Code to flood Kellogg with bogus job applications after strikers sacked
businessinsider.com
businessinsider.com
https://github.com/SeanDaBlack/KelloggBot/blob/main/req.py
Edit: The code is not PERFECT as MANY people have picked it apart below.
But if I had to work with this code on a daily basis I would certainly not mind.
If you ever need a code review just post your code on hacker news and say it's well written....
https://www.selenium.dev/documentation/test_practices/encour...
public class Login {
public void testLogin() {
// fill login data on sign-in page
driver.findElement(By.name("user_name")).sendKeys("userName");
driver.findElement(By.name("password")).sendKeys("my supersecret password");
driver.findElement(By.name("sign-in")).click();
// verify h1 tag is "Hello userName" after login
driver.findElement(By.tagName("h1")).isDisplayed();
assertThat(driver.findElement(By.tagName("h1")).getText(), is("Hello userName"));
}
}Into this?:
public class SignInPage { protected WebDriver driver;
// <input name="user_name" type="text" value="">
private By usernameBy = By.name("user_name");
// <input name="password" type="password" value="">
private By passwordBy = By.name("password");
// <input name="sign_in" type="submit" value="SignIn">
private By signinBy = By.name("sign_in");
public SignInPage(WebDriver driver){
this.driver = driver;
}
/**
* Login as valid user
*
* @param userName
* @param password
* @return HomePage object
*/
public HomePage loginValidUser(String userName, String password) {
driver.findElement(usernameBy).sendKeys(userName);
driver.findElement(passwordBy).sendKeys(password);
driver.findElement(signinBy).click();
return new HomePage(driver);
}
}/** * Tests login feature */ public class TestLogin {
@Test
public void testLogin() {
SignInPage signInPage = new SignInPage(driver);
HomePage homePage = signInPage.loginValidUser("userName", "password");
assertThat(homePage.getMessageText(), is("Hello userName"));
}
}All of the Java codebases I've worked with, that have 20 levels of hierarchy to 'clean up' the code bases and make it easier to edit, turn into giant balls of spaghetti at some point.
Abstraction can be very useful, but it can also definitely lead to spaghetti if it gets out of hand or is done incorrectly.
1. undescriptive variable names (eg. data2)
2. inconsistent formatting
3. copy pasted fragments everywhere
- Complicated flakey in-line xpaths '//*[@id="content"]/div/div[2]/div/div[1]/div[1]/div/div/button' ?!
- Time.sleep(x) is flakey, you should wait for the element to appear
- case first_name | last_name both uses a first_name() generator, should just be generate_name()
- Opening and closing the driver 10000 times
Can you be more clear on this? I don't see where this is happening. There's a start_drive function that they call once in main and use that reference the entire time.
https://github.com/SeanDaBlack/KelloggBot/blob/main/req.py#L...
- Complicated flakey in-line xpaths '//*[@id="content"]/div/div[2]/div/div[1]/div[1]/div/div/button'
How else would you get around navigating the DOM which this has to match precisely?
- case first_name | last_name both uses a first_name() generator, should just be generate_name()
Very subjective?
- Time.sleep(x) is flakey, you should wait for the element to appear.
Agree with this but maybe it's not possible for some reason in regards to how the webpage is configured?
https://github.com/SeanDaBlack/KelloggBot/blob/main/req.py#L...
They run start_driver() inside a while loop with 10000 iterations
> How else would you get around navigating the DOM which this has to match precisely?
For that specific one I'd probably try "//*[contains(text(), 'Apply now')]", if they add a single element to that page the entire xpath will fail in the code example
> Very subjective?
Do you have two first names?
> Agree with this but maybe it's not possible for some reason in regards to how the webpage is configured?
Maybe! Still, I bet you it's possible to wait for an element even if it's your own action taking effect.
I mean wouldn't that allow 10,000 parallel operations? If you waited for each one to complete, then close each one, it would take forever.
EDIT: Gruez(below) made the point that the code isn't written to be async so this is definite issue.
> For that specific one I'd probably try "//*[contains(text(), 'Apply now')]", if they add a single element to that page the entire xpath will fail in the code example
You're prob right about this to be honest.
