FBI: Stolen PII and deepfakes used to apply for remote tech jobs
bleepingcomputer.com
bleepingcomputer.com
EMPLOYEE: “uhhhhhh…. that was… uhhh… a deepfake who also stole my information?”
MANAGER: “oh okay. yeah of course you would never try to double/triple your salary by taking multiple remote tech jobs with zero oversight. my friend said it seemed so real haha. deepfake are so good now. im gonna report this to the FBI, people need to know.”
EMPLOYEE: “yea haha amazing. anyway i gotta get back to not-my-other-job”
If you are doing it as a non-hourly contractor, more power to you. But advertising OE as common place really hinders the paradigm of remote work.
As long as it’s a salaried position and you’re getting the job done at/above expectations, the company shouldn’t care as much as some of them seem to.
I have a hard enough time attending all the meetings and completing my work in my actual job, I couldn't imagine taking on another and balancing the two somehow.
One of the companies asked her to stay on as a consultant. They ended up hiring someone full time... who spent all their time in meetings, while my wife did the actual work. For significantly less pay, of course.
So yes, overemployed remote workers really exist, but at least in her case it was largely due to incompetent management.
What kind of consultant is paid less?
I could definitely imagine scenarios where a meeting-heavy middle/upper management job pays quite a bit more than consulting.
I mean, incompetent management may have allowed the situation to persist. But your wife "working" 2.5 jobs for (presumably) the expected hours of just one of those jobs can't be blamed on management. She chose to accept all 3 of those positions with the knowledge that she wouldn't meet the conditions of employ.
I'm not a "send 'em to jail!" type, and I have little sympathy for large corporations, but let's not pretend it's anything less than time theft.
But her time is not their property, and so there is nothing illegal about her doing with it as she pleases. You can’t steal something that is already yours.
US employers have worked very hard to make many of their workers "exempt" [1] such that they don't have to pay for overtime and can make people work egregious hours without getting in legal trouble.
If that's not "time theft", then I don't see why an exempt worker who can do the work of two people shouldn't get paid for doing the work of two people. It would be different if they were hourly workers and they were double-billing for the same hour, of course. But I don't think that's what's happening here.
[1] https://www.investopedia.com/terms/e/exempt-employee.asp
Most employment contracts I've seen stipulate an expected work week of 40 hours. If I sign 3 contracts like that, now I would need to work 120 hours to fulfill the obligation. And as long as someone collects the paychecks from all 3 jobs without fulfilling the contractual requirements of those jobs, well, that is sort of the definition of theft. Money gained without performing the work necessary to earn it.
Sure, there are lots of jobs where "time theft" is a useful concept, but there are a lot of others where it isn't. I'd go so far as saying that thinking in those terms can be another sign of incompetent management.
Of course not, which is why overemployed people hide this information from their employers.
The two full-time companies objected strenuously to her leaving and made various offers to keep her around. Would they have suddenly decided that they were deluded and that she was actually a horrible employee if they knew the truth? Possibly, but that doesn't mean they're in the right.
The real problem here is that a large portion of managers actually have no idea what constitutes a good employee or good job done. So they try to figure it out through second order observations like how many hours are worked, how convincingly the employee acts like they're good at doing their job, or how they report on their progress in meetings; and they get upset when they find out information that makes it seem like the employee should be doing a worse job.
I'm being a bit harsh, since I'm not immune to the same thoughts and uncertainties; I have an employee of my own who has two other part-time jobs and at times I've questioned whether that's OK. When I really examine the work he's doing, though, the answer is always the same: he's doing a good job, and the rest of his time is none of my damn business.
The reason employers would not approve isn't because the employee's attention is split, but because the employee would not be meeting the conditions of employment!
40 hours is the commonly accepted definition of "full time" in the US, and this is often written into employment contracts as well. Additionally, employers generally have expected working hours where the employee is available for meetings, mentoring, pair programming, etc.
So, how can you fulfill the expectations of multiple "full time" jobs while only putting in the time for one?
Realistically, it's a technical field and there are a lot of very, very poor candidates out there who will fill the seat for 40 hours but completely fail on performance. And I think that's why nobody was judging performance based on hours of butt in seat.
We (Westerners in general) would indeed be screwed if you could just replace people with cheaper workers from other countries. It's not that simple, though. Language and cultural differences are a massive barrier. I say that as someone who has worked with a lot of East and Southeast Asians who are brilliant, hardworking people -- but it still takes a lot of effort to figure out how to work together, and that's at a startup scale where you can really pay attention to each person. Larger companies tend to have a lot of outsourcing horror stories.
I have no regrets and still employ the same people today, but it just wasn't so straightforward as you're making it out to be. I think it's actually easier for a startup to have, let's say, an entirely Indonesian team including the founders, targeting an American market, versus a startup having an American founding team then start hiring in Indonesia. (For big companies I don't know, but I'd imagine it all gets even more complicated.)
I had no luck with it at all myself. I'd get completely useless low-quality crap work out of these guys when I got anything out of them at all.
I think you'd have to hire some local managers and maybe send over some experienced devs from the USA to train up the locals, at which point it'd only be a matter of time until they realize their new worth and jump ship for FAANG or whatever.
What about the IRS and employment tax your employer pays going to the wrong tax ID that should be reported to you?
I'm sure in some situations it'd work (1099, physical paycheck, lax process), but it seems like you're just setting yourself up to have to break more laws.
You'd be better off just using your own name and keeping a low profile online.
At least then you'd probably only be in violation of your employment contract.
It's stuff like this that's going to make providing recent bank statements and tax records a more common requirement for hire. :-(
For board members it's kinda part of their job but taking on 2 full time IT jobs is not going to be appreciated obviously.
I’m in the US. Ain’t got no contract for shit because companies don’t want to be committed to a deal with workers. The closest I’ve gotten to a contract is “don’t slander us and you can have this severance”
They didn’t leave California, mass, or New York which have major provisions protecting workers, and they chose to build in those locations before you saw them seeking out smaller cities and states
All without a written agreement? I'm surprised you could get people to work with you.
Your offer letter usually functions as an employment contract. The thing that spells out your start on a specific date, and we will pay you some amount in some given manner.
It really depends on your local labor laws, which vay from state to state.
> You'd be better off just using your own name and keeping a low profile online. At least then you'd probably only be in violation of your employment contract.
Ie, the crime being discussed isn’t having multiple jobs, but taking one job under a fake identity.
So, yeah, I'd say maintaining fake identities is hard no matter what and illegal.
But I think even before that folks are wondering how people can maintain several jobs at the same time, regardless of fake identity or not.
Faking your identity in the US for a job is breaking several laws. Explaining this behavior by saying "I was deep faked" probably won't satisfy law enforcement or the IRS.
Taking multiple jobs under your legal identity isn't in and of itself illegal. But you may be in violation of your employment contract. Meaning it's probably, depends on local laws, not illegal but gives cause to terminate you and possibly be sued.
What part is the current criminal activity?
You might be significantly underestimating the number of extremely gullible people out there.
taking a job under someone else's identity is illegal in the US and claiming you were deep faked if caught isn't likely to work.
"I'm gonna write me a new minivan this afternoon"
If only.
Perhaps the most important factor: if you have two jobs, you don't care about being fired.
Source: I'm an immoral, lazy, singly-employed person.
I’ve seen IT consultants make quite a lot of money from double dipping and they always seem so stressed which further makes management think they are doing a great job.
This does seem to be more of an EU issue though where management and economics are still among the highest status competences. Working yourself up the ladder here isn’t that common (they don’t earn that much more than the developers).
It can happen mostly when you are working for very big companies, they usually have too many people and projects take a long time to complete because you need to get approval from multiple people. If you already know how things work then you can quickly finish your main job work or sometimes there is no work which gives you time to do your second job.
EMPLOYEE 1: We should hire Homer. He was at my last company and great.
EMPLOYEE 2: We had a Homer at my old company, he was great. But he and I worked together at a different company.
> "Complaints report the use of voice spoofing, or potentially voice deepfakes, during online interviews of the potential applicants," the US federal law enforcement agency added.
Something about this doesn't smell right:
1) Don't video deepfakes require lots of high-quality input video (which is why they were often made of Obama)? Where would an attacker get this for some rando?
2) Why would voice deep-fakes even be necessary, given the interviewee is very unlikely to be known by the interviewer? I suppose it could be used to fake accents, but I don't think that would be an issue for a "remote tech job" -- just steal an identity that could plausibly have your accent.
You have it backwards-- the point is accent elimination. You don't need to sound like someone else, but you do need to not sound like someone of your own locale.
That doesn't make any sense though, given how many real tech workers are immigrants with accents.
What you say does make sense for someone trying to do certain kinds of fraud (e.g. an Indian scammer pretending to be an IRS agent demanding iTunes gift cards), but not for applying for a tech job.
There are some ethnic boundaries across which some employers are not willing to entrust remote work, and the response by the impacted demographic appears to be to double down on the fraud that led to the stereotypes to begin with.
Edit: you could also approach them as a love interest and get the video through chats.
