Hacker News

codedge
How to compromise your system with a job interview codedge.de

dprkh3 hours ago

There is a YC company that makes a coding interview tool. They want you to run their CLI on your machine and trust that it won't do anything malicious, when in fact it installs a bunch of things onto your machine without consent, scans processes, and intercepts requests from AI tools. It's crazy that people think this is acceptable.

stronglikedan3 hours ago

Just that fact that the company expects a candidate to even have their own machine is egregious.

mistersquida minute ago

> Just that fact that the company expects a candidate to even have their own machine is egregious.

In the company where I work (in recent history, the most valuable company on the planet), there are younger employees who do not own personal computers.

One of them was (with different company now) a Gen Z developer who did not personally own a computer (besides a phone).

I was floored. Still am.

morkalork2 hours ago

What, you can't expect a candidate at least have a laptop?

s_devan hour ago

What if your laptop is broken? You should be restricted from getting a job? What about if you just landed in the US and didn't want to have to present it to the authorities to scan and plan on buying a new one because they are cheaper there. What about if a family member was currently using it. There are plenty of valid reasons why you might not have a laptop in general or at the moment in your life.

redox99an hour ago

Then you should find a way around it. If an applicant can't even manage to get a laptop for a few hours I rather hire someone else.

In extreme cases we can work it out but you should have something that makes up for the extra annoyance compared to 99% of applicants.

nkrisc38 minutes ago

In most work places you are provided a computer to work on. So you could very easily not have a personal computer during your career as you are always provided one to work on.

Probably not common, but certainly plausible. Not everyone wants to bring work home or have hobbies that are the same as their work.

redox999 minutes ago

I wouldn't want to hire someone who literally never uses a computer outside work (to the point of not owning one).

metalforeveran hour ago

I’m a lead engineer and have been Staff plus for more than 5 years. I’ve actually personally run into this problem (not having a working laptop for an interview). I don’t really do laptops well because it’s not a good environment to get work done in. I can see a large screen(s) desktop setup better and prefer that.

redox995 minutes ago

I used laptop because that's what the parent said, but I really meant a computer of any kind at home. I assumed a remote interview. If its an interview in person at an office I'd definitely expect hardware to be provided.

rootusrootus12 minutes ago

> I can see a large screen(s) desktop setup better and prefer that.

I kinda assumed that most developers took a similar approach to me. Laptop because portable when you need it, hooked to large screens, nice keyboard, nice mouse/whatever. I don't know what having a desktop would really buy me. I do 99% of my work with the laptop docked but that remaining 1% it sure is handy to grab it and go.

fsckboy18 minutes ago

the mention of laptop was not adding a laptop requirement to the original question

mock-possuman hour ago

Wow your suggestion is “let them eat cake?”

Do you actually believe what you’re saying, or have you not thought it through?

CookieCrispan hour ago

What reality are you living in?

fsckboy16 minutes ago

there are people out there who don't want to hold your hand.

stop advocating that we discriminate against them because you feel you need your hand held.

LostMyLoginan hour ago

If a candidate reached out claiming they didn’t have a machine to interview with, I’d gladly find another path forward. But I imagine that’s a small minority in this industry.

It wouldn’t stop them from being hired.

kulahanan hour ago

Any obstacle whatsoever, especially one you yourself admit is very rare, is much more likely to result in a dropped interview if one is even offered. Why bother?

You’ve got 10,000 candidates applying. Seriously, what would make “doesn’t have a laptop” stand out to you positively? Why not just go with the 9800 applicants who do have one? Surely there’s no reason to think “broken laptop = good dev”. It’s so much easier to simply go with a candidate who has no problems. Beyond that, what’s the deal with making candidates do stuff on their own machines anyways? You don’t know what’s on there. You don’t even know if it’s stable enough for a test, and none of that has any bearing at all on their skill.

I’ve never worked in the Bay Area, but if this is common practice, I think I dodged a bullet.

[deleted]an hour agocollapsed

thih9an hour ago

Some people share laptops, others don’t have one at all and are fine with a tablet or smartphone.

leoedinan hour ago

Are those the people you want to hire for software development jobs though?

Honestly I would see that as a huge red flag. In western countries a used laptop costs almost nothing.

metalforeveran hour ago

I’ve personally run into this issue of not having a working laptop in an interview setting. It’s not always money . I just don’t like getting work done on a laptop. I use a desktop. I’ve been staff+ for more than 5 years .

Hamuko23 minutes ago

I've done all of my recent interviews on an iPad.

[deleted]an hour agocollapsed

phendrenad22 hours ago

For all its talk of 'meritoctacy', the bay area really runs on looking the part.

shimmanan hour ago

Because meritocracy isn't a real thing.

It's just another form of authoritarianism, despotism, and oligarchy. Who decides what work is worth rewarding? What about the type of work?

It was always an antidemocratic idea sold to tech workers to stop the idea of questioning the system.

