Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

33% Positive

Analyzed from 734 words in the discussion.

Trending Topics

#company#run#own#interview#code#job#sure#email#linkedin#coding

Discussion (17 Comments)Read Original on HackerNews

dprkh42 minutes ago
There is a YC company that makes a coding interview tool. They want you to run their CLI on your machine and trust that it won't do anything malicious, when in fact it installs a bunch of things onto your machine without consent, scans processes, and intercepts requests from AI tools. It's crazy that people think this is acceptable.
stronglikedan30 minutes ago
Just that fact that the company expects a candidate to even have their own machine is egregious.
MajorTakeaway26 minutes ago
Even more reason to use VMs.
tamimio20 minutes ago
They (not what OP is talking about but usually these software) detect if a VM exists and abort, to prevent “cheating”.
bitwize12 minutes ago
How about no.

If you want me to run a particular piece of software, send me a fucking computer. If you want me to be on call on a company-managed cellphone, send me a phone that you can own and manage all you want.

Do not ask me to download, install, or run malware on MY computer or phone as part of the APPLICATION process. If you are the sort of company that thinks this is appropriate, then I do not want to work for you. I've actually turned down work because of this. "Oh, they just want you to install this Chrome extension to make sure you're not cheating during the video interview." No. Fuck you. Don't touch my fucking equipment.

delichon36 minutes ago
Maybe it's a pen test such that if the CLI can phone home you fail, to weed out candidates with weak security fu.
forinti3 minutes ago
> “A relevant opportunity” with part-time remote work and a great hourly compensation

That is so suspicious at the moment.

pronoiac20 minutes ago
If you run across something like this:

* perhaps archive your findings

* report the abuse to their hosting

I'm dropping emails to jsonbin.io and to ZapHosting (who run 147.189.174.138) about this.

sixtyj32 minutes ago
It reads like a true crime story.

Bad actor had prepared the set up so precisely that Claude Code could not detect it.

Malware Bytes? Acronis? There must be some template…

john_strinlaiabout 1 hour ago
out of the list under "Before you start with the test, you might be suspicious about the following:" there is only one that is important:

only interact with people using an official email address.

the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).

aliasxneoabout 2 hours ago
I get enough legit and illegitimate ones every week on LinkedIn that it's become really easy to tell the difference. Hard to pinpoint in a comment because it's mostly a gut feeling. But, in rough order:

1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.

2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.

3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.

4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).

Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.

stevekempabout 1 hour ago
Honestly unless I'm planning on quitting my current job, or if I were unemployed, I just ignore the linkedin.

Sure they spam you with "XX wants to connect", or "I'm awaiting your reply" emails. But real contacts and friends can call/email you, and everybody else can wait six months.

Despite only connecting with actual people I've worked with, not recruiters, I still get "suggested" posts which are slop, and "that happened". The site is a cesspool.

sandeepkdabout 2 hours ago
These seem like a common pattern lately. I feel for it but again people are creative in making business out of others desperation.
esafakabout 2 hours ago
I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

https://opensourcemalware.com/blog/latest-contagious-intervi...

NalNezumiabout 1 hour ago
.... Why would you do job interview when they expect you to run some code on your own system, on your own time?

Maybe I work in a different field but last year when I was still looking for jobs, only one company asked for coding assignment and every other company did coding interview which is always browser based editor.

I feel like the industry is mature enough that you can tell a company that sends you a zip file of code to f-off.

msdzabout 1 hour ago
> .... Why would you do job interview when they expect you to run some code on your own system, on your own time?

Because both the company and you know it’s the most effective job interview “filter” in SWE roles.

> on your own time

It may not be unpaid if you’re applying to a decent company.

The issue here is their poor implementation (zip file), not the concept itself, IMO.

zuzululuabout 1 hour ago
wonder if codex can catch issues ?

> A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.