57 comments

[ 3.6 ms ] story [ 70.5 ms ] thread
You don't have to be an evil North Korean to do that. Outsources have been doing it since time immemorial because they can't achieve sales in any other way (or, through direct corruption - often offshore outsourcing shops are owned by managers of their clients, who effectively use them as tools for siphoning money away).
The supposed problem is being peddled by a company called Socure, who, coincidentally, offer the solution to this problem. There are absolutely "fake" remote workers floating around but to suppose this is some grand security-focused North Korean government conspiracy rather than people from poorer nations trying to get paid is without evidence. "North Korean" job applicants has become a meme, any suspicious looking applicant is being labelled "North Korean" by people who've read articles planted by Socure. If this were a grand North Korean government orchestrated conspiracy we would not see hundreds of job applicants engaging in exactly the same strategy for the same job.

https://www.socure.com/blog/hiring-the-enemy-employment-frau...

https://www.paulgraham.com/submarine.html

Many users here don’t seem to understand that they are reading content marketing.
company finally swipes right only to get catfished by a DPRK agent

nice

I am building a free service to counter exactly this problem.

This has been going on since 2018 at least and I have flagged thousands of such applicants.

FWIW, it the "insult Kim Jong-Un" meme that's been going around doesn't work
Did you try it? What did the person say?
How do you know?
Jeff Geerling recently discussed being contacted by the FBI to learn more about minature KVMs, one of the devices North Korean fake IT workers use to appear to be coming from other countries https://www.youtube.com/watch?v=Lc2hB2AwHso
In this case, the KVMs are plugged into multiple laptops being run in people's basement/spare bedroom, it seems. Someone will earn a set amount per laptop per month, to accept a company-supplied laptop (from a us company) then plug in one of these little KVMs to give a remote worker access without as much ease in detection.
So I must be really dumb here but what exactly does the kvm do? It's just stated that it has an Ethernet port and an HDMI and therefore can remote control a computer? And he said the North Koreans are putting them on people's computers as if North Koreans breaking into people's apartments is a common occurrence we've all experienced? And why did the FBI contact him about this?

There's obviously some context I'm missing here, I always thought kvm was the Linux kennel virtualization system...

Its not just North Koreans using them. Its also everyday US citizens who want to be digital nomads.

When i looked at https://www.reddit.com/r/digitalnomad/ a few years ago it didn't seem like any solution really worked reliably.

But if you had a farm of them and one guy maintaining them, rather than sticking it in your parents basement with nobody to maintain it, that might be something different.

The part that's really sad is that we have tons of out of work devs right now. This sort of thing only makes it harder for the legitimate people to get hired. An easy fix for this is for a place like Pearson to set up verified interview centers, which will allow for verified virtual interviews (on both sides of the table).
Not sure why that comment got downvoted. It doesn't seem to detract from the topic at hand.

Not sure if it's feasible, but it's definitely something to consider.

Interesting idea! This seems like a natural extension of the coworking space business concept.
Another solution might be UNIONS that would have __membership verification__ including things like citizenship (which country(ies) are they a citizen of?), skills tests and training, etc.

Just like competition requires 5+ similarly sized entities for a healthy marketplace of companies, my informal opinion is that unions probably similarly shouldn't have overwhelming market share. However my feeling on contracts between unions and corporations is that the contract should be negotiated between multiple companies and multiple unions to produce the most level playing field possible.

The interview process in US is already insanely ridiculous, but this would only add an additional level of crazy to it. Honestly, licensing would be less bad by comparison.
I don't really see north korean workers as any less deserving of work
Wouldn't the issue be that an interview center could take money to lie/etc? When I start a job I would have to go through I-9 verification - if that process is not good enough to weed out fakes, how would another verification work better?
Maybe.

You’d lose out on people who don’t live near an interview center and potentially have legal issues if people had disabilities that impacted their ability to travel to an interview center but not their ability to do the job.

I don't really understand the logistics of this to be honest. From the article it doesn't sound like these people have false IDs, they just make fake LinkedIn profiles?

In a lot of countries certainly here in Germany your employer has to pay social security contributions and needs your insurance, healthcare information etc. In addition if you're a foreigner you need to know their legal status to see if they can even work. Like what do these scammed companies do, just wire money to some guy they interviewed on social media and ship company property to random addresses? Is that even legal in most places?

They presumably wire the money to a person operating in the US who sends a portion of that money to the NK employee. The US person is then the one in the company payroll files. At least that's my understanding.
That’s part of what is being exposed here. The hiring process for many companies is not very robust. I doubt many even check references
My understanding is for a US employee, the employer is supposed to confirm eligibility to work in the first 3 days of employment. Some form of government id plus a social security card or a passport or something like that. IRS form I-9

Otoh, if these positions are independent contractors, form I-9 isn't required. Just a tax id for reporting purposes.

I would imagine whoever is hosting the laptops may be authorized to work in the US and could also be convinced to provide identity documentation. I think there's a lot of borrowing of documentation by immigrants/migrants who are not authorized to work in the US; so there's probably a marketplace somewhere too.

They're targeting locales and companies with less stringent checks.
Because it's contractors. You are not an employer in that person's country.
Maybe this, with mandatory senior executive and board accountability, will be the wakeup call to stop the outsourcing problem of the last 50 years.
I think the paranoia and fear this kind of idea promotes is perhaps the point of all of it.

Why this is being discussed publicly? It seems way more reasonable to inform IT companies directly, or investigate it outside media attention.

