184
submitted 3 months ago by 0x815@feddit.org to c/technology@lemmy.world

cross-posted from: https://feddit.org/post/1094761

Archived version

KnowBe4 needed a software engineer for our internal IT AI team. "We posted the job, received resumes, conducted interviews, performed background checks, verified references, and hired the person," the firm writes on its blog.

"We sent them their Mac workstation, and the moment it was received, it immediately started to load malware."

[Special points to KnowBe4 for publishing this on its blog. If this can happen to a security awareness firm, it can happen to everyone.]

top 20 comments
sorted by: hot top controversial new old
[-] TrickDacy@lemmy.world 32 points 3 months ago

That company's training materials are hilariously terrible.

[-] Shirasho 17 points 3 months ago

They treat you like a child with no self respect. They are awful.

[-] PM_Your_Nudes_Please@lemmy.world 28 points 3 months ago* (last edited 3 months ago)

It’s because the training materials aren’t aimed at the typical Lemmy user who knows how to dual-boot Linux and built their own hackintosh for fun. It’s aimed at Jim in accounts receivable, who is 2 years away from retirement and hasn’t learned any new tech literacy skills in the entire 23 years he’s been with the company. It’s aimed at Pam in HR, who panics and says the internet is broken because she deleted her Chrome desktop shortcut for the fifth time this week. It’s aimed at Jill in accounts payable, who called IT to say her computer wasn’t working, (the power was out in the entire building, because a trash truck hit the power lines across the street.)

IT deals with a lot of BS, from users who don’t know anything about how computers or modern scams/hacks work. KnowBe4 is aimed that those users, because an organization’s security is only as impenetrable as its dumbest “oh hey I found a USB drive outside the front doors. I’m gonna plug it in to see what’s on it” users.

[-] TrickDacy@lemmy.world 8 points 3 months ago

Yep. The videos feel like they were designed by people who have never spoken to another human before. And yeah, seems like they are catering to old people who were new to email in 2003.

That's because they are. Those are the people who are most likely to fall for phishing.

[-] TrickDacy@lemmy.world 5 points 3 months ago

All I know is I have to waste an hour or so on this crap every year and it's annoying.

[-] jet@hackertalks.com 22 points 3 months ago

Hiring somebody without ever physically seeing them is a curious reality

I'm surprised , if the intention has stated, is to work well paid job and place a resource, why load malware at all?

If they're just trying to remote into the device, why are they remoting indirectly to the laptop? Why not use a remote KVM that hooks up to the output and USB ports?

[-] pixely@lemmy.world 7 points 3 months ago

Interesting point about the KVM. To make it transparent the KVM would need to report the model of a real monitor in the display EDID data. Also if you’re monitoring the device, which is almost certainly a laptop, it would be suspicious if it was plugged in to a monitor 100% of the time.

[-] jet@hackertalks.com 26 points 3 months ago

Having a laptop permanently in a dock is pretty normal for tech workers.

[-] femtech@midwest.social 6 points 3 months ago

Mine is either connected to a USBC dock at home or the office. I have only used it without when at a hotel.

[-] pixely@lemmy.world 1 points 3 months ago

Sure, I use a ThunderBolt dock at home, but being docked 100% of the time is probably not normal.

[-] 5too@lemmy.world 7 points 3 months ago

Mine has been docked for months at a time. I recently started shifting it to be near the kids when they're home; but not undocking it wouldn't strike me as strange at all.

[-] pixely@lemmy.world 3 points 3 months ago

That’s fair!

[-] Eheran@lemmy.world 12 points 3 months ago

How do you get out of North Korea unnoticed?

[-] AmbiguousProps@lemmy.today 26 points 3 months ago* (last edited 3 months ago)

Go through China. Although this seemed like a remote position.

[-] MonkderVierte@lemmy.ml 10 points 3 months ago

That guy or is it only a stock photo?

[-] pixely@lemmy.world 11 points 3 months ago

The article says it’s a stock photo that has been edited with AI.

[-] MonkderVierte@lemmy.ml 6 points 3 months ago

Didn't see that. Thanks!

[-] jumjummy@lemmy.world 6 points 3 months ago* (last edited 3 months ago)

Prompt “make this guy look like a North Korean hacker or something idk”

[-] HerrHelmus@lemmy.world 3 points 3 months ago

Someone wanted to see the new season of The Inside Man early

this post was submitted on 24 Jul 2024
184 points (97.4% liked)

Technology

59374 readers
3766 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS