Father-son duo helped techies ‘hack exams’, earn top scores for big payday
theprint.in
theprint.in
The whole ecosystem and culture around this is just ridiculous. Despite entering this career field with undergraduate and graduate degrees in CS from serious universities, the first (and only) question that people asked me was, "what certs do you have?" People go around talking about which "cert" they want next, and which ones are the hardest to get. People list all their "certs" in their email signatures after their name. People really measure their worth, and the worth of others, by these things.
So I've played the game by reading the exam guides and taking the tests (the military pays the $300-$1,500 testing fees for us in most cases, at least) and got "my certs." Now I'm a CISSP, CISM, CEH, and CCNA. The content of the exams isn't all bad; it's certainly different from academic CS and more applicable to managing IT. But these are just multiple-choice tests that one can easily pass with superficial knowledge obtained from a 100-page exam guide. Someone asked if CISSP was the hardest test I've ever taken... no... my final exams for Theory of Computation and Advanced Algorithms were...
Anyway, I've come to find out that most people don't even read the exam guides to learn what little material they contain. The typical approach, apparently, is to acquire a "dump," which is the bank of actual questions, and then repeatedly take "practice exams" so that they've already seen (and memorized) all of the questions that they might encounter during the actual exam. So, blatant cheating. I think this is very well known throughout the military IT community, and probably among the certification vendors too, but everyone turns a blind eye to it. If we stopped it, then most of our staff wouldn't be allowed to work on the LAN (see above), and then how would we get anything done? If the certification vendors stopped it, then the money would dry up as fewer people would take their exams.
I've also done network stuff, it's quite a lot more technical. But in the end it's still a silly thing to do multiple choice for. Debugging a network is a skill that's hard to boil down to that kind of exam, though to be fair they do show you how in the courses.
There is no substitute for hands on with real hardware.
I know there are a few areas in which they are seemingly unavoidable, i.e. government, military, financial. But if I see certifications on a profile I am interested in and I believe we have a role that matches what the person is looking to do, then I will use the more unscripted part of the interview to go to first principles and test the foundations of CompSci understanding with far fewer buzzwords.
This was before all the bootcamps arrived but even then I wouldn't completely dismiss it.
That isn't really the question because I haven't written a resume since 1992.
The way the content of the exams came about was, Sun's super smart engineers thought really hard about questions like, "How can we build enterprise-scale software predictably and reliably in the future?" They came up with some ideas that seemed self-evidently true, turned them into a design orthodoxy, built massive technologies and frameworks to enable/enforce them, launched it with a tidal wave of marketing that is hard to imagine now, published hundreds of pounds of books, and created a system of certification exams all before getting enough experience with the technology to realize, "Gosh, we thought this would be a good way to build enterprise systems, but it really isn't." If you got a Java enterprise certification around the year 2000, it largely consisted of indoctrination into ideas that were about to be tossed into the dustbin of history.
At the time, I would have taken any job I got, and getting more Sun certifications like their Enterprise Architect certification (which meant you could explain why EBJ 1 was a really great idea) seemed like a good way to make myself more employable, but luckily for me, shortly after completing the Web Developer certification I got a job unrelated to enterprise Java, and I escaped further investment in that world.
cheating is definitely rampant. I find that when trying to find study material for exams, half the search results are exam dumps
And I do see it from their point of view: certs are a low-effort (on their part) way to weed out obvious frauds and scam businesses. They're borderline useless, but are at least indicative of effort.
To me, this feels like the same problem as OKRs in an organization. When your goal for success is a high score on the exams for a job rather than the ability to do the job, folks will optimize for the high score on the exam. Setting hard goals that determine success will determine where folks spend their time. Along those same lines, I don't see this as a problem for third party entities like CompTIA/(ISC)2/ISACA/Cisco/Etc to fix, but rather poor management and expectations of employees.
OKRs and certificates aren't bad, they just need to measure the objective value to the organization as opposed to arbitrary standards (such as you must have X certificate to work here, or increasing pay based on certs earned).
Those tests mentioned above can be useful litmus tests for folks in the recruiting space to sort through candidates, especially if they have a large number of applicants, but I worry that it excludes folks that could otherwise be very good at the job/role.