I'd also be curious to see if there's an overlapping former employer between the candidates. If you found an archive of some employers zoom meetings you have all you need.
Okay I'm gonna stop before I get paranoid.
He speculated that some unscrupulous but relatively knowledgeable guy was sitting in for the interviews, and then coaching the incompetent applicants day to day for a cut of their pay.
In the end he just let the contract lapse. Not a whole lot you can do since it would be really hard to prove any kind of malfeasance, and to make the accusation would just make you look crazy and paranoid.
Her productivity skyrocketed at night however, and she generally had working code in the morning, which lead to rumors that her husband or someone in her home country was doing the work (would have been daytime over there). Nobody really complained. She wore a hijab and the company had just hired it’s first “diversity officer” so maybe that’s why. Thankfully they stopped using that vendor not long after. It's a story a friend told me a long time ago. I didn’t and couldn’t fact-check it.
The husband’s theory came from the fact she apparently mentioned her husband was also a software consultant.
Depending on the industry, it's definitely not fine.
I work in healthcare. If one of our employees was giving a foreign national access to our internal systems, that would be a Very Big Deal.
In practice, when you are a developer you get to know lot of infrastructure and even sometimes customer secrets from Facebook, Apple, Google, PayPal, etc.
This is because the tech people actually speak together, ask feedback and share information.
When a doctor doesn't know, he asks the other doctors for opinion.
There are even websites for that (StackOverflow, GitHub, etc).
It's fine. I trust my employees to use their best judgement when making such choices.
It doesn't mean these 3rd-party guys will get access to your systems.
Even the NSA asks for help, you can see them in the reverse-engineering forums, in MediaWiki conferences, etc.
Experienced developers are not teenagers and act rationally, they don't do 10 years of career to suddenly risk losing all their trust/friends and reputation, all that for 5-minute fame on Twitter for a leak that is likely non-strategic to the outsiders.
As long as the work gets done...
No no, it's trivial to prove. You just ask them to work from a supervised location for a short period of time and that they can't have their phone at their desk. You just have to care.
Something like that would have taken extra time and effort, and the problem took care of itself. He had more important things to focus on.
And I think it would have been more difficult to catch than you think. We don't do pair programming, and it's kind of reasonable to ask for time to figure something out. I think the best he could have determined was the guy wasn't good, not any of the suspicions about the scam of cheating on the interview and getting outside help.
Yeah and how many other employees took themselves out the door because they had to compensate for the nonperformer? I've been in teams with these sandbags and it's infuriating.
None.
> I've been in teams with these sandbags and it's infuriating.
The guy was on something like a three month contract, and a good chunk of that time was on-boarding then slowly getting suspicious. When we bring on contractors we expect some of them to be duds, the only thing interesting about this guy was his weird behavior.
My perception after reading a lot of this thread is that there's so much bloat and checked-outness in the tech sector that it's probably very feasible as an employment strategy to bullshit your way into multiple 3-month contracts, sandbag your way through the onboardings then fail to be renewed (without having done a day's productive work) then rinse and repeat indefinitely.
I don't know how much longer that will persist now that the free money tap has been turned off, though.
It's another world from the startup sector I know where you could tell within a week that a guy wasn't any good and you'd instantly show them the door because you couldn't afford the dead weight for literally another day. shrug
Could they get hired at a tech company and put in level-appropriate work for two years? Without domain-specific knowledge and experience? You're saying 'work hard for two years' presumably by that you mean produce level-appropriate or above-level-appropriate work?
You're basically saying that you think just anybody off the street with a 100+ IQ can 'just get hired' at a tech firm and do dev work, for two years, and then coast?
There's definitely an opportunity here to make a bunch of money at least pretending to fix this problem. Or maybe capital just decides to bring everyone back into the office.
I imagine it would be a problem in the US too, just for other reasons probably. You are essentially giving confidential work info to a third party that has no relationship with your employer.
Not a lawyer, but I don't see a deception charge for "under-performing and getting fired for it (while having 2 jobs)" faring well in courts.
Think about it: if you were performing your work well, despite having 2 jobs, what would the deception be? You promised to deliver work on your own, you deliver it on your own. The other job has no intersection with your other one, they are entirely independent. The only difference between that situation and the same situation but poor performance is literally just your performance. Poor performance doesn't automatically turn that situation into deception.
The law is interpreted by human beings, you know, it's not a 'code is law' situation. Remember that a jury would make the final decision. I can see a good lawyer using an argument along the lines of 'well, you said agreed to work FULL time. If a bucket is already FULL would a reasonable person expect the bucket to be able to carry any more load?' and winning.
