Firewall"/other problems?

They can, I think that's the point of the "avoiding in-person meetings" warning.

Say you have an office in South Korea. A South Korean developer starts working for you as a remote employee, and their IP looks like it's connecting from South Korea. You say "cool, awesome, but you need to come to our office in Seoul once every two months for our regular all-hands meeting," and they keep skipping out on it, claiming family emergencies or whatever. That's the warning.

That was my understanding.

Re: How not to hire a North Korean plant posing as a techie

#66
>Evading in-person meetings or requests for drug tests.

I am surprised about the request for drug tests. Is this common in the US?

Except for high-security jobs, which are never possible remotely anyway, I have never heard of a client or employer asking for a drug test. If I got a request for a drug test, I would quit immediately. Even if I am sure it is negative, my private life is my business. Any attempt to control my private life I see as a personal attack.

Re: How not to hire a North Korean plant posing as a techie

#67

>Evading in-person meetings or requests for drug tests. I am surprised about the request for drug tests. Is this common in the US? Except for high-security jobs, which are never possible remotely anyway, I have never heard of a client or employer asking for a drug test. If I got a request for a drug test, I would quit immediately. Even if I am sure it is negative, my private life is my business. Any attempt to contro…

Intel had me do a drug test just for an internship that I was almost going to take in 1996 or 97. I'm not sure if they still do that, I haven't had a drug test since getting my Chinese work visa (which required a drug and Aids test).

Re: How not to hire a North Korean plant posing as a techie

#68

>Evading in-person meetings or requests for drug tests. I am surprised about the request for drug tests. Is this common in the US? Except for high-security jobs, which are never possible remotely anyway, I have never heard of a client or employer asking for a drug test. If I got a request for a drug test, I would quit immediately. Even if I am sure it is negative, my private life is my business. Any attempt to contro…

My first “real” job demanded a background check where they could “interview my neighbors to get a sense of my character” and other egregious things. I tried many times to get in touch with the background check provider’s (backcheck in Canada) privacy team, never ever got to a human or anyone to return my voicemails.

The employer was completely incredulous I would refuse to submit to the background check and thought I had stuff to hide. I was laid off in short order. I do t regret anything, this was invasive and unnecessary. I’ve never had to do a background check again beyond providing an extract of my police file that says I have no convictions.

Re: How not to hire a North Korean plant posing as a techie

#69

>Evading in-person meetings or requests for drug tests. I am surprised about the request for drug tests. Is this common in the US? Except for high-security jobs, which are never possible remotely anyway, I have never heard of a client or employer asking for a drug test. If I got a request for a drug test, I would quit immediately. Even if I am sure it is negative, my private life is my business. Any attempt to contro…

Companies have weird requests sometimes. A good decade ago or more, I was asked to sign a disclosure that I was not a member of a certain faith (that has/had anti-tech sentiment at the time). That would definitely not happen these days.

Re: How not to hire a North Korean plant posing as a techie

#70
post #49

I'm amazed that the "alt-detection" problem from multiplayer games has become a business problem. I guess the US gov has been doing this for decades for security clearances, is there a commercial equivalent that works internationally? And there's still the "man-in-the-middle" problem.

The U.S. Office of Personnel Management data breach in 2015 exposed the personnel files of anyone who had applied for a job with the U.S. federal government. It was blamed on China, and it may have been, but that isn't to say they didn't sell or trade the data to N.K. That data would be extremely useful in building fake profiles that pass inspection, as bundled with LinkedIn data it would show what profile ingredients get people hired.
Post reply on HN