However, there's two elements with 'Apply now' on the page. A button with 'Apply now' and a dropdown with 'Apply now' that opens when you click that button. Lol
https://jobs.kellogg.com/job/Lancaster-Permanent-Production-...
Welcome to scraping hell!
> Do you have two first names?
It's generating fake names. It doesn't matter.
You can chain them! It's still better to [0] the text one and then click the pop-up than use div chains the whole way down. Yes it's not perfect, if I was testing the site as part of Kellogg I'd ask for test ids to make them unique, but it's still immune to additional divs.
> It's generating fake names. It doesn't matter.
This hurts my soul
>https://github.com/SeanDaBlack/KelloggBot/blob/main/req.py#L...
the call to "start_driver" is inside the "while (i < 10000)" loop
> 1. undescriptive variable names (eg. data2)
Doesn't matter. The file is 200 lines of code.
> 2. inconsistent formatting
That didn't make the code harder to read/follow.
> 3. copy pasted fragments everywhere
Meh. Really, I've seen code where everything that could be repeated was encapsulated in a function/method/class which was being used only once.
Right, I can follow the code just fine too, but OP's claim was
>well written, rather pretty code
Like you mentioned, the file is only 200 lines, so you can get away with quite a bit and still be understandable/maintainable, but that doesn't mean they're all "well written" or "rather pretty".
- Have you seen Carmack or Torvalds code?
> inconsistent formatting
- Needs more explanation? It's python, consistent formatting is enforced
> copy pasted fragments everywhere
- Nothing wrong with that AT ALL if you understand how it works. It's literally the fundamental premise of Github Co-pilot.
Which means it’s probably at least 80th percentile nowadays.
As far as developer quality goes...I'm afraid I'm not qualified to comment.
Additionally, there are plenty of red flags that any human reviewer would quickly pick up with these applications. The addresses don't exist. The random prior occupations it submits are rarely in line with what you'd expect for these positions. The name generator is pulling random first names for the last name as well. And the randomly generated email addresses contain names that don't match the name on application. So, the script will submit an application for "Susan Justin," a former Surgeon with the email address ronaldbrewer@example.com, at an address that doesn't exist.
I'm sure this is a nuisance for the HR analyst who's the first line of defense in reviewing applications. And they might've had to bring in someone with more technical/fraud skills to help weed out the fake applications, but it seems quite manageable.
[0] https://github.com/SeanDaBlack/KelloggBot/blob/main/src/resu...
Though they'll probably use that as an excuse to not provide insurance or pay a living wage... :(
That wouldn't be so hard to do, would it?
Edit: One thing I didn't think of was application source IP address. It's possible the ATS records that info when an app is submitted, so they could possibly delete bogus records that way but I'm no ATS expert and this is literally just my own conjecture.
I base this opinion off of ~6 year old data and experiences. The "best" horror story was an ATS that used client-side browser datetime without timezone support as their official timestamp record for various events.
If picketing IRL factories is allowed, what would the law be on DDOS of an online business by union members?
Even regular picketing sometimes gets sanctioned by the police. Just this October John Deere picketers were sanctioned for blocking a gate. [1]
[1] https://nptelegraph.com/business/deere-wins-injunction-again...
>Even regular picketing sometimes gets sanctioned by the police. Just this October John Deere picketers were sanctioned for blocking a gate. [1]
Did those actions get put down because it was labor action, or was it because those actions were not acceptable? ie. if I said [unpopular thing] online, and a bunch of protesters showed up to my house and blocked my driveway, preventing me from going to work, would it be reasonable for the police to disperse those protesters? would it be reasonable for me to get an injunction against those protesters to prevent them from doing it again?
Not sure how to respond to your example because its a different situation? Do you think workers are just angry in the same way the mob outside of your house is? Or do you maybe think they are just trying to survive in this world?
To me, this almost sounds like "it's easier to ask for forgiveness than permission, ie. what uber does, and runs counter to principle of rule of law.
>Do you think workers are just angry in the same way the mob outside of your house is?
so culture war protests = not fine, economic protests = fine?
To the second point, I don't think we need to decide on the fineness of either, in order to understand their qualitative difference.
I'm pretty sure union/striking isn't a valid excuse to violate laws, and that "picketing IRL factories" doesn't violate any laws (ie. they do in on the sidewalk/public roads).
A coal company in Alabama recently won a restraining order that fully prohibited a picket line at their mine: https://www.msn.com/en-us/news/us/judge-issues-restraining-o...
Manually submitting 50 job applications with false information also does not violate any laws that I am aware of.
The focus then becomes on automation. But if I automate the job application process at 1 application/day, that's not illegal. So it becomes a balancing act between how fast I am automating, and how shoddily designed the application system is.
I don't think it's as cut and dry as "this is illegal" or not.
But in the context of the parent comment ("what would the law be on DDOS of an online business by union members"), there's a valid discussion to be had.
If my code submits 1 fake application to each open position, once per hour or once per day (which is well within what I can do manually), and that code is shared between thousands of striking workers (and their supporters), and that results in downtime or inaccessibility, should that be illegal? If so, why? Would it be different if there wasn't code, but just thousands of strikers submitting applications as fast as they manually can and as fast as the website allows?
At what point does the responsibility lie with the company who isn't rate-limiting or captcha-ing?
Personally, I believe that if a few thousand striking workers decided to manually fill out job applications as fast as they could, as opposed to walking a picket line, that should potentially considered a valid form of protest. If the job-application-taking website fails or slows down or HR gets a headache, so be it. That's sort of the point of union workers protesting - cause headaches so their voices will hopefully be heard.
And at that point, what is the difference between a few thousand people manually submitting applications or using code to submit them at a pace which they manually could anyways?
Is holding up every car that enters or leaves the work premise not considered an intent to harm the operations of the company?
Is resfuing to do your job, slowing the overall production of the company, not considered harmful to the company?
What is the intent of the striking worker who airs their grievences on signs and media?
Striking, by nature, has the intent of causing grief/headache/slowed business/etc., in order to make demands heard.
My intent here is 100% to harm the company by hurting their bottom line.
A lot of it hinges on intent. If the people striking are attempting to overwhelm the service, I could see that being illegal, regardless of whether or not a program was used to assist in the denial of service.
Put another way, if I and a group of friends coordinate to call your office and tie up all of your phone lines, should there be legal consequences for my group?
>Put another way, if I and a group of friends coordinate to call your office and tie up all of your phone lines, should there be legal consequences for my group?
I think this is somewhat detached - your friends aren't striking workers trying to make a point - but I think it somewhat depends on what easily available mitigations I could employ. Can I simply block the numbers? Then I should do that. Can I rate-limit the number of times a certain number can call me? Then I should do that as well.
More illustratively, if my phone system is poorly designed and only accepts 1 phone call every 5 minutes or it crashes, should there be legal consequences for someone who calls twice in that 5 minute period? I say this, because if a website has no rate-limiting, no captcha, and can easily fall over -- is it really solely the fault of the striking workers who manually submit applications?
All systems are "poorly designed" if by that you mean they'll fail under pressure but this could have been prevented. It would, after all, be possible to design a car that is more resilient to running over a row of caltrops, it would just be expensive and unrewarding most of the time.
Of course, the person disrupting the system is a biased party. He shouldn't get to decide what counts as poorly designed in order to excuse his disruption; if you allow that, he's always going to claim that whatever vulnerability he found is just poor design. We don't think this is a good excuse for the NSA; it shouldn't be a good excuse for anyone trying to overwhelm a phone system.
Was my phone analogy poorly constructed? Yes. Does your extension all the way to NSA hacking innocent citizens make sense? No.
(IANAL, working from American perspective)
OTOH, if we're going to consider "sharing too much information to an individual for them to process it" to be a DDOS, there are a whole bunch of Terms of Service that will need to be rewritten. So maybe this is a good idea...
https://www.eff.org/deeplinks/2021/06/supreme-court-overturn...
> the Court adopted a “gates-up-or-down” approach: either you are entitled to access the information or you are not.
To me, it sounds like you are entitled to submit a job application or you are not. I don't see how a charge under the CFAA for submitting an application would stick, when they are inviting the public to submit applications.
You can't make someone using your computer a crime just by retroactively deciding that you don't like they way someone used it.
They are also the reason many corporations are immoral.