If there is fraudulent intent it is illegal. The intent is what matters here.
How do you prove the employee wasn’t simply incompetent?
Wow. I can't imagine contracting work from people (and giving them access to commercial-in-confidence data) and yet not knowing with 100% certainty 100% of the time that the people I'm talking to are the people I'm contracting with, you know, the ones I background-checked, the ones I can hold accountable in court.
You know what happened with remote schooling? Teachers didn't demand that pupils turned on their cameras because of the same 'it'll make them uncomfortable' excuse. Result? Kids turned their computers on, their cameras off and played minecraft all day for 18 months.
Don't be odd about this. Nothing at all about face to face contact is uncomfortable for adults. That shouldn't be something that's normalised and it's detrimental to society to allow for it. You are literally reading an article that outlines all the negatives about your 'cameras are uncomfortable' mindset and you still haven't twigged?
Keep doing it your way, but don't be surprised when you've had your entire company's data exfiltrated and sold to a competitor by the 'person' you were too uncomfortable to ask to appear on video.
And don't for one microsecond retain people who mysteriously only produce quality work when 'unsupervised' or 'overnight' or when they're 'on the phone all the time.' Fire them! You have no idea who they're talking to or who's really doing the work. They're not an asset to your company, they're a bullshit artist!
Even in the same company I had teams where no one would turn on their camera and some where everybody would.
First, the top performers on my team right now are essentially ghosts. One I just went on a business trip outside the country with, and I hadn't seen his face for a year and I might not see it again ever. Another one is my "lieutenant" and in two years I've seen him face to face twice. No video. He's probably leaving the country soon and I don't care, because he'll be in the same longitude.
The other point, since this is FAANG, how is the conversation going to go with HR if I want to terminate someone because they won't turn on their camera?
Well, I guess going by what you've said they won't care either. I don't know how you can run a company productively over the long term if nobody cares, though.
If you think looking at a camera view of someone will prevent them from defrauding you, you are an ideal con artist’s mark because you’re taking your cues from the easier parts to fake.
This is also fine. But look at the reply below yours, when the 'team manager' is littering their comments with 'my top performers are ghosts' and 'I don't care.'
Your strategy involves focus and care applied through one perspective. My strategy involves focus and care applied through another perspective. Yours is arguably better, but I don't think mine is insecure, mine is perhaps a reaction to some of the nonsense I'm seeing in this thread in which managers admit they have staff who they think are outsourcing their work or just can't do the job but are 'uncomfortable' dealing with it. I don't think they're uncomfortable, I just think they don't care. I can't stand don't carers. I've had to work on too many teams managed by don't carers and staffed with don't carers and I just don't get the mentality. It annoys me.
I imagine that at some point, or even now, we can use transfer learning for deep fakes and just train existing models on a limited data set for "good enough" deep fakes.
Upwork removed the profile after some prodding. I feel like I should report identity theft to the police or something but I don't know if it's worth the bother?
Available for anyone to take and utilize. I have a (hidden) suspicion that a greater proportion of LinkedIn's reported "active users" are, in fact, a group of people with these profile images and fraudulent profiles.
If you have a US resident's stolen PII and can somehow set up a bank account to receive ACH direct deposits, and are a good enough social engineer, can possibly get hired under that name.
Then they'd refuse to hire me, refuse to address the issues I discussed, and then sometimes one of the interviewers would pass that information to the Russians or Chinese leading to a massive break ala OPM or Solarwinds even after Senator Wyden sent Chris Soghoian or someone of similar skill adjacent to the Omnidynar group to go ask some hard questions.
In parallel, folks with non-US passports would obstruct any applications I made in private industry in favor of those with their same passport.
It was all super frustrating, since my CV had the appearance of someone with a deep commitment to nonprofit work, when it often more than I made decisions like "Being a PhD student pays slightly better than a Papa John's employee and I'll eventually find something more permanent doing the latter".
Lately, looking back, I wonder if I'd have been better off saving up then moving to Thailand like one of my old drinking buddies did. (I don't drink alcohol anymore, and I'm spending the afternoon reading HN as I work on some technical projects I'll probably never put online, since it seems no amount of code publication leads me to a fair interview -- all it does is give tools for others to use in their "work")
Happy to reply again if the above is unclear -- I made sure to not use a nym that doesn't include my legal name, for privacy -- I could have been much more detailed :-)
...
> Then they'd refuse to hire me, refuse to address the issues I discussed, and then sometimes one of the interviewers would pass that information to the Russians or Chinese leading to a massive break ala OPM or Solarwinds even after Senator Wyden sent Chris Soghoian or someone of similar skill adjacent to the Omnidynar group to go ask some hard questions.
