Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
59% Positive
Analyzed from 959 words in the discussion.
Trending Topics
#company#site#com#should#email#legit#https#using#fun#recruiter
Discussion Sentiment
Analyzed from 959 words in the discussion.
Trending Topics
Discussion (44 Comments)Read Original on HackerNews
Seems like this is becoming a recurring theme, similar story was on the front page last month.
https://news.ycombinator.com/item?id=48546294
If the victim is deep enough to check hook's content, it's unlikely they will just stop here losing suspicion. I'm sure most devs wouldn't think that doing `git commit` can be malicious (git security oversight?).
http://www.catb.org/jargon/html/H/hacker.html
> 1. A person who enjoys exploring the details of programmable systems and how to stretch their capabilities, as opposed to most users, who prefer to learn only the minimum necessary. RFC1392, the Internet Users' Glossary, usefully amplifies this as: A person who delights in having an intimate understanding of the internal workings of a system, computers and computer networks in particular.
> 2. One who programs enthusiastically (even obsessively) or who enjoys programming rather than just theorizing about programming.
Maybe they don't want to give any identifying info to the domain registrar? Or just minimizing their online presence?
Unrelated to this git pre commit hook attack but yeah
they added this back in 2023 (https://news.linkedin.com/2023/april/linkedin-s-new-verifica...), but very less people actually bother to verify with their email, so not having it doesn't always mean it's illegitimate.
I stopped being surprised by new stuff I learn about an OS I've been using for 25+ and 10+ as my daily whip and just enjoy the discovery-buzz
these take-home interview nightmare stories are so common ... I'd hate to see a bad actor take advantage by offering a "service" to unsuspecting and underinformed folks like ... erm ... me
“erd” [2] is a modern alternative written in Rust that some people prefer.
[1] https://en.wikipedia.org/wiki/Tree_%28command%29
[2] https://github.com/solidiquis/erdtree
Looks like these folks really did their homework.
It's nasty, but I have to respect their skills. I'll bet it works, quite often.
I suspect it's clever, experienced, engineers, leveraging LLMs.
I'm not talking about switching to cold contacting companies as a job hunting strategy. I'm saying if you get a suspicious outreach from a rando on linked in on behalf of a company THEN you only continue if you can reach out to the same person via official company channels.
Give defenders a better shot…
should i remove it?
there is no place for fun, whimsy, moods, or personalization on the web. sorry.
(no, at least not at the request of random internet stranger #10545346)
I joke, anyway, and bear the downvotes. Totally worth it.