Passwords and interviews
radar.oreilly.com
radar.oreilly.com
Unfortunately, that isn't true for some people. When unemployed and living paycheck to paycheck with few, if any, marketable skills in a depressed area with a spouse and kids, the employer/employee power balance shifts dramatically to the employer. If I were in that situation and I thought giving up my password was the only thing between me and the job, I would probably consider it.
"Take as your life's objective the goal of getting money for doing your own thing. You were born to do this. Never lose sight of this and settle for second best because this is one compromise that will guarantee unhappiness. Leave that kind of compromise to others - they were born for it. You are not." -- Mark Tarver
I can completely understand why someone would hand over their passwords to a prospective employer when asked. There is a huge power differential as you point out. However it is no less stupid.
Here's a basic rule I try to keep in mind, and I think it is extremely important in a hard job market as well, and that is to keep options open and work on ensuring you aren't on the bad end of such a bad exchange. The way you do this is by doing what odd jobs you can to put food on the table, so that even if you need the job you don't need it so badly to take a shit deal.
The fundamental nature of any transaction is that when one party is in a tough position (the formal term is having a poor "best alternative to a negotiated agreement") that person is going to get screwed over. When your BATNA is to have your kids go hungry, most decent parents will gladly give up their own dinners, let alone their Facebook password.
Quality of life surveys in Germany, where the government-provided social net is rather tightly knitted compared to American standards, shows unemployed to have about as much joy as cancer patients.
For those who watch TDS/Colbert, they poke fun from time to time at Fox News et al for making up scary things that kids supposedly do - the latest was soaking tampons with vodka and sticking them up your butt. This feels like the "soaking tampons with vodka" of the professional world. Someone probably has done it, but it is really uncommon and not worth losing sleep over.
The insidious thing about this is not if it happens for people looking for tech jobs (they're generally clued in enough to refuse, or go somewhere else, or make a fake Facebook account filled with stuff like "I love working so much!" and "I saved a man's life with a quick appendectomy at my volunteer gig"). People looking for lower-tier jobs are in less of a position to be able to refuse.
Whilst this may be a non-story at least it shows that people are thinking about these things and waking up to the things that suddenly become possible once your entire life is lived online.
If I were more cynical I might think that this story was intentionally stirred up by someone who had an interest in gauging the public reaction to this.
To graduate you had to apply online. However, they never actually integrated the graduate application process with their auth process. So when you applied to graduate you had to "sign" your application with your password. This app, password and all, would then be emailed out to everyone in the Records and Registration office. I presume they then manually logged into my account, and if that succeed I had verified my identity. If this password wasn't tied to, say, the ability to take out a student loan then maybe it wouldn't be a big deal.
I tried explaining to the person who answered the records office phone that this process was broken and I needed another way to identify myself (I'm an out of state student). They didn't care and didn't understand the issue. No one took me seriously until enough people tweeted about it that a PR person contacted me and had IT fix the problem.
So: Mr(s). Non-technical also tend to have very different ideas about passwords than, for example, HN readers.
I mean, I'm not a fan of people not understanding a tool(service) they use, but if your job pertains to asking for passwords, then you should definitely need to understand the repercussions of such a request, at least on a social engineering level.
It's not even programming, it's privacy. If companies are going to continue to hire non-technologist that use technology especially in a specialized way like this, then they're going to continue to make common-sense mistakes like this.
Besides privacy, it could turn out that HR involved in other domains are broken relationships. If anybody has any examples, I'd love to hear them.