Stupid example: You build a rocket, fly it, write how you did it. That demonstrates a certain understanding of physics as
If I want to require an understanding of basic physics I can require people to have done a project which satisfy that requirement.
I've been doing something similar for hiring junior engineers and how well they perform creating a project is the single most important factor to forecast their work performance. No leetcode required.
On the other hand, it is how computer security often does work. I can't count the number of times I've had to go through a listing of false-positive flags from some braindead OWASP checklist penetration/vulnerability tester.
A true AI will not only pass the Turing test, it will do so by cheating.
The HTTP specs places no limit on URL length. All the specs say is that browsers have finite limits and recommend that everything that transmits or receives URLs allows at least 8000 characters.
A bit of Googling suggests that Chrome can handle URLs of up to 2 MB, Safari 80K, and Firefox somewhere above 64K.
I can't find anything on how long a URL that the popular shorteners can handle.
A URL shortener as a method of data exchange.
The data URI spec does not define a size limit but says applications may impose their own.
Chrome - 2MB for the current document. Otherwise the limit is the in-memory storage limit for arbitrary blobs: if x64 and NOT ChromeOS or Android, then 2GB; otherwise, total_physical_memory / 5 (source). Firefox - unlimited IE ≥ 9 & Edge - 4GB
You also could use blob URLs, which have a 500Mb limit.
An example: 1. Alice constructs a data url with the base64 encoding of a zipped and encrypted document, submits it to her favorite URL shortener and gets a short URL back. 2. Alice transmits the short URL to Bob, perhaps as metadata in an cryptocurrency transaction. 3. Bob receives the short URL, navigates to it in a modern browser and extracts the data.
This is not anonymous unless the shortener is guaranteed anonymous, which it won't be.
[1] thatsthejoke.jpg
I'm guessing no, because what could be the incentive to doing that unless there's money involved? Why would someone who passed the test and gained the cert want to dilute the value of the cert they just earned by making it easier for people further down the pyramid to pass the test?
1. Those might even include answers written by previous test-takers. Memorisation of such answers would be futile because the questions change from year to year.
Work pays us to study, take the exam and even pays a bonus if we pass.
Am I smarter as a result of that exam? No. But I'm easier to sell. Some clients ask directly for certifications, others ask leading questions to our sales people I think.
Would i put my certifications on every variation of my CV for any job I apply for? Probably no.
While I'm at it: Someone else here writes about instantly rejecting people because of shibbolets like certifications.
I'm fairly smart, well liked by colleagues and very well liked by customers. However I have been dumped in screening I don't know how many times, dumped during interviews etc for something nobody told me but now seems to be gone.
Well everyone who didn't take me seriously: Thanks! I'm now a consultant working somewhere else with someone who pays better. And I am very motivated to give your competitors an edge ;-)
It's definitely going to be a "you get out what you put in" thing though. Folks trying to rote-memorize dumps aren't going to get anything out of it. Personally, I used practice tests to evaluate and tell me where I needed to go back and study more, and then jumped back into the material in those places.
All these certs stuff they re like uni, you know all they prove is very theoretical and you must have too some genius colleagues who can code amazing things but somehow never deliver and some messy dude who iteratively build the money printing software that pays for all this theory.
So, no better test than the client for me.
Im always surprised at the lack of follow through I see at so many levels.
http://ravimohan.blogspot.com/2007/04/learning-from-sudoku-s...
Interestingly, when I decided to get a ham license, the method you describe as cheating is precisely how every single person and resource recommended preparing for the exam.
I find it fascinating that certs are seen as so important in the military. I work for a Fortune 500 company and we care nothing for certifications. We don’t even really care about education (unless you are applying for an internship or first job out of college). Real life work experience is all that matters. When I look at a resume and see a bunch of certificates listed, it makes me suspicious that they are trying to disguise lack of ability with multiple choice tests. But, that mostly comes back to not having any faith in certificates.
Ideally the pools are far larger than the questions you'd receive on the actual exam so trying to memorize the right answers is actually harder than engaging with the material. These test providers could do the same thing. They should expand their test pools to be extremely large by tweaking the values in each question so that one Q becomes 10.
Prior to the federal government publishing question pools (I believe FAA does too), testing groups would send in folks to sit for the exam, memorize the questions then run outside and record what they saw. Do that enough times and the question pools emerged in their records and then they grew a big business selling that "dump".