Or: most unions are legitimately just trying to improve the situation for their workers, and many business owners have a conscience and weigh more than profits in their business decisions. It’s mostly the mega-wealthy who have become disconnected from normal humans and give us these Snidely Whiplash characterizations that ultimately paint both sides with a bad brush.
Is it worse than what kelloggs is doing, spending money to replace striking workers rather than giving them a raise?
Maybe it's the Scots Borderer in me, but it warms my heart.
(edit ... link: https://www.wired.com/2010/01/guilty-plea-in-scientology-ddo...)
The DDOS would fall under (among, I'm sure, other laws) the CFAA and could be a felony if someone wanted to pursue it.
https://github.com/SeanDaBlack/KelloggBot looks like its still up for now
yea... why would they use their real name haha
The obvious reading is that they legitimately saw no problem initially and then realized later that it was legally questionable and yanked it.
Turns out those hunches are pretty reliable, who woulda thunk it.
it's the invocation of it that would be, right?
I'm strongly against the idea of using weaponized computer code to disrupt their hiring operations and flooding. Sounds like it is probably illegal.
I guess I am new to Ycombinator, is this type of thread the norm here? Seems pretty sketchy and I would say this is probably the lowest quality thread I've seen on this entire network this week.
As far as I am concerned, anyone has the right to disagree. The company disagreed on terms with some potential hires who wanted a better job offer and has a right to look elsewhere for employees. There is nothing more to it than that.
The community guidelines are an attempt at saying please be decent so as to foster a more desirable community. Think about it. That is why you are here and not reddit.
>>Be kind. Don't be snarky. Have curious conversation; don't cross-examine. Please don't fulminate. Please don't sneer, including at the rest of the community.
>>Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.
>>Eschew flamebait. Avoid unrelated controversies and generic tangents.
For example, if a tech union offered networking opportunities, resume-building help, internships, and access to companies looking for employees, I would join.
Typically engineers for example will join something like IEEE, ASME, or AIChE.
The reason for this difference is that in the case of well paid, in demand professions like engineering, it is typically a better strategy to just have enough money stored to to bridge the gap and move on to another job quickly if your employer is shitty.
Laborers don't typically have those privileges, so they form organizations that help them defend their current jobs.
And I would add, banning employers that use anti-labor tactics... Bring in "Scabs" ? Lose access to the best people until restitution is made.
Edit: I also think incentives can be better aligned by bringing more equity or corporate performance pay eg: you get $20 an hour base pay, but $15 an hour is actually in company stock or bonuses on profit etc.
IIRC westjet (canadian airline) had a lot of success making every single employee have equity pay ("be an owner/shareholder") ...
If you look at /r/antiwork you’ll realize that these demands are more and more moving goalposts. I don’t understand that subreddit. They think jobs grow on trees.
Why is this relevant? Does being labeled as a "striker" give you additional legal rights that you wouldn't otherwise have?
>It's no different than mailing in a bunch of applications, it's just digital instead. They aren't burning down the offices
"not burning down offices" seems like a pretty low bar for acceptable conduct. that doesn't mean their behavior is legal. The obvious analogy would be: would it be legal to spam a pizza restaurant with fake orders? Or spamming a doctor/hospital with fake appointments? Or spamming police departments with fake tips?
Actually, yes.
For instance, if you are an employee who is striking, you have the right to use racial slurs to abuse and harass employees who are not striking, without being fired for use of those remarks. See Cooper Tire & Rubber Co. v. NLRB. (Remarks included: "Go back to Africa, you bunch of f--- losers!", statements regarding fried chicken, watermelon, etc.)
There are a variety of other rights conferred by law.
Spamming a police department with fake tips is specifically illegal (making a false police report and/or obstruction of justice and/or USC 1001). I'm not sure about fake appointments for a hospital, that seems the most unclear of the cases you've listed.
A bunch of trump supports went to Washington to "protest" - not turning out very well for them. Similarly with many other protests (BLM etc etc), folks getting picked up breaking windows, stealing, burning down buildings etc - they don't get off free because it's a protest or there is not something in the law that makes calling something illegal a protest legal.
No one made that claim.