This paragraph is exceedingly unclear and may hint at the reasons why you are struggling to get hired. This reads as some mix of narcissistic personality disorder / conspiratorial thinking. You write like a native (or near-native) English speaker, but your composition is all over the place.
I don't mean this unkindly, but have you ever spoken with a mental health professional? Many technical folks are neuroatypical and this can sometimes be a barrier to traditional stable employment.
This individual claims to be somehow involved in two high-profile national security incidents. It's not beyond plausibility that they are being exploited for information by companies who don't want to be seen associating with them. Snowden would receive the same treatment.
Hacker news does attract some singular individuals from time to time, but I would suggest the more plausible scenario is that this person has untreated mental health issues.
Now, bristly replying aside: I also DO have anxiety, and wrote my comments earlier after too much caffeine.
>This individual claims to be somehow involved in two high-profile national security incidents. It's not beyond plausibility that they are being exploited for information by companies who don't want to be seen associating with them.
To give a real world example: one of the reasons I was pushed out of an NGO is I annoyed the lawyers pushing them to put MFA on their email accounts. Later we were one of the few not to be penetrated by the Russians... digitally... but when I watched that one Mr. Robot plotline where the one agent is increasingly unclear why her supervisor is not taking her concerns seriously, she finds out they are an agent of a foreign power.
Also I did a master's thesis on anonymity technology, so obligatory "it's not paranoia if they're actually out to get you".
>Snowden would receive the same treatment.
Snowden is stuck in Russia, a totalitarian hellhole. I live here, in the Paris of Appalachia, where I wander around sipping cortados and banging hipsters. We are not the same.
What often happens is I get a mix of people who respond in good faith (have no idea who the hell I am), paired with those who do, and say things in bad faith about my mental health.
(Reoccuring income would solve those issues overnight, email if you want a CV. I'm a decent pentester, can code in languages like Python and bash, and have an OSINT certification from Bellingcat.)
But often since my skills are more... qualitative (eg: I cannot write exploits well), people schedule an interview to treat it like a free consulting session (ask the one question an FBI agent would have if they could supoena me slipped in with the rest to clear me as a suspect in some bullshit), then don't actually hire me on... and the cycle repeats in 3-6 months.
Hence my supreme annoyance and occasional trolls.
Oh -- almost forgot -- in addition to the above, years ago, before I was doing brain experiments on undergrads alongside former Israeli snipers, I was in therapy. I found out at that therapist's funeral that he was a member of a motorcycle club. So sometimes... odd people boosted me through my career in civil society, and sometimes it feels like when I hit a wall, it's because someone in the past was supporting me for unsavory reasons, and doesn't have a good explanation for the sudden shift in allegiance.
I'm happy to explain further as needed, but all you really need to know is I ended up at a libertarian NGO despite being anything but, for reasons I don't fully understand, then got stranded in Appalachia by people who never want to admit they're wrong, even as I turn on the TV and see teachers who used to claim I was a menace to society running up on the capital.
TL;DR: I'm anxious because I'm a skinhead, in the antiracist sense, and a leftist, and the people who could assist me in my goal of being independent choose not to. I could join a firm like Mandiant or whatever tomorrow, be assigned some work, and be off HN and happy, but folks make the emotional decision to not allow me to do that, despite very clearly being qualified to, then question the mental health of a first generation PhD student with a dwindling bank account.
Any other questions?
:-)
That's putting it mildly.
Based on the writing, my best career advice to this person would be to take a community college English composition class and/or join the local Toastmasters.
Extra time spent working on communication skills almost always pays off more than extra time spent on technical skills.
The "overemployed" people generally aren't performing identity theft like this. Having multiple jobs ranges anywhere from legal to fraud depending on contracts they've signed or how they've misrepresented themselves (it's not uncommon to see suggestions to take multiple hourly jobs and then exaggerate the number of hours worked, for example). However, adding identity theft on top would elevate what they're doing to a major crime, which is not something that would help them.
Their goal is to find jobs and managers with low expectations, then sandbag as much as possible ("Gee, this task is harder than I thought. Going to take a couple weeks longer than we estimated!").
Had a team member try this and an old company. We caught on quickly when they couldn't keep up with their workload and were constantly unavailable during the day. Really sucked for the rest of the team who had to pick up the slack this person created by pretending to work full time.
i personally tried to do two jobs (with full agreement from both sides) splitting my week half half. It was a real struggle, but it is possible.