I can't imagine managing large question pools manually, but with digital tools it's become trivial in edtech circles. Why these test providers don't end it is beyond me. (Probably because the federal "cert" game status quo is plenty lucrative.)
We had this debate between dev in my company because the execs want to see everyone certified for the cloud provider they spent millions choosing without asking us, fine.
So myself I did it the hard way, spent 20 hours studying for this things, preparing for the exam, building little things to make sure I got it, to a point I feel really a lot less noob on the thing and actually start buying into it. I passed with flying color and it took me a quarter of the alloted time at the exam, fine.
But I have colleagues who just asked me what bank was the closest to what I saw at the exam, tried and only studied where they failed, some barely passed, some barely failed, and I insist each time it s better to have a holistic theoretical understanding rather than just a quick practice run but are they worst colleagues ? Some have kids, some are my managers, some are so humiliated to have to be revalidated as competent, they just cant enjoy it. They dont cheat, they do the absolute minimum to get a grade and move on.
And I challenge you to tell you never did that in your entire studying life. I remember a class of compilation theory when I was 19 that I studied the 5 hours before, and forgot 5 hours later to get a 45% grade that still passed my year and fine. Did I cheat? Hell no, but I was lazy and did the bare tolerable minimum.
But, should we certify people in IT like that, I think your manager and your team and your clients already know what you're worth, so I agree it s pointless.
I've heard of something similar.
One of the employee suggested that he didn't need the cert. This really didn't sit well with management. Then he explained why: his previous job was on the team building said cloud product they decided to use. That was the reason he got hired.
Useless to say he didn't work there long.
These things are a racket. Mostly for the companies making the test but below them there's also the whole ecosystem of business trainings, people selling "exam guides", private tutoring and what not. It's very close to a pyramid scheme.
That being said, my trainings from SANS where useful but wildly expensive. The most fun were trainings by Offensive Security such as OSCP. Good luck passing that one with just a few exam trainings.
> The typical approach, apparently, is to acquire a "dump," which is the bank of actual questions, and then repeatedly take "practice exams" so that they've already seen (and memorized) all of the questions that they might encounter during the actual exam. So, blatant cheating.
Children I know in UK high schools (12-18) are being "educated" solely in this manner that you describe as cheating.
I don't think you're wrong.
Basically, the "teacher" gives them past exam questions to do right from the very start of a 5 year course. They never get any reference books (nor online equivalents), they're not taught the subject matter, only taught how to answer the exam questions. It's diabolical but what passes for state education at the moment.
To clarify, I have no problem with practising on past exam questions but you need to actually educate people before you ask them to answer questions on the material.
In school I was very idealistic about learning: prioritizing understanding over grades---even a bit to my detriment. But forcing me to do pointless learning sure brought out my cynic.
In one Sherlock Holmes story, Watson is appalled to learn that Holmes still thinks the sun revolves around the Earth. But Holmes resents this new fact. It clutters up his well-organized memory with useless trivia. He tells Watson he can't wait to forget it as soon as possible. I'm as eager as Holmes to forget all I learned. It kind of shakes my identity to see myself thinking that way.
And it turns out the cert is only good for 3 years. Then I need to do it all over again. Or write 20 blog posts about networking and get them approved (for a fee I believe). I wonder if this explains some of the dumb tech blogs I see.
Like others here, I've always felt certs were a more negative signal than positive. Mine is on my resume for now, but I'm a little embarrassed by it---how crazy is that?
Which represents a real conundrum for job-seekers: you never know if you're talking to somebody who think certs are required, or somebody who thinks that lack of certs is required.
Have never done Network+ but I did another similar one that allowed a short (maybe 1-2 hour) refresher course to renew after the 3 years, and I didn't have to go through the whole test again.
The numbers that I see for "Big Tech" software engineers seem to be in a whole different universe, though. Better to keep practicing for your algorithm interviews.
From about 2002, Australian Quality Training Framework (now reorganised as the Australian Quality Framework) deemed you unable to continue working in your area of expertise and demanded you get certification. Outward Bound instructors with 20 years experience would suddenly find that a neophyte with a certificate was deemed able to direct dangerous rock climbing experiences, while they could only look on in dread.