Also, we need steps towards reducing the possible tools that fake workers could leverage. These steps would put a strain on some recent technological developments. A strange and wild paradox.

It's been over 75 years. It could not be clearer that this attempt to punish the ordinary people who live in North Korea for having a government that the US finds disagreeable will not succeed in somehow fomenting revolution. What it has succeeded in doing, apparently, is sustaining a level of poverty and isolation that motivates even crazy schemes like this.

Here's how to actually stop it: stop weaponizing poverty to beat a Cold War-era dead horse, and end the damn sanctions.

Have your new hire turn up and meet with the team on day one.

They'll soon twig if that's not the person who's getting called into a quick meeting in 5 minutes to discuss some new issue.

I can’t find the tweet but apparently you can also filter these folks out by asking them to criticize Kim Jong Un
So, again, the answering to this and most every other hiring ill in software over the past 15-20 years is… licensing.

So, let’s think about this logically. There is no baseline of candidate identification or competence in software and the jobs pay very well in physically comfortable conditions. It makes sense that unqualified liars would apply for these positions. Why shouldn’t they? I am honestly curious how far the fraud and incompetence can go and devalue the industry before someone cares enough to tackle the problem l.

If only governments could provide a very simple “check identity” service online. I think this should be a basic service nowadays.
Something is amiss here...Developers make hundreds of applications to even get a reply much less an interview...While apparently, barely English literate North Korean IT workers are getting all the jobs :-) Time to praise the Supreme Leader on LinkedIn ?
> As US-based companies become more aware of the fake IT worker problem, the job seekers are increasingly targeting European employers, too.

All the US companies I've worked for made sure I was legit before I could log into anything, so I assume background checks to be ubiquitous there, save for the cheapest companies. European employers on the other hand...

Can’t they just make week 1 in person compulsory?

You can easily dress that up as an onboarding thing and would solve this, no?

I suspect it could be worse than that. It feels like certain countries' tech sectors are being partly taken over by IT workers from foreign intelligence agencies or from foreign entities with ulterior motives. Especially when you consider countries with small populations and few natives in the tech sector.

For example, in Australia, it seems like at least 8/10 software engineers are foreign-born. Most of those are probably genuine (not from intelligence agencies) but Australia has such a tiny native population of engineers compared to that of most foreign countries in its vicinity that it wouldn't be difficult for a country like China or India to overwhelm our tech industry with a few highly-placed workers in order to gain political leverage. I was thinking that there might be more software engineers working for Indian and Chinese intelligence agencies in the world than there are native-born software engineers in Australia (of all kinds). It's a numbers' game.

North Korea seems like the tip of the iceberg there though it is an easy example to talk about because everyone understands how the North Korean government operates and everyone agrees about the threat they pose compared to more subtle threats from other countries which aren't seen as opponents (at least not to the same extent).

But also, consider a company like Facebook which hires maybe 20K or so software devs. A country like India which has a large number of software developers, if it wanted, could easily put together a task force to infiltrate and take over Facebook in a focused decade-long effort if that was its intent. They almost certainly do have some people inside every major tech company right now.

If a group can have a few highly placed people inside a target company, they could then recruit more of their group into the company and start promoting their own until they have full control over the critical systems. It's a weakness of our current highly centralized tech sector.

Something else that could happen is a foreign intelligence agency could wait for people to get promoted naturally and then reach out to dual-nationals which they have leverage over (e.g. because of family members or assets owned in the foreign country) and then use that to demand favors. Then they could help coordinate the engineers to recruit more of their own to achieve even more control. Different groups would form factions within the target company and every normal employee would be unwittingly pushed out because anyone trying to 'improve or simplify things' would be seen as a threat to various nefarious agendas which rely on complexity to hide backdoors or algorithm exploits.

Imagine how valuable it would be if you could hijack's Google's search algorithm or Facebook's recommendation engines to prioritize your group's businesses and/or agendas.

This is a problem the USA caused, and could easily solve, by dissolving the armistice and declaring an end to the Korean war.

only seven countries are currently participating in the embargo and sanction of North Korea, (at the behest of the united states.)

They cite LinkedIn profiles with 25 connections as easy tell tale signs. Well, I've got news for you: hacked LinkedIn profiles. Happened to a colleague of mine. Profile with more than a thousand genuine, reputable connections got hacked. Picture and name got changed to something East Asian sounding/looking. CV got changed to US defense contracting. Luckily this tripped some automatic account lockdown otherwise it might have well gone undiscovered for a while. Few people will remember every single LinkedIn connection, there's no notification of name change in messages etc. Quite likely this profile was sold to North Korean fake IT workers.
Feel like at least one coworker might be better if they were this.
The LinkedIn thing is very weird, what about all the guys that worked for another company for a long time and didn't bother with LinkedIn? I don't buy that, but the trend of these guys not showing up in-person at all is very suspicious, though not impossible. There are all kinds of reasons people want to do remote work, and some of those reasons might preclude an in-person meeting (like you might find out about a disability).

Still, I agree that's pretty suspicious. However, they didn't offer any proof whatsoever these guys are from North Korea or any motivation for why they would be doing this from North Korea. So, that sounds like potential U.S. propaganda.

They said they worked with the FBI, which honestly is a red flag for that kind of thing. Rather, if a company states without proof they're from NK, it's very likely BS. If the feds say it's North Korea without proof, it's definitely BS (they have resources to prove it!). If the Feds say it and provide proof, then we can talk about the proof.

I hate how this is acceptable to make such claims about another country without providing any evidence. Same goes for Chinese or Russian hackers. It’s just whoever the US government is unhappy about.