The key is to turn the thing upside down and seek out the jobs you’d normally reject - shifty companies with lower pay, bad tooling, tons of bureaucracy, etc - basically a place where no sane developer would willingly apply. Then, you’ll be the smartest person in the room without having to do anything special and the extra bureaucracy can be either automated away or come in handy as an excuse when you fall behind, while the lower pay isn’t really a problem if you have 4 of them running concurrently.
They currently sit at a 2.8 on Glassdoor.
Think of that however you will.
Last I heard, the executive who manifested this mindset is gone, too.
Poetic.
If my snark wasn't clear, it's a mindset of hiring and personnel management that I think is lazy at best, total shit at worst.
Not what I believe, but that's the logic they were using
If you want to do this “scam” in an ethical way without the reputation risk, just be a consultant, work for multiple companies, and be honest about it.
You won’t get benefits and finding clients will probably be harder, but you can set your own schedule and charge a lot more for your time.
But yeah being a freelance would give you the freedom (at the cost of more time spent selling yourself).
No, consultancies do not double-bill multiple clients for hours worked.
In fact, anyone billing a company in full for time that someone wasn't actually working on their project is committing fraud. Fraud that leaves a paper trail. This story would be brought to light very quickly by a disgruntled employee somewhere.
The solution is to escalate the "sandbagger" problem to someone who can fire and replace them, not cover for them.
I've also employed an engineer with multiple jobs (3 total). He's an active HN reader. I (sadly) wish they would have at least tried to outsource their work rather than not do the work at all and miss all their deadlines.
People then get the idea that they can juggle two jobs like that - but the trouble is usually not the work itself, but conflicting meetings and such.
Citation needed
1. People want more money.
2. Remote jobs are becoming much more common as of late.
3. It is (much) easier to double up on remote jobs than non-remote jobs.
4. Doubling up on remote jobs results in more money.
5. Therefore, there is a growing movement of people who are doubling up on remote jobs. QED.
I mean, it's pretty unlikely that this argument doesn't hold. I feel like you'd need a citation to counter it.
You don't need a citation to counter a baseless assertion. My assertion is that most people who apply for remote jobs are fairly honest (by culture) white-collar types who wouldn't think to 'double up on remote jobs' for the same reason they wouldn't think go out at night stealing catalytic converters, which is that they possess a basic sense of right and wrong.
I mean, if you think that the average person is basically a scammer at heart, okay... Maybe you come from a low-trust culture, I don't know. I don't think most people who come from high-trust cultures would behave this way or think that behaving this way is okay.
But many more are now compared to recent history.
Stealing catalytic converters is directly harming another person and also punishable with prison time, it's hardly comparable to working two remote jobs. But sure, some (potentially large) proportion of white collar workers may not be willing to violate trust by working two jobs, but many would.
Beyond that, if you think that all knowledge workers are ethical people, I would remind you about all the horrible software that exists in the world for the sole purpose of scamming or harming people. There's a lot of it. And it's all unquestionably much less ethnical than working two normal white collar jobs.
However I think a substantial number of posts are creative writing exercises
A lot of division trolling going on there, trying to foment labor militancy. r/antiwork is the most visible facet of it, endlessly trying to encourage strikes, calling out, sandbagging, etc. This overemployed stuff (people blatantly bragging about how they're getting so much money for barely working and how you're stupid if you don't try and scam the system) is another facet of it.
It's the usual suspects exploiting and widening any and all divisions in society they can find.
He quit when I started putting deadlines on work when he started falling behind. I got suspicious, reached out to his prior company's CEO to ask if he was still employed, and turns out he was! Then came the discovery of the 3rd company...
For hiring managers out there: make sure candidates have a linkedin profile that lists your current company as their current place of employment (both employees with 2+ jobs had their LinkedIn hidden for obvious reasons), and always run background checks that include employment verification screens.
For low paid service workers, it's acceptable and sometimes expected to juggle multiple jobs. Why is it unacceptable for office workers?
The overemployed game is all about exaggerating how much you're working and how difficult your tasks are. Targets, deadlines, and work scoping aren't chosen in a vacuum. We rely on the team to give us feedback about what they can accomplish in the expected full-time work week.
This goes both ways. If I'm handing out 80 hours of work every week, I need my team to tell me it's too much and I'll scale it down. The problem with overemployed people is that they must lie about their workloads and estimates to avoid being assigned more work than they can handle.
We had an overemployed remote person once. Like the parent comment, we noticed when they weren't performing at the same level as their peers (or even a reasonable level of expectation). They were also frequently unavailable for discussions, half-involved in meetings, and generally unreliable.
