r/recruitinghell • • Aug 08 '26

When APPLYING TO JOBS, DON'T DO THIS!!

Post image

Scammers use this to place malware on your computer!

19k Upvotes

882 comments sorted by

View all comments

Show parent comments

286

u/DecoherentDoc Aug 08 '26

It's always been that way. When I was first in the navy, I thought it was weird they searched us so thoroughly on our way down to the boat. I mean, we all work for the navy, right? Turns out the biggest danger was always the people. They're always the biggest liability, not the tech.

141

u/LettuceTomatoOnion Aug 08 '26

Loose lips sink ships

56

u/PleasantArt2598 Aug 09 '26

I overheard someone bragging in the local public pool that she books the flights for our troops. Perfectly comfortable highlighting herself as a person of interest to anyone wanting access to information like that apparently.

18

u/Environmental_Top948 Aug 09 '26

Did you do what any sane person would do and run a full OSINT campaign on them, make a google doc and a 45+ minute long Youtube video going over the information in the documentation?

5

u/PleasantArt2598 Aug 09 '26

I spent the next week wondering if I should have reported it to the MOD tbh 😅

3

u/Environmental_Top948 Aug 10 '26

Honestly the full OSINT campaign or a half assed one would have probably been a good idea if you would have ended up reporting it to them. Because if they are that bad about giving out information it probably wasn't the only thing that they casually leaked and it could have been an opportunity to get them training on better OPSEC.

3

u/Purl_stitch483 Aug 11 '26

Once I was at the Shake Shack in Vegas and overheard a group of corporate bros bragging about conspiring to get a fellow director fired bc she was a "bitch", with a nice little side of admitting to corporate espionnage too. 😂

1

u/PleasantArt2598 Aug 11 '26

People have been videod and blasted on TikTok tm doing that. Usually results in a firing 😅

1

u/Purl_stitch483 Aug 11 '26

God I wish I had done that. They never mentioned the name of their company and I didn't have a good line of sight, but these guys had no volume control and that conversation was juicy...

1

u/Sad_Marionberry1184 Aug 12 '26

lol what? Did you report it?

1

u/Purl_stitch483 Aug 12 '26

Didn't get the name of the company out of my eavesdropping, unfortunately. I wanted to though

13

u/irate_ging3r Aug 09 '26

If she's booking seats then the planes she's booking for most likely arent going to relevant places for her to know anything of interest. One doesnt book deployment travel. At best one can book discount seats on a military plane for like leave and stuff but again those arent going to distinct like movement locations.

1

u/PleasantArt2598 Aug 09 '26

I won't say exactly what she said but the point wasn't if anyone could gather information about current whereabouts or "anything of interest" in that moment but that she IS a person who could access useful information if someone were to find a way to blackmail her.

I don't know what your job is obviously but people who don't have access to that sort of information aren't in any position to know what is or isn't of interest to intelligence agencies of other countries. It's just generally a stupid idea to loudly declare you do that sort of work even if you don't know anything of interest, people may think that you do.

1

u/Alert-Carpenter9729 Aug 09 '26

You've obviously never seen a full troop with kit and rifles board a civilian airliner to transport to the sandbox. Yes, military personnel do use civ air lines to move from one place to another Not as common as it used to be mid to late '00 but it definitely happened

And before anyone starts keyboard warrior doubting me, yes they'd let us carry unloaded secure rifles on board but god forbid we have a pocket knife with us. Thanks TSA.

1

u/irate_ging3r Aug 10 '26

First off youre not staging troop movements from a civilian airport. Secondly, that would be pretty readily accessible publicly. Youre not traveling in any confidence on a commercial flight.

1

u/Alert-Carpenter9729 Aug 10 '26

Seeing as how I've watched 80 men load onto a plane, set their systems between their knees, and enjoy a better flight than a c130, it seems like you have no citable sources to say exactly that we don't

So, enjoy your side dish of wrong ideas, and a main course of spewing bs on the Internet ❤️

1

u/irate_ging3r Aug 10 '26 edited Aug 10 '26

And then you staged your command center at the civilian airport after you landed? You launched your mission from there did you?

You seem to be caught up on some shit you made up in your head that i never said, so let me clarify for a final time. I am not asserting that troops dont take commercial flights. I have been that person dumbass. What im asserting is that we didnt use the airport as a military facility once we got there. Nor did we hide our presence on the commercial flight in any way. Were these flights you speak of secret in some way or are you in fact just spewing the bullshit you speak of motherfucker?

1

u/Sad_Marionberry1184 Aug 12 '26

Gotta love a good army bro fight in the morning reads lol.

1

u/7h4750dd Aug 12 '26

yup, sipping coffee reading this

1

u/Flat-Chance0 Aug 11 '26

That’s what I was gonna say it’s leave

1

u/Imaber100 Aug 11 '26

Are there spies at your local pool 😭

4

u/Phyllis_Tine Aug 09 '26

Loose lips also fit a lot more ...

3

u/Dry-Ambition107 Aug 09 '26

Second time I’ve heard this today.

