only interact with people using an official email address.
the rest can be used as yellow/red flags, but simply asking for confirmation via an official email address will thwart the vast majority of scams (including other ones, like someone claiming to be from Intuit calling about your QuickBooks or whatever).
It is a decent rule, but one which is immediately thwarted by companies going out of their way to constantly look illegitimate.
And then google whether the domain is associated with phishing attempts. i've been targeted several times recently by folks with "official" email addresses but whose domains are (per google) strongly associated with phishing.
That is so suspicious at the moment.
1. Look at the person's LinkedIn profile contacting you and examine their post history. In one comical scenario the "recruiter" had a long 4 year gap where they were writing comments in English and all of the sudden they switched to Spanish. Mostly short, pointless comments as well.
2. Look at the company and make sure they have a legitimate website and are still actually in business. Even better, see if there's a public team page that lists this person.
3. Give the recruiter an email (I usually use something like SimpleLogin) and ask them to forward you the details. Of course, pay close attention to what address they send it from.
4. In addition, or alternatively, ask the recruiter for the public job listing (scammers almost always "paste" it into a DM or upload a clearly AI generated PDF doc).
Once you learn the game it's not too hard to start picking up on them. I've made it a game to play along sometimes just for fun. Ultimately, at the end of the day, make sure you report them on LinkedIn. I've had the account disappear within a hour of doing so.
Sure they spam you with "XX wants to connect", or "I'm awaiting your reply" emails. But real contacts and friends can call/email you, and everybody else can wait six months.
Despite only connecting with actual people I've worked with, not recruiters, I still get "suggested" posts which are slop, and "that happened". The site is a cesspool.
I deleted my account after I got my first job offer and have never used it since.
If people dislike the site so much, I don't understand why they don't delete their account. Is there any value provided, or is it the fear of missing out on potential future value?
In the company where I work (in recent history, the most valuable company on the planet), there are younger employees who do not own personal computers.
One of them was (with different company now) a Gen Z developer who did not personally own a computer (besides a phone).
I was floored. Still am.
It's just another form of authoritarianism, despotism, and oligarchy. Who decides what work is worth rewarding? What about the type of work?
It was always an antidemocratic idea sold to tech workers to stop the idea of questioning the system.
The idea that simply "talented" workers should rule just seems to speed run towards fascist aims. How do you consider which workers are worth more than others? If you do to the wrong school are you suddenly worth less? Do you think society will have certain preferences? What about in our neoliberal society where money is the only purpose to life?
https://en.wikipedia.org/wiki/Workplace_democracy
Corporations are the last authoritarian forces we willfully allow to dictate how we live our lives, I think anything to dismantle their power is worth pursuing. If democracy is good enough for states, it should surely be more than good enough for the economy.
As someone who is a big fan of consensus and voice, I don't see how current corporate leadership could get worse if more workers inside the company had more opportunities to direct its future. It's their future too, they need a say and telling people to just leave goes back to the neoliberal decaying value of money above all us.
It absolutely is a real thing. You don't get to declare that an existing word with more than 2000 years of history doesn't exist.
It may not exist in the Bay Area or in whatever subset of parameters you invented, but it absolutely exists and is something to strive towards.
> The idea that simply "talented" workers should rule just seems to speed run towards fascist aims.
Complete non-sequitur with 0 evidence.
> How do you consider which workers are worth more than others? If you do to the wrong school are you suddenly worth less? Do you think society will have certain preferences?
You decide just like everything else. Based on context and some objective measurements. It's not a perfect system, because sometimes measurements can become the goal, rather than the underlying objective, but it's the best system we have.
The first recorded uses of "meritocracy" are apparently by Marxist sociologists in the 1950s. They used it to describe a dystopian society, where merit serves as a moral justification for social classes, and social class determines the opportunities available to gain and demonstrate merit.
Of course the idea that career success and influence should be based on demonstrated ability and effort is ancient. But once you start building a society based on that idea, you run into Goodhart's law.
Do you have any evidence for that? Aside from the thought-terminating cliché "it was used by Marxists once" ?
Honestly I would see that as a huge red flag. In western countries a used laptop costs almost nothing.
Why do you think the job posting doesn't explicitly mention "owning a PC" as a requirement? If it's a relevant criterion why not make it clear there? If it's not, why have it at all, only to keep it hidden in your biases?
Accepting to run random code sent by someone you don't know should be a red flag for them. Getting asked to run random code sent by someone you don't know should be a red flag for you.
In extreme cases we can work it out but you should have something that makes up for the extra annoyance compared to 99% of applicants.
Probably not common, but certainly plausible. Not everyone wants to bring work home or have hobbies that are the same as their work.
I kinda assumed that most developers took a similar approach to me. Laptop because portable when you need it, hooked to large screens, nice keyboard, nice mouse/whatever. I don't know what having a desktop would really buy me. I do 99% of my work with the laptop docked but that remaining 1% it sure is handy to grab it and go.
If you are just making web apps, it does not matter, but I do data processing where having the headroom can make a big difference.
I do have the cheapest used laptop I could find for those moments when I might require portability.
In one instance for a data-oriented job interview I spun up a VM in the cloud because they linked a kaggle dataset for the at home test that was just a bit too big for my laptop to handle.
