I would call the on-site interview and/or minimal background check "the most pareto frontier thing you can do."
Verify their ID in person, issue their laptop etc in person, make sure someone who interviewed them is there to meet and greet them (and attest that it's the same person they talked to.)
If you can at least do a final interview in person also, then that's even better.
It takes that level of verification to become a security guard or a school bus driver. Anybody in computer security should be doing this.
[1] https://www.sterlingcheck.com/services/fingerprinting/
[2] https://www.aamva.org/technology/systems/verification-system...
I live in China, a supposedly autocratic country and one with universal ID, and even companies here don't take fingerprints. ID will be shown when you are officially onboard. I can't say for all, but for most companies (at least the ones without the need for a security clearance), requiring ID at interview will be seen as a red flag, and requiring fingerprint would probably be put on social media and name shamed, if not straight up reported to the authorities.
Not that I’d do it. The paradox that security for a firm means zero privacy for me is too much to bear these days.
Again, I can't say for all, and I'm sure there are certain companies and positions which require such measures, but I could not imagine requiring fingerprints (or even ID during interview) to be acceptable in most cases.
It’s pretty common in finance, government and human services. Amazon is very aggressive with this - contractors in their facilities get regular background checks.
Usually the employee goes to a third party run by a company like Idemia to collect the biometric. I can’t imagine not collecting the ID information of perspective employees - that’s just asking for fraud.
I don't know what the equivalent in the US is, but https://www.fbi.gov/how-we-can-help-you/more-fbi-services-an... seems similar enough.
I'd trust an FBI report more than taking their fingerprints and the like.
(The current SF-86 only wants your residence addresses for the last 10 years. Used to be "List all residences from birth".)
You're in a much more authoritarian country, and that would be using your non-universal, national ID. How do you authenticate someone coming in from overseas?
Answer: your authoritarian government doesn't let them in, or authenticates them for you in a joint process with your HR department.
Btw, I am nitpicking here, but by universal I meant used across the whole country, i.e. national.
I rolled out these level of controls at a big company and got push back from the sales team -- they needed access to generate leads. do demos on the spot, etc. Was a hard fight and I lost.
I run outsourcing agency, we work with US clients and have seen lots of fake applications (different degree of sophistication), so far we have either rejected them right away, or we were able to filter them during (remote) interviews.
This is more tricky with remote-only jobs or worse, "gigs" where you don't even meet people. But also, I would've expected open source to be "infiltrated" a lot more than it has, since that's very much anonymous internet culture... but also a culture of code reviews and the like.
Local knowledge, too. If they claim to be from Krakow, get someone from there to chat to them. If you hear frantic typing, they're imposters.
That's oddly specific. Any famous examples?
https://www.bellingcat.com/news/americas/2022/06/16/the-braz... The Brazilian Candidate: The Studious Cover Identity of an Alleged Russian Spy
Maybe also Pablo González Yagüe aka Pavel Alekseyevich Rubtsov.
> "The candidate did not speak Serbian, despite graduating from the University of Kragujevac, in Serbia."