The idea that simply "talented" workers should rule just seems to speed run towards fascist aims. How do you consider which workers are worth more than others? If you do to the wrong school are you suddenly worth less? Do you think society will have certain preferences? What about in our neoliberal society where money is the only purpose to life?

rootusrootus2 minutes ago

What would your preferred alternative look like?

antisthenes37 minutes ago

> Because meritocracy isn't a real thing.

It absolutely is a real thing. You don't get to declare that an existing word with more than 2000 years of history doesn't exist.

It may not exist in the Bay Area or in whatever subset of parameters you invented, but it absolutely exists and is something to strive towards.

> The idea that simply "talented" workers should rule just seems to speed run towards fascist aims.

Complete non-sequitur with 0 evidence.

> How do you consider which workers are worth more than others? If you do to the wrong school are you suddenly worth less? Do you think society will have certain preferences?

You decide just like everything else. Based on context and some objective measurements. It's not a perfect system, because sometimes measurements can become the goal, rather than the underlying objective, but it's the best system we have.

jltsiren2 minutes ago

You may have heard the joke that polyamory is wrong, because it should be multiamory or polyphilia. Meritocracy is a similar case. Because the word mixes Latin and Greek roots, it's unlikely to be old.

The first recorded uses of "meritocracy" are apparently by Marxist sociologists in the 1950s. They used it to describe a dystopian society, where merit serves as a moral justification for social classes, and social class determines the opportunities available to gain and demonstrate merit.

Of course the idea that career success and influence should be based on demonstrated ability and effort is ancient. But once you start building a society based on that idea, you run into Goodhart's law.

htrp2 hours ago

Name the company

dprkh2 hours ago

Litmus

sakjur2 hours ago

I first thought this was a tongue in cheek joke before I realized you were the original commenter and looked them up.

I've described some prior experiences with some interviews as failing my litmus test and have cancelled further interviews when people start demand much too much from me before I'm on a payroll.

MajorTakeaway3 hours ago

Even more reason to use VMs.

[deleted]an hour agocollapsed

tamimio3 hours ago

They (not what OP is talking about but usually these software) detect if a VM exists and abort, to prevent “cheating”.

bitwize3 hours ago

How about no.

If you want me to run a particular piece of software, send me a fucking computer. If you want me to be on call on a company-managed cellphone, send me a phone that you can own and manage all you want.

Do not ask me to download, install, or run malware on MY computer or phone as part of the APPLICATION process. If you are the sort of company that thinks this is appropriate, then I do not want to work for you. I've actually turned down work because of this. "Oh, they just want you to install this Chrome extension to make sure you're not cheating during the video interview." No. Fuck you. Don't touch my fucking equipment.

fsckboy11 minutes ago

how about they do what they want, and you do what you want, and you don't collaborate with each other if you can't get along? no reason to be angry.

if one of my hiring practices would reliably generate that many f-bombs, i'd consider it a success and stick with it!

exe342 hours ago

I have a desktop that I use as a remote server for the GPU, so I'd be happy to disconnect the ssd and boot off a usb stick.

delichon3 hours ago

Maybe it's a pen test such that if the CLI can phone home you fail, to weed out candidates with weak security fu.

bryanrasmussen2 hours ago

if that was the purpose it should weed out candidates who agreed to install the app for a job interview.

mapmeld41 minutes ago

Since no one mentioned it - this seems to be a major and real problem in the crypto job space. In their job market it's more believable that a 'stealth startup' is reaching out and doing a code challenge from an unfamiliar email or repo, and crypto devs are likely to have a wallet or passwords accessible on their system. They are willing to go above and beyond the regular spam or AI conversations to get access.

denysvitali4 minutes ago

Yes, I got targeted too: https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-...

(Don't work in crypto, but there's a crypto company with the same name as the one I work at)

fsckboy9 minutes ago

cheap laptops are cheap, simply don't use your "real" computer.

fwip25 minutes ago

Also, to be into cryptocurrency, you kind of have to be gullible to begin with.

john_strinlai4 hours ago

out of the list under "Before you start with the test, you might be suspicious about the following:" there is only one that is important:

only interact with people using an official email address.

the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).

sgbeal41 minutes ago

> only interact with people using an official email address.

And then google whether the domain is associated with phishing attempts. i've been targeted several times recently by folks with "official" email addresses but whose domains are (per google) strongly associated with phishing.

forinti3 hours ago

> “A relevant opportunity” with part-time remote work and a great hourly compensation

That is so suspicious at the moment.

zuuna2 hours ago

Being on the job hunt myself this is very helpful! I do however prepare public repos and showcases for such interviews/applications, I hope my luck streak doesnt run out

Terr_25 minutes ago

> It never asks for elevation. It doesn’t need root, UAC, or sudo, because nothing it wants is root-owned. SSH keys, AWS credentials, browser profiles, wallet data, .env files - all of it is user-owned by design, because you need to read it routinely.

Tangentially, what have people found that works well in term of hardening [0] desktop linux?