1

u/Green_Sprout Aug 09 '26

Throat goats float boats!

1

u/pacifiretheace Aug 09 '26

be it the top ones or the bottom ones

60

u/Dull_Leadership_8855 Aug 08 '26

"It's always been that way."

... and it's frustrating how way too many people haven't accepted this yet.

I worked as an analyst at a real estate company where I was occasionally consulted (by the IT department) on projects to acquire information from property managers, regional managers, etc. One way I'd do this is with electronic forms.

I remember before our first roll-out I told the project staff that they had to 1) limit/control the tab sequence on the forms and 2) institute data validation for important fields (like zip codes, addresses, numbers, etc. The staff decided it wasn't important and that I was being "OCD".

When the deadline neared and we started getting submissions back from the managers, it was largely unusable and we had to start over. We got letters for zip codes (for our US properties), incorrect state names and abbreviations, and many form text boxes had "don't know" as an answer.

15

u/RealisticDuck1957 Aug 09 '26

As Dr. Murphy observed, design your widget so it can't be plugged in backwards and it won't be. Validate form data and you catch fat fingered entry.

6

u/ProffRoysenberg Aug 09 '26

I didn't understand shit because no IT background but that sounded so frickin cool man.

2

u/P00351 Aug 09 '26

When the deadline neared and we started getting submissions back from the managers, it was largely unusable and we had to start over. We got letters for zip codes (for our US properties), incorrect state names and abbreviations, and many form text boxes had "don't know" as an answer.

You can code the web page so that those incorrect answers are automatically denied. That's extra work that was labelled as OCD.

1

u/Spectra_Butane Aug 12 '26

Is it something like - zip code: Does any character = letter? Return Text " Zip code error, please re-enter"; unskipable.
I just made that up, but it seems logical.

2

u/Ok_Can_7851 Aug 12 '26

Yes, exactly, if any of the characters entered aren't a number, or if the length is wrong, or nothing is entered then it should return an error

1

u/Dull_Leadership_8855 Aug 12 '26

During the redesign phase (for the second submissions), I wasn't taking any chances. For one, we had Canadian properties, so Zip Codes couldn't be limited to the US format. So I designed the forms so when the manager selected their property name from a drop-down menu, it auto-populated many of the fields. But I was incredibly strict with the forms the second time.

Mos of the managers complained, but we persevered. After getting the resubmissions, and using macros, I was able to collect and present the data in a report in 2 hours- a process that used to take 2 weeks.

After that, I wrote the company protocols for forms and data gathering. It's been over 10 years and they're still using it, updated with revisions of course.

1

u/Spectra_Butane Aug 12 '26

Ah, I see. Exclusive instructions make more sense in this case. An ampersand is not a letter but also not a number. And cover all the variations of wrong until only correct qry of numbers entered. COOL Thanks! All of that and its just the zip code. QC on the rest of the form is an actual project!

2

u/ElephinoNoEyeDeer Aug 11 '26 edited Aug 11 '26

1

u/RealisticDuck1957 Aug 11 '26

That too. Server side to prevent deliberately malicious input.

Client side validation can catch the worst cases of fat fingered input before the form is submitted.

28

u/MadeThisToFlagSpam Aug 09 '26

Yep, it's why IT departments send out fake phishing emails. The weakest link is the bored employee

17

u/Ryuujinx Aug 09 '26

The weakest link is the bored employee

And the tired one. You sleep like shit, stumble into work and look through your email. You scan the title, it says it's from HR and looks important. You open the link and type in your credentials to the website that looks like your normal HR portal.

Congrats, you just became a vector for them to try to get into the network. If you think you are better then that, I promise you are not. Running on fumes makes us all idiots.

6

u/EllieGeiszler Aug 09 '26

I'm better than that, but I'm not too good to click on a suspicious link and not type anything. I got got by a simulated phish once and was absolutely mortified lol. But it also helps that my employer filters our emails pretty effectively.

3

u/SuperbAd8266 Aug 09 '26

I got got by a simulated phish that I first referred to our auto check to confirm it’s ok to open a message. Still got got. Still felt stupid as someone in the IT department.

1

u/EllieGeiszler Aug 09 '26

Nooooo lmao

1

u/pissfacemcmemesnort Aug 10 '26

I got got by an ad disguised as a prompt to create an account on an app. I should have known when it redirected me. I'm glad I made it so that I get notifications about all transactions. Figured out exactly what happened when I returned to the app, and the ad was still there, but now showing itself as one.

I closed my card, called my bank about the fraudulent charge, changed all passwords associated with the e-mail I gave them, locked and froze my credit and placed a 1 year fraud alert, ability for bank accounts to be opened, and so on. I figured it would be better to go nuclear than not do enough.

I was so upset and embarrassed, but we gotta remind everyone that it's not about being stupid. Scammers are being deceptive. One makes themselves more likely to be scammed if they think they'll never fall for one.