Certification was a turf fight between different bureaucracies: State versus Federal. Of course, the Federal Government won the battle, as they controlled the purse strings. University qualifications and technical college qualifications, all provided by state institutions, were ignored. A plumber had no need to sit a technical college exam. A federally-approved privately-run Registered Training Organisation (RTO) could provide you with the appropriate certification. It was all too easy. Hand over the money and take the certification test. The hack for a fork lift driver's certificate was to turn over the test paper: the answers were written on the back!
It should have been a national scandal. But, of course, we Aussies are too compliant. And in the end, the federal bureaucrats expanded their empires. I seem angry. And yes I am. Worthless paper certification is hiding the risks being taken with Australia’s future.
The trade jobs are traditionally where the disabled/dyslexic/neuro-quirky(?) excel IMHO because of the one-size-for-all nature of exams.
https://qualifyme.edu.au/rpl-skills-trade-recognition/
Pretty sure it's a revenue raiser and does fuck-all for anyone else.
> You will need a certificate for these skills. Have you been doing the job for 20 years? Sorry.
I've encountered an alarming number of people with decades of "experience" who were in fact incompetent. Certs are a bad solution, but they're a bad solution to a real problem.
It truly is "The Lucky Country".
1. Impersonation during an exam/interview.
2. Project work; end to end.
4. University degrees, including PhD end-to-end. You just need to attend a few classes.
A poor or lower-middle income family has very very few escape routes into middle income group. Educational credentials is one of the best ways. A college degree opens multiple doors; government jobs, interviews in private companies etc., So the clamour to get educational degree in India is almost unprecedented. For example, the competition to get into IITs is immense. Google "Kota tuitions" for gory details. Here's a small example[1][1] https://timesofindia.indiatimes.com/home/sunday-times/deep-f...
This is true universally, so I don't think it explains why some people in some countries are extra desperate to get degrees
There's a _lot_ of very poor people in India, vastly more so than in a "fully developed" nation.
But at the same time, India's recent economic growth is enormous, giving a far larger percentage of the population opportunities they've never had before.
But there's enormous competition for those opportunities.
So basically it's the right moment (more like "right half century") for India to have this problem, there's so much opportunity but also so much competition, that each small step forwards academically can mean a jumping a generation ahead of the curve on economic growth.
To put it another way, you can model economic development by chucking a lump of meat to a school of starving piranhas.
What does this even mean? Is there some dataset of all exam questions? And to what standard is it capable of answering them? Do you have a source to substantiate any of this?
GPT-3 is certainly capable of regurgitating facts, even to the point of rewording them, and connecting a small number of facts together. But it's not capable of making logical deductions in any consistent manner.
Here are two examples. Everything after "A:" was generated by GPT3 Neo.
Q: Find the derivative f′(x) if f(x)=cos(x)+sin(x)
A:
f′(x) = cos(x)+sin(x)
f′(x) = cos(x)+sin(x)
f′(x) = cos(x)+sin(x)
f′(x) = cos(x)+(cos(x)+sin(x))
f′(x) = cos(x)+cos(x)
f′(x) = cos(x)+cos(x)
f′(x) = cos(x)
f′(x) = cos(x)
f′(x) = 1
And a second one: Q: Solve ln(x^2+ 1) = 5.
A: x^2+1 = e^5.
Q: Solve ln(x^3+ 1) = 5.
A: x^3+1 = e^5.
Q: Solve ln(x^4+ 1) = 5.
A: x^4+1 = e^5.
Q: Solve ln(x^5+ 1) = 5.
A: x^5+1 = e^5.
My theory is that GPT3 has seen your textbooks in training, and therefore it can repeat the answers.I don't believe it knew my exam questions because I translated them from Czech printed books. I tried computer science and literature questions - it got 100% on the literature section (5 questions) and 4/5 on the CS section.
I'll try again later and post the log too, but I'm on the go now.
Citation? I haven't heard of it being that good at such a general task, and DDG & Google don't seem to return any hits for that statistic.
Having said the above, unfortunately there are very few ways to do all round assessment of individuals in a purely objective manner. Human biases would always be there in subjective assessment and an interesting thing i see in India is that a lot of people mistake English speaking ability and communication skills for overall ability.
The ones that skew towards heads down work ask a lot of LC questions (the kind cheated on in the article).