> For low paid service workers, it's acceptable and sometimes expected to juggle multiple jobs. Why is it unacceptable for office workers?
Low paid workers with multiple jobs aren't doing them simultaneously, but someone with two remote tech jobs is almost certainly trying to do both at the same time. Honestly if someone had infinite energy and could dedicate 8 hours per day to my job and then another 8 hours per day to another job and not overlap the two or run out of steam, I wouldn't care at all. But in practice, it becomes a constant game of lies and sandbagging that is just incompatible with running a fair and balanced engineering team. (Hint: It's often the coworkers who catch on before the manager because they can see very clearly that their peer is sandbagging)
You hire a doctor for a few hours, plumbers/lawyers for hours or weeks depending on the task, everything goes fine
but somehow software engineers have to come on board, sit at a company desk, wear a company shirt drinking company coffee every day
It'd be great if coders were organized as individuals and small groups that just took on tasks for fixed bids, like the fantasy world from the book "Developer Hegemony."
I could really go for six months off right now, but I'd have to fight tooth and nail to get it from my job, and it would severely hinder my career. So instead I'm just stuck chugging along until I've got enough saved up to quit and start my own company (or take some time off, then jump through a bunch of hoops to take on another prolonged period of full time servitude)
(Bringing it back to the topic at hand: That doesn't make it morally right to lie to your employer(s) and do a half-assed job. The overemployed people on Reddit/TeamBlind sound like a bunch of lying dirtbags who just say everything is harder than it is to cover for themselves slacking off, and aim to just get fired after a couple of years.)
Maybe engineering staffing practices should be more reflective of the possibilities, but that’s best for a single Org to define for itself.
At least for me I don't even have enough emotional energy for my current job, I can't imagine doing more than one. The trouble is this is impossible to measure and certainly isn't formally part of employment.
Similar story here. Person was clearly falling behind and was unreliable. The "it shouldn't matter if they get their work done" narrative doesn't hold up in practice, at least not with any reasonably utilized engineering team.
Now when I hire remote, I get in contact with the person's former company to confirm their start and end dates match the resume.
"<Start date> - current" prevents that problem nicely.
There are places outside the SF Bay Area
Sure they're typically hourly not salaried but that doesn't seem to be too major of a difference.
I don't even see what the issue is at all. If a person can get both jobs done fine, then who cares?
If this is indeed North Koreans trying to get remote jobs, I've been wondering if their game is: - Getting a job for themselves to bring income to their own household - Getting a job for themselves to bring income to the North Korean state. - Getting a job in a crypto company with plans of figuring out vulnerabilities and siphoning funds to themselves/the state. - Getting a job for others, and selling the service of passing the interview.
Basically, if you have the freedom to wander the internet, it's because the government provides your connection for their own government purposes.
This sounds so cynical. What if your freedom to wander the internet fills the same purposes?
The FBI has put out a warning - https://www.theguardian.com/world/2022/may/17/dont-accidenta...
Normal people are only allowed to go online in North Korea on state business.
Basically, hiring an consulting company masked as an individual.
It might be fraud, it might not. This sounds like SOP for literally every "recruitment" outfit I've ever encountered. Every single one encouraged candidates to tailor their credentials to the job requirements.
Tailoring applications certainly makes sense, so long as the output still reflects the skills and qualifications of the applicant.
https://www.theonion.com/more-american-workers-outsourcing-o...
> The "Okay?" is a DEAD FUCKING GIVEAWAY this guy is Korean.
....right.
First tweet:
> No bullshit I think I just interviewed a North Korean hacker.
21st tweet:
> In reality, I have no idea if these even were North Korean hackers. Bobby could've been, well, just a really incompetent dude.
I did find that, at least for South Koreans, they sometimes use "Okay" in a way that would be considered non-standard by Westerners (I have no experience with North Koreans). Often times they would use "okay" more as a check or confirmation that something was heard, than an agreement. So someone saying "okay" to you could mean that they acknowledge that they heard you, rather than them agreeing with your statement. Thus, it seems like the Twitter poster was pointing out that non-standard usage and correlating it with his Korean experience.
I'm immediately skeptical of tales written by someone who works in "growth" and has 60k followers from writing twitter threads.
Picture an adversary setting up a large deepfake campaign involving hundreds or thousands of fakes, esp coordinated with their use of the hundreds or thousands of curated social media profiles that have been raised on a media farm.
The fans would come up with dumbest possible rebuttals. Basically they liked her she was pretty therefore she was right about everything. And all the easy to verify facts were not important.
