4 ms·
Cybersecurity nerd here, have talked to many platform and financial company CISO’s, security teams and recruiters over the past few years. Fake interviewees ar
by apimade 2y ago
Cybersecurity nerd here, have talked to many platform and financial company CISO’s, security teams and recruiters over the past few years.
Fake interviewees are pretty rampant. We’re getting to the point where presenting yourself in-person to a government representative, agency or a private attestation company will be part of the onboarding process. At this point it looks like it’ll be iris scans.
In the US it’s even an issue in-person with H1B’s where they get interviewed and hired online, then someone else shows up.
Also the fact that insider threats are almost never budgeted for, and so many companies blanket-approve access to systems like logging systems, customer support systems, source code, etc - means attackers don’t even need to get hired into a very important role to get the data they want.
- mistrial9 2y ago> then someone else shows up someone else shows up ? what is the denominator
- kbrkbr 2y agoWe've seen that also. You interview someone online, help file the paperwork to get into the country and work visum, and then someone else, a technically much weaker guy, shows up on the first day. We had that twice in the last two years
- dalyons 2y agowild. So the paperwork and the visa etc was all actually filled out with the details of the weaker guy? Including the photo and suchlike? crazy that gets past the companies immigration lawyers Also, doesnt he just get fired straight away and lose his visa? Seems like very high effort and low chance of success, I must be missing something
- kbrkbr 2y agoThis is in EU. You have three months to find a new job, which I found here after your comment made me think [1]. This may be a reasonable gamble, as many companies do probably not expect such a rochade, and do not have detective measures in place. And if that doesn't work, you still have 3 months time to find another job in an environment that favored job seekers at this time. [1] https://expatrist.com/losing-a-job-in-germany-with-eu-blue-card/ https://expatrist.com/losing-a-job-in-germany-with-eu-blue-c...
- Terr_ 2y ago> At this point it looks like it’ll be iris scans. Oh god no, a piece of not-that-secret information which can't be revoked when eventually leaked. "This is a courtesy alert that your iris scan has been found on the darkweb..."
- tiahura 2y agoLike your name or address?
- meepmorp 2y agoYou can change your name and address, you cannot change your irises.
- dilyevsky 2y agoThat argument works for fingerprints because it’s possible to replicate them (kind of) but how do you replicate someone’s eyeballs assuming supervised setup ?
- deleted 2y ago[deleted]
- Terr_ 2y agoIf we assume "supervised setup", then doesn't that negate the fingerprint issue too because a supervisor can tug off fake-fingers and wash tips with alcohol etc? Either way, I think this is one of those "if it was used properly, people won't like the limitations, so they'll use it improperly" situations. Kind of like with social security numbers.
- Terr_ 2y agoNo, because nobody trusts full-names or addresses the same dumb way that they wish they could trust iris-data or fingerprint-data. "Welcome to Acme Bank. To prove you are the owner of this bank-account, please supply your full name and street address. *ding* Authentication successful! Please choose an amount to transfer." At best, biometrics can only replace usernames. In other words, information that is quasi-public and not expected to be easily changeable... With the additional problem that sometimes it changes all on its own.