But to have nothing, no desktop, no laptop at all, is _odd_ for a developer. How did you get through school? If not school, then how is it a hobby-turned-profession without something to develop on?
The whole "no one should be denied access to a job" angle is weird too. What is the limit to accommodations?
Do you actually believe what you’re saying, or have you not thought it through?
It wouldn’t stop them from being hired.
You’ve got 10,000 candidates applying. Seriously, what would make “doesn’t have a laptop” stand out to you positively? Why not just go with the 9800 applicants who do have one? Surely there’s no reason to think “broken laptop = good dev”. It’s so much easier to simply go with a candidate who has no problems. Beyond that, what’s the deal with making candidates do stuff on their own machines anyways? You don’t know what’s on there. You don’t even know if it’s stable enough for a test, and none of that has any bearing at all on their skill.
I’ve never worked in the Bay Area, but if this is common practice, I think I dodged a bullet.
I've described some prior experiences with some interviews as failing my litmus test and have cancelled further interviews when people start demand much too much from me before I'm on a payroll.
If you want me to run a particular piece of software, send me a fucking computer. If you want me to be on call on a company-managed cellphone, send me a phone that you can own and manage all you want.
Do not ask me to download, install, or run malware on MY computer or phone as part of the APPLICATION process. If you are the sort of company that thinks this is appropriate, then I do not want to work for you. I've actually turned down work because of this. "Oh, they just want you to install this Chrome extension to make sure you're not cheating during the video interview." No. Fuck you. Don't touch my fucking equipment.
if one of my hiring practices would reliably generate that many f-bombs, i'd consider it a success and stick with it!
I guess, sure, companies are technically allowed to request you install malware on your computer. It's probably a CFAA violation, but nobody gives a rat's ass about the CFAA unless you're hacking the FBI, so who cares.
Also, make no mistake: a piece of software that is designed to record your screen, keypresses, etc is malware. It is spyware. You have absolutely zero guarantee it isn't install hooks into your system that will exist long after the application is gone.
Just do the interview in a browser sandbox like a normal person, and share your screen. Boom, problem solved, we figured this out 10 years ago. Really that paranoid about cheating? Then pay up and do an in-person interview, paper code test and all. I've had it done to me multiple times.
(Don't work in crypto, but there's a crypto company with the same name as the one I work at)
* perhaps archive your findings
* report the abuse to their hosting
I'm dropping emails to jsonbin.io and to ZapHosting (who run 147.189.174.138) about this.
Yes I most likely will tell them to get lost, but if I get an invite from Larry/Sergey I want to be ready.
That felt dishonest and I ignored the email.
Do not install anything on your machine, ever. Tell them politely ~to fuck off~ that you are not interested and move on. I know the desperation to be jobless will obfuscate your mind but again, never ever install anything on your machine when job hunting. I've seen people lose their crypto savings in seconds to say the least.
You've been warned.
Tangentially, what have people found that works well in term of hardening [0] desktop linux? For example, at least keeping "banking" separate from code-development?
I figure the only good way to keep separate user accounts and whenever I have to do something as root, I switch to the most-secure and least-used of the accounts.
What? There is no world outside github?
The rest of the article is legit, but they had to insert some monopoly worship...
Maybe I work in a different field but last year when I was still looking for jobs, only one company asked for coding assignment and every other company did coding interview which is always browser based editor.
I feel like the industry is mature enough that you can tell a company that sends you a zip file of code to f-off.
Because both the company and you know it’s the most effective job interview “filter” in SWE roles.
> on your own time
It may not be unpaid if you’re applying to a decent company.
The issue here is their poor implementation (zip file), not the concept itself, IMO.
Bad actor had prepared the set up so precisely that Claude Code could not detect it.
Malware Bytes? Acronis? There must be some template…
https://opensourcemalware.com/blog/latest-contagious-intervi...
> A note on the AI part: Claude Code was not able to detect any strange things when just prompted to scan the code base for unusual patterns.
> read process.env directly, which in this app means MONGO_URI, JWT_SECRET, SENDGRID_API_KEY, CLOUDINARY_API_SECRET, PAYTM_MERCHANT_KEY
yeah it can run arbitrary malicious code, but let’s also highlight that it can read the fake app’s own dummy environment variables
> When the victim connects out to […], the server sees the source address on the accepted socket, exactly as any web server sees a visitor’s IP. No discovery, no scanning, no registration of an address. This is precisely why outbound-only design is so convenient for the attacker: it works behind NAT, CGNAT, a corporate proxy, or a home router with zero configuration, and it doesn’t matter if the victim’s IP changes.
huge
> If there is no UI/Desktop environment the module for leaking browser data or screenshots is self-limiting.
yeah this is why a VM is important, it’s because it doesn’t have a UI so screenshots don’t work
> … and reinstall your OS - better safe than sorry.
yeah just for thoroughness’s sake after having a RAT installed (hopefully you didn’t do this step last)
Regardless if you get an offer or not, you will invest a significant amount of finite time in each interview cycle and if you do get an offer, you'll be investing even more time into that company.
So no matter who you are, protect your time and remember that interviewing is always a 2-way street.