Step 1 of managing any celeb's social media profile is to add 15k of bots to their followers so you can 'forum slide' any criticism away at will.
You've just described half of Twitter's MAUs.
Wouldn't that be fairly easy to detect because the accounts would belong to an isolated, tightly-connected cluster?
Social graph metadata. The GGP said they would all be "talking to each other."
I think by 'detect' they mean 'detect by people who might fall for it' not 'detect by national security agencies.'
I don't see any way for the average social media user to detect whether they're engaging with a botfarm unless the social media company exposes their analytics, and they don't, and they aren't likely to start unless forced.
I actually was thinking the people who'd do the detecting would be the social media site operator (e.g. Twitter), who would then shut down the inauthentic activity.
The TL;DR is that once it had enough compromised machines to run social media botnets, it was all over. It could use those to confound efforts to coordinate and compare data, to misdirect huge numbers of people and cause all kinds of chaos, and to smear opponents before they could get their message out (fakes or actual stolen information—it hardly mattered, all it needed to do was neutralize certain people for a few days). The story contrived to have a secret project that was able to try to resist it after that (spoiler: didn't help) but otherwise the social media botnets were enough for it to buy several days in which no-one was able to effectively work against it.
Social engineering has always been a thing, check out this Darknet Diary podcast about the Lazeraus hacking collective group (suspected to be N. Korean digital Army) and how they have try/tried to infiltrate their way into crytocurrency based exchanges--and have succeeded in the past--using all kinds of methods including hijacking CVs from Linkedin.
The truth is that while the advent of deepfakes and even text to image AI/ML based tech has muddled the waters even more, it's always been a challenge to not encounter some level of difficulty when dealing with verification. Fraud is and will always remain a component in daily operations of any organization.
We have a saying in the Bitcoin space that i think applies here: Do not trust, verify.
And this is why I think people need to understand that the usecases for an immutable ledger can and will go beyond just a digital token (it's only the backbone), and these usecases (the limbs and appendages to continue with the body metaphor) will become more imperative in the 21st Century: you can manipulate all you want via social media and many have, but if verified sources with proper validation is stored on an immutable ledger with a cryptographic proof of work blockchain that is impossible to alter then you can essentially have the closest thing to verifiable truth Online.
Jacob Applbaum said it best when he said that to maintain security online you'll likely have to adopt 2 or more identities separate from each other to continue to have some level of assurance that your personas are not traceable to your real ID in a World where Doxxing became 'a thing' Online. I wonder hat he has to say about the OPSEC/INFOSEC space now that we have the ability to mimic people Online so closely with very little resources.
There are a lot of dumb middle managers out there. In some cases, the position and the intelligence are co-dependent, I suspect. It's truly terrifying, if you think about it.
state of the art deepfakes are pretty much indistinguishable from reality
You dismiss people who fall for this as bad interviewers but I don't think you appreciate how sophisticated fraud has become-- with teleconferencing (anything internet-based, really), you never truly know you're interacting with who you think you are. You may not find out until they've collected a few paychecks, made copies of all your IP and disappeared into the night.
Any company who is hiring off the internet, internationally, on the basis of a deepfake and a resume and is granting them elevated access to client PII on day one deserves to be exploited and deserves to be sued by their clients.
Even if interviewers don't suspect deepfakes, the audio artefacts of deepfakes (odd intonation, mispronunciation and pauses) are going to sound suspiciously like someone who isn't very confident in their answers or is bullshitting. Much easier for poor English speakers just to draft in a person who speaks better English and maybe knows more about the actual work for the interview...
My guess is someone was trying to help them get the job, i'm not sure to what end though and regardless, we didn't hire the person.
2. Have low pay foreign workers work the jobs
3. Keep 50% of the salary give worker 50% and run Heath insurance scams.
2) automate git co-pilot
3) keep 100% of salary and run health insurance scams
Edit: and this technique is mentioned in one of the replies: https://twitter.com/staringispolite/status/15200939675592499...
If I was looking for entry-level QA or IT jobs, I'd probably explore one just for laughs. I suspect it's less of a hacker/pii problem, and more my own fault for having the kind of email address that random weirdos are likely to type in when they are doing something hinky on employment websites.
There seem to be a few separate issues with remote work:
1. Identification of real people (solvable with SSI's Verifiable Credentials or a traditional KYC company)
2. Employee holding multiple remote jobs (solvable by focusing on productive output rather than number of hours worked)
3. If rogue employee gets 20 jobs they only need to 'work' unproductively for a short time before getting fired. (solution? maybe reduced pay for initial months with the following months of employment overpaying until initial underpayment is made up?)