For anyone who has paid attention to CFAA if you have a computer used in interstate commerce and someone knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer, then whamo, down you go.
This code that has been written to disrupt the operations of this business (Kellog) if it does disrupt their operations and they complain, the person knowingly transmitting it is at risk.
Again, calling something a protest is not a free pass.
"Rutgers University professor Todd Vachon, who teaches classes about labor relations, said he's not sure the company will be able to hire enough workers to replace the ones who are out on strike in the current economy, and Kellogg's may have a hard time finding people willing to cross a picket line."
https://www.cbsnews.com/news/kelloggs-will-replace-striking-...
So yes. They have been fired. Kellogg has announced that.
They cannot fire the employees in question, they can only replace them 1:1 and w/ the amount of publicity, and the striking it's bound to deter a lot of potential applicants, and with people using automated and manual methods to spoof applications --some presumably locally even going through the entire application process, going through training, and quitting day one on the floor... seems to me like it'll bleed Kellogg's dry long before they ever find the employees they need to continue.
They're more likely to fully automate 100% of the plant before they find the staff they need for permanent replacements.
I'm seriously betting Kellogg's does a full reversal, esp when profits start to fall, and revenue expectations get dwarfed by the boycotts that are ongoing.
Personally, I can do without ever buying poptarts, eggo waffles, or any of their cereal. There's plenty of alternative junk food out there to fill the gap.
Your metaphor to police corruption is also why "context" is an important thing. In that case people would actually get hurt, in this case a company loses money. They are different scenarios completely.
Logic is not part of the CFAA.
However, Kellogg's is soliciting job applications from the public. Automating the submission of a single application is clearly legal, but submitting many with the intention of overloading digital systems is clearly illegal.
IMO, this case is legally ambiguous because they are using a digital system to overwhelm a human system.
The public is 'authorized' to submit one application, so it's hard to say submitting many applications is unauthorized, unless done with intent of crashing servers.
Yeah fuck it if this is bad, then I definitely don't want to be good.
By what principle does a group of striking employees have some intrinsic God-given right (or right conferred by some other source of truth, outside the law) to sabotage the company that they are protesting? Is the company their property, that they have veto power over hiring? Is the labor force their property? If there is some property-like interest that grants these rights, then under what circumstances would that interest became their property rather than the original worker's? Is it strictly first come, first serve? Is there a vesting period during which this right accrues? Are the striking employees as a group to be considered a form of government, that they may regulate hiring and firing? What elevates this right or interest over other cherished principles, such as free association? Or do the strikers simply wish to subjugate such principles to serve their own self-interest?
I believe that you propose mob rule. It is no surprise, then, that you are in conflict with a nation ruled by laws, rather than by mobs and strongmen.
If you have somehow gotten yourself into a position where you are supporting a family based on knowing how to do one thing that you can only do for one company, sorry but you either massive screwed up your life (unlikely) or you are afraid to step outside your comfort zone and work elsewhere (likely).
It isn't? In many parts of the US a car is needed to hold a job, or to even get to the grocery store (which might be miles away). Moreover, grocery stores do provide the means to "feed your family". Does that mean looting/vandalizing them is fair game after failing to "negotiate" with them?
I did encounter a password field bad enough that password management software generated passwords aren’t allowed but “Password12345” is.
Presumably it will soon gain one, if it hasn't already.
They have a browser extension too, I guess it detects the displayed captcha and submits it to the API
Finally repercussions for the sites not updating their recaptcha versions and annoying everyone with v2
This is not advice, just observation.
I kind of see the point that you're trying to make, but I'm sure you understand that not everyone is in the same position to pick and choose jobs that the majority of HN find themselves in. Often when someone takes a job, it's because they need a job in order to live.
It's pretty shitty of you to suggest that that individual should be barred from future employment because they had to take a job that was available, even if the reason it was available is disagreeable.
We're currently living in one of those rare times where there are a lot of non-questionable jobs going unfilled, and employers are a little uncomfortable with the number of job vacancies. So, if you have to take a job, there are currently plenty out there that keep your hands clean of strike-busting.
Sure, but "ethically questionable jobs" is a pretty massive spectrum, and I'm not sure that I would agree that "making cereal during a labor dispute" meets the line of "to unethical for me" for the majority of people.
