Hacker News new | ask | show | jobs
by syngrog66 9 days ago
I once received a suspiciously too good to be true job offer, and at the last minute they surprised me by insisting I use a specific laptop they insisted on mailing me. One they would possess prior to me, and "configure" as superuser, before giving to me to use while working for them.

I declined, as diplomatically as I could. I should not have to spell out in precise detail how dangerous to me their proposal was. In the eyes of an adversary/APT predator: ignorant --> naive --> gullible --> prey --> profit. Rinse, repeat, scale up.

3 comments

Isn’t this how most tech companies, if not most companies in general, operate? Ive only had one BYOD job in 15 years. Even if you’re a contractor this is common.
You'll have to spell it out for me the problem, because that seems entirely what a corporation with an actual IT department would do.
Perhaps logging into GitHub (without creating a separate "johndoe-mynewcorp" account)?

I'd need to see a number of red flags before interpreting a corporate laptop as an attack vector though.

And if it is an attack vector, hey, free laptop right? (OK, giving an adversary your home address is an issue, but not giving your employer your home address would be seen by the employer as an issue, so more of an impasse).

hmm, i don't understand why you think this is suspicious. doing their stuff on their machine is ... fine i guess?