These are that you can find the exact solution for in the time it takes you to read the question out loud for the interviewer...
-
Meanwhile ones that skew towards leadership are asking questions that you can't cheat nearly as easily on.
Having in-depth conversations with technically knowledgeable people, sure you could maybe you could get some sort of teleprompter, but the breadth and depth of knowledge being asked means you'd be hard pressed to keep up if you didn't already know the domain pretty well.
There's also a greater focus on talking about yourself, like things you've done for example. Now you can borrow someone's story, but again, it's many many times harder to deliver it convincingly than it is to deliver a LC answer that has a known optimal solution that you're already expected to follow near verbatim.
-
The difference is simple, the amount of resources you're willing to put into testing.
Places asking LC questions are doing so as a cheap filter.
Places assigning a high ranking engineer to talk to you are making an investment.
I understand the dilemma a few companies in tech face, like FAANG. There's so much demand they can't afford that in-depth approach for everyone.
But I do see a problem with how systemic the cheap filter approach has gotten. So many companies hurting for applications in the pipeline are putting up silly hoops that ironically seem to favor people who aren't that technically experienced.
I mean who's going to do better on a LC Hard with dynamic programming, the person who's spending 8 hours a day at work writing code, mentoring, doing code reviews, meeting stakeholders, etc... or the fresh grad who spends 8 hours a day running through your company's question list on LC?
I recently saw a post on Blind about a company dealing with a bad hire... they hired a CS PhD as a Senior dev only to find they were executing at the level of a Junior. Want to venture a guess as to how they managed that?
[1] https://testing.uic.edu/tests-administered/proctoring-servic...
Perhaps India is a culture where academic/certification performance is highly valued, instead of hands-on experience. However, if "cheats" end up getting all the jobs because of that, and they end up performing well in their jobs, there is really no harm[*], other than highlighting how certification is useless. If they end up performing bad, commercial interests should incentivize employers to not look for good academic/certification performance anymore, like it's done, for instance, in most IT jobs in the "West".
I've witnessed plenty of cheating in my University days, and I never felt "threatened" by "cheaters": I knew what I was in for, and if they weren't, that's their loss (and win, because we were not matched against each other). The only regret I have is that many of them ended up taking teaching jobs (I can't see how they can properly make their students excited about the art of CS), but it's because those good at CS had good industry jobs waiting for them at significant pay raise compared to academic careers (so it's not academic scores that hindered them from continuing in academia).
[*] Sure, principled cheaters (it may sound like an oxymoron, but it's not), should try to get rid of the certificate-valuation (by eg anonymously exposing how easy it is to cheat, and how irrelevant it is to their on-the-job performance) to stop this money-grabbing scheme altogether.
He looked nothing like his linked in profile, but i gave him the benefit of the doubt since maybe it was an old picture... It wasn't. All this was over video chat..
https://www.youtube.com/watch?v=47mfohGyeBg
https://www.youtube.com/watch?v=HpGGmE4ayLY
https://www.youtube.com/watch?v=09gS6TykNQM
Not just in India, even in Canada, to make the top dollar and join upper middle class league, new breed of cons always game the system and use shortcuts. Once they join the class, they game the real estate market. Cycle goes on and on. They always win, rest of innocent ones who comply with rules and system are stuck behind with minimum wage job and renting single rooms, never get to ever see a dream house of their own.
That sounds like a failure of the companies to do a proper background check and follow up for proof of employment.
HR can realistically only check your last employer because anything older than a few years may as well be made up.
I imagine HR could ask you for a proof-of-employment letter if you said you worked at Microsoft and Facebook* for a couple of years but neither showed up on a background check. I imagine they'd be even more suspicious if you additionally didn't have any references from either company.
* Feel free to replace with any other "top companies" of your choosing
Without a network you’re screwed and it is probably much easier for me than for eg a fresh Indian person.
I also definitely thought of just lying and scamming to escape the min wage trap, but I was never confident in my ability to be duplicitous.
That's one explanation.
Truth is a degree or a visa doesn't check for employability (unlike in America where someone has to be able to secure employment to come or stay in the country).
> To counter that, he modified his resume and added 2 fake experiences from top companies as Network Engineer.
So he lied about being an engineer after doing a two year tech support degree? That would be a pretty big red flag to me (and by claiming he's a real engineer, he might get afoul of the law).
