How to compromise your system with a job interview

(codedge.de)

25 points | by codedge an hour ago ago

6 comments

  • john_strinlai 16 minutes ago

    out of the list under "Before you start with the test, you might be suspicious about the following:" there is only one that is important:

    only interact with people using an official email address.

    the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).

  • aliasxneo 30 minutes ago

    I get enough legit and illegitimate ones every week on LinkedIn that it's become really easy to tell the difference. Hard to pinpoint in a comment because it's mostly a gut feeling. But, in rough order:

    1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.

    2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.

    3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.

    4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).

    Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.

    • stevekemp 9 minutes ago

      Honestly unless I'm planning on quitting my current job, or if I were unemployed, I just ignore the linkedin.

      Sure they spam you with "XX wants to connect", or "I'm awaiting your reply" emails. But real contacts and friends can call/email you, and everybody else can wait six months.

      Despite only connecting with actual people I've worked with, not recruiters, I still get "suggested" posts which are slop, and "that happened". The site is a cesspool.

  • sandeepkd 29 minutes ago

    These seem like a common pattern lately. I feel for it but again people are creative in making business out of others desperation.

  • esafak 36 minutes ago

    I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

  • zuzululu 16 minutes ago

    wonder if codex can catch issues ?

    > A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.