> So, if you have to take a job, there are currently plenty out there that keep your hands clean of strike-busting.
So is strike-busting the only place you draw the line? What about having to take a job at Hobby-Lobby? Or Chick-fil-a? Amazon has some some pretty sleezy stuff, so you don't want to support them. Walmart employees often depend on food stamps, and you should keep your hands clean of supporting a company that treats it's employees so poorly.
There are tons of jobs that you could take in order to keep food on your table that aren't Kellogg, or Hobby-Lobby, or Chick-fil-a, or Amazon, or Walmart.
If you keep digging, you'll quickly run out of "non-questionable" jobs. You are definitely welcome to blame the employer for their actions, policies, and decisions, but it's not fair to say "Well Jonny over there once worked at a company that I have an objection to, so he should never be allowed to have a job again!"
David Dick, of Old Forge PA, letter to the Scranton Tribune, 1902:
"A short time ago, my son, James Dick, had his home attacked at night by an angry mob. The windows were smashed and the house so damaged that he had to move his family out and come to my place for shelter. Now, why these depredations? Because my son and I try to earn a living for our families..."
JR Gorman, employee of Exeter Shaft, West Pittston: "They hung me in effigy and hooted me in the street. I had to go armed."
Of a miner named John Colson: "Five years before he had been in a mine explosion... Colson had been taken from the mine for dead, but he finally lived, blue-scarred, wholly blind in one eye and almost blind in the other... [W]ith the strike came hard times, and [his] sons, though willing to help their parents, had many mouths of their own to feed ... so that old John Colson was compelled to go back into the mine. He told me he was doing [an African-American's] job, turning a fan in a deep working, and he earned only 75 cents a day, but he was glad to be employed again."
Of the mob that attacked John Colson: "The police had warned him of his danger, and he had, indeed, already been stoned, and yet, naturally fearless, he was going back alone. Having a revolver, he thought he could defend himself. A trainload of soft coal was passing; a mob of men appeared, shouting at him threateningly. He reached to draw his revolver, and a man on one of the cars dropped a huge block of coal on his head. Colson fell in his tracks, and after further beating him, the mob robbed him of his revolver and a new pair of boots, and left him for dead. For three days he lay unconscious in the hospital..."
John Colson's mother: "He might better be dead, for he's brought disgrace on the name... He deserved all he got. He wasn't raised a scab."
— McClure's Magazine, XX, November 1902 http://moses.law.umn.edu/darrow/documents/Right%20to%20work....
120 years later, the enemy of the Union is still systematically Otherized, and deserves to have his life destroyed.
Don't worry! All the abuses of capital, the Pinkerton stories you've heard of? Those, and worse, are all quite real too!
I don't believe that anyone taking these positions are doing it in order to advance their career.
> will probably leave them worse off
Worse than homeless, starving, and possibly dead?
The suggestion isn't necessarily moralistic. It's just a way to bring about collective action. In a strike, workers are sacrificing their immediate benefit for greater benefit in the long term. Workers generally win concessions through collective action. It didn't work here because unions in the U.S. are weak. If workers were better organized, they would have stood a better chance. Well organized labor benefits society as a whole; just look at the Nordic countries.
This is literally in reply to the company firing all the workers who used collective bargaining.
The collective bargaining I was suggesting was to talk with your own companies which have a business relationship to Kellog.
Work in a hotel that has minicereal boxes? Get with purchasing to stock a different brand. Work in a grocery? Ask the owners to stock a different brand on a public forum.
See Kellogg flakes at a friend's or family's house? Ask them politely not to support union busting.
Daily call one local business until they agree not to stock Kelloggs.
Collective bargaining might help, but even Kellogg's union isn't capable of doing much -- only one factory is striking. Why would an unaffiliated union spend huge resources on helping Kellogg workers rather than its own members?
Because otherwise unions will target them, in turn, with worker's actions. That is how union power works in places that have real, functioning unions.
Unions protect workers against exploitations, and that is good for everyone.
Heh, reminds me of a song: https://www.youtube.com/watch?v=Ww5l5BAJ39A
Also, both Kellogg's and Post make shredded wheat and Raisin Bran.