The brilliance was that he did nothing. If the person got in he would keep the money. If not, he would return the money!
https://www.indiatoday.in/mail-today/story/inside-delhi-hidd...
https://www.scmp.com/week-asia/people/article/3123929/indias...
https://www.newindianexpress.com/cities/kochi/2021/oct/31/th...
https://indianexpress.com/article/india/up-govt-fake-degrees...
https://redwiretimes.com/netizens-flood-ida-with-job-applica...
Edit: And the main problem with increasing the number of seats is corruption. You can't just give people money and expect them to create an institution that actually educates people. All of the processes required to make that work will have to be made and expanded etc. It takes a long time to go from corrupt poor country into a modern country where things like education exists in abundance.
I always thought the purpose of these kinds of exams was to determine if you had enough work ethic to pass them. The information actually included is peripheral at best most of the time.
- From an Expert who is good enough to pass an enormous variety of IT certifications but reckless and inept to cover his tracks.
- The splashing of the suspect photos on a national newspaper before their conviction in court. Love the note under their photo... "Photo by special arrangement"
- The ability to easily overcome most software cheating detection software etc...
There is a lot on criticism here of the education system in India and the Certification industry. Although many of the points raised are relevant, lets not forget that cheating in unfortunately prevalent at the most exquisite levels of Academic research in the so called developed countries.
Random sample:
------------------------------------------
"More than 60 Fall CS50 Enrollees Faced Academic Dishonesty Charges"
https://www.thecrimson.com/article/2017/5/3/cs50-cheating-ca...
"Luxembourg Prime Minister Bettel accused of massive plagiarism - Only two pages of 56-page university dissertation were plagiarism-free, magazine investigation finds"
https://www.politico.eu/article/luxembourg-prime-minister-be...
"German education minister quits over PhD plagiarism"
https://www.theguardian.com/world/2013/feb/09/german-educati...
"Guttenberg plagiarism scandal"
https://en.wikipedia.org/wiki/Guttenberg_plagiarism_scandal
"2012 Harvard cheating scandal"
https://en.wikipedia.org/wiki/2012_Harvard_cheating_scandal
------------------------------------------
1. Were caught.
2. Were publicized.
3. Were indisputable, and not in some grey boundary area.
Oh, that's cool...
...wait, you actually meant "to cheat", not "to solve a technical problem in a clever way".
It's infuriating to me as well.
If a site doesn't work without it, leave. Poor design correlates with poor content.
If you really want to read it, use a proxy site like archive or outline.
I generally keep it off while browsing for information.
When I'm doing local dev or working with trustworthy sites only, I turn it on.
After a while, the process of toggling it is almost automatic, though it still takes a few clicks and typing.
As I mentioned earlier, I've grown to avoid sites which tell me JS is required, and have found that it's mostly a good thing, because that type of design usually correlates with poor quality content, so they're really doing me a huge favor by denying me.
I will wait for the project to be open sourced (as per their stated intention in their FAQ) just for that extra bit of peace of mind, and reluctantly suffer with Safari in the meanwhile.
https://news.ycombinator.com/item?id=28799049
A WebKit-based browser for macOS with support for Firefox and Chrome extensions. I’ve been using it for the past month and uBlock Origin works perfectly!
More info about the extension support here:
If you give a user sudo privileges, and then they don't know what they're doing so they rm -rf or worse, then management puts you squarely to blame. If the user has a cert you can point to, and regs that say users with that cert may get sudo privileges, then you can point to the regs and the cert so that now the certifying organization is to blame. Or more likely the user will be blamed, malice will assumed instead of ignorance. Which brings to mind Bear's rule 11 (I'm Bear): Never attribute to malice, without investigation, what you can attribute to ignorance, as ignorance is common and malice is not.
duckduckgo for "india exams cheating": https://duckduckgo.com/?q=india+exams+cheating&t=newext&atb=...
Uh, don't turn off safesearch btw. Whoa that was crazy.
I have a close friend who used to get paid $5k-$10k per (Chinese) student to take tests fore them until she started looking too old to pass for a student. When she aged out she just started a "Test Prep Center", and now has about a dozen test takers working for her. She spent more $$ on her house in Palo Alto than I will make in my career.
That's just capitalism.