I figure the only good way to keep separate user accounts (e.g. one just for banking) and never ever use sudo from any of them.

[0] https://xkcd.com/1200/

vlod2 hours ago

I've been meaning to learn/run QEMU on my linux box. I assume I don't need to do anything apart from rebuild the image each time I need to do this?

Yes I most likely will tell them to get lost, but if I get an invite from Larry/Sergey I want to be ready.

m3047an hour ago

You'll probably need to enable some "secure memory mode" in BIOS, e.g. a boot error that you ignore which says something like "KVM disabled by BIOS" needs to be made to go away.

pronoiac3 hours ago

If you run across something like this:

* perhaps archive your findings

* report the abuse to their hosting

I'm dropping emails to jsonbin.io and to ZapHosting (who run 147.189.174.138) about this.

denysvitali3 minutes ago

A lot of hosting providers don't really care, sadly :(

aliasxneo4 hours ago

I get enough legit and illegitimate ones every week on LinkedIn that it's become really easy to tell the difference. Hard to pinpoint in a comment because it's mostly a gut feeling. But, in rough order:

1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.

2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.

3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.

4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).

Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.

stevekemp4 hours ago

Honestly unless I'm planning on quitting my current job, or if I were unemployed, I just ignore the linkedin.

Sure they spam you with "XX wants to connect", or "I'm awaiting your reply" emails. But real contacts and friends can call/email you, and everybody else can wait six months.

Despite only connecting with actual people I've worked with, not recruiters, I still get "suggested" posts which are slop, and "that happened". The site is a cesspool.

sorokod39 minutes ago

A recruiter recently sent me an "I'd like you to explore..." email. Every "further info" link in it pointed to znsrc.com/[unique_id] rather than to the displayed address.

That felt dishonest and I ignored the email.

joshribakoff35 minutes ago

That’s standard click tracking usually. No different than clicking on a sponsored Google result.

sorokod32 minutes ago

Sure, would have preferred an honest "we use standard click tracking service, it will totally redirect you to our website" or some such thing

Kuyawaan hour ago

I received so many of these requests to install malware that I removed linkedin from my life completely (besides the scam and spam flood)

Do not install anything on your machine, ever. Tell them politely ~to fuck off~ that you are not interested and move on. I know the desperation to be jobless will obfuscate your mind but again, never ever install anything on your machine when job hunting. I've seen people lose their crypto savings in seconds to say the least.

You've been warned.

sandeepkd4 hours ago

These seem like a common pattern lately. I feel for it but again people are creative in making business out of others desperation.

nottorp42 minutes ago

> The code is available on Bitbucket, which IMHO is uncommon

What? There is no world outside github?

The rest of the article is legit, but they had to insert some monopoly worship...

sixtyj3 hours ago

It reads like a true crime story.

Bad actor had prepared the set up so precisely that Claude Code could not detect it.

Malware Bytes? Acronis? There must be some template…

NalNezumi3 hours ago

.... Why would you do job interview when they expect you to run some code on your own system, on your own time?

Maybe I work in a different field but last year when I was still looking for jobs, only one company asked for coding assignment and every other company did coding interview which is always browser based editor.

I feel like the industry is mature enough that you can tell a company that sends you a zip file of code to f-off.

msdz3 hours ago

> .... Why would you do job interview when they expect you to run some code on your own system, on your own time?

Because both the company and you know it’s the most effective job interview “filter” in SWE roles.

> on your own time

It may not be unpaid if you’re applying to a decent company.

The issue here is their poor implementation (zip file), not the concept itself, IMO.

[deleted]3 hours agocollapsed

esafak4 hours ago

I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

https://opensourcemalware.com/blog/latest-contagious-intervi...

zuzululu4 hours ago

wonder if codex can catch issues ?

> A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.

akarshhegde18an hour ago

[flagged]

minitech2 hours ago

Slop article. Good for scam awareness I guess, but the main value of the analysis and advice is comedy.

> read process.env directly, which in this app means MONGO_URI, JWT_SECRET, SENDGRID_API_KEY, CLOUDINARY_API_SECRET, PAYTM_MERCHANT_KEY

yeah it can run arbitrary malicious code, but let’s also highlight that it can read the fake app’s own dummy environment variables

> When the victim connects out to […], the server sees the source address on the accepted socket, exactly as any web server sees a visitor’s IP. No discovery, no scanning, no registration of an address. This is precisely why outbound-only design is so convenient for the attacker: it works behind NAT, CGNAT, a corporate proxy, or a home router with zero configuration, and it doesn’t matter if the victim’s IP changes.

huge

> If there is no UI/Desktop environment the module for leaking browser data or screenshots is self-limiting.

yeah this is why a VM is important, it’s because it doesn’t have a UI so screenshots don’t work

> … and reinstall your OS - better safe than sorry.

yeah just for thoroughness’s sake after having a RAT installed (hopefully you didn’t do this step last)

hn-front (c) 2024 voximity
source