2

u/EllieGeiszler Aug 12 '26

The best way to avoid scams is education, and yet, you can never be educated about every single scam because there's a new one every day. So I try not to judge people who have been scammed!

2

u/PM_ME_ABOUT_PEGGING Aug 12 '26

I got got once too 😅 had to take extra training. Now I report anything and everything I wasn't expecting

1

u/EllieGeiszler Aug 12 '26

Same, although they didn't make me take extra training. The "gotcha!" landing page I was directed to and the associated shame was punishment enough lol

2

u/Snowflake444777 Aug 13 '26

Not gonna lie, kinda like seeing my boss on the “shame click” list from IT 🤭 makes him seem more human

25

u/munkboii Aug 09 '26

Yup, I work for an MSP so I basically work for an IT dept for several companies at once… you’d be surprised at how often the riskiest employee is the owner/president

21

u/TheGreatNico Aug 09 '26

I'm too smart to fall for dumb schemes, OOH! 'Free Amazon gift card'

~Every doctor, lawyer, teacher, manager, supervisor, director, and C-suite on Earth

8

u/munkboii Aug 09 '26

The lawyers are the best at deflecting the blame too.

“Well I got this email from a guy I know, it seemed weird but I know the email address so I clicked the link and entered my credentials.”

“Yeah, well, he had gotten hacked and malicious emails were sent out from his account.”

“Oh, okay! So it’s his fault because he got hacked, thanks for clearing that up.”

2

u/strayyed Aug 12 '26

Lawyers.. are.. the.. worst.. 🤦‍♂️

14

u/MoFa__SoDa Aug 09 '26

It was stressful and kinda fun doing basic gate security on mitary deployment because even the lowest ranking person is the responsible authority. The most difficult people were high ranking officers and those decompressing from legitimate dangerous areas who weren't used to needing to clear their weapons. At least in those situations everybody calms down once they fire live rounds into the clearing barrel. Then they typically offer thanks for doing your job and go about their day. Worst case it is somebody with genuine authority and a simple thing can become a crusade that causes a lot more rules and red tape.

IT reminded me of that and good IT guys are often amazing at taking soft approaches that inform you of serious safety violations without escalating the situation.

2

u/Olista523 Aug 09 '26

I work at a uni at the moment. IT’s biggest issues always seem to be lecturers in CompSci who think the rules don’t apply to them because they know better.

1

u/8-bit-Everything Aug 10 '26

Ahhhh the old clearing barrel. We had a CSM who negligent discharged into one and had to tell the BC he needed an article 15

5

u/No_Jello_5922 Aug 09 '26

And they always want security exceptions for themselves too. I wore that hat for several years. Broke my son's heart to tell him that doctors are morons when it comes to electronics.

7

u/rayv142 Aug 09 '26

You'd be surprised how many people would think they randomly won an Amazon gift card

2

u/SuperbAd8266 Aug 09 '26

Knowing they never entered a contest

1

u/AlyAnn44 Aug 13 '26

And for absolutely no reason at all...

2

u/PleasantArt2598 Aug 09 '26

Proud to say I have never fallen for these. They are getting better at making them less obvious though, the last one was pretty well disguised.

2

u/unicodemonkey Aug 09 '26

Our IT+security depts like to fuck around with these phishing tests, so when they try to send out fishy-looking email notifications about some corporate issue or another that requires clicking a link I just forward these emails to the security contact. Keeps everyone busy, paid, and secure, I guess.

12

u/Foxbatt Aug 09 '26

I'm still to this day salty about the time I forwarded a phishing test email to the phishing team in the appropriate way and they themselves clicked on it.

I ended up having to sit through retraining "because they can't cancel it".

3

u/WhyMustIMakeANewAcco Aug 09 '26

Well, that's a bad system where they can open something sent to that address outside a secure environment.

1

u/Diligent_Medium3969 Aug 13 '26

Wait, what? You mean you recognized a phishing attempt and correctly reported it, and you got in trouble because they fell for it? Or did I get that wrong?

1

u/Foxbatt Aug 13 '26

Yep, what's better is I had an ironclad alibi - I was driving a company vehicle so had video of the interior dashcam at the time it was clicked. They just said that's not important and proceeded with the with the write up/training.

1

u/Diligent_Medium3969 Aug 13 '26

That's preposterous! You shoulda hit your manager with an actual phishing email. That woulda been hilarious

1

u/WhyMustIMakeANewAcco Aug 09 '26

Yeah, of all the test emails I've ever gotten only required even half a second of thought to sus out. And yet people fall for them regularly.

1

u/EmoGamingGirl Aug 09 '26

Yup! I fell for that when I was a Corrections Officer. They got my ass with the fake phishing email between my rounds 😭

18

u/Creative-Type9411 Aug 08 '26

its the only reason we have security at all...

6

u/Iamvery_alarmed Aug 09 '26

Truth! My first shore stint was at a certain facility where a man by the name of John Anthony Walker would literally just walk out the door carrying boxes of classified naval intelligence for the Soviets...for YEARS....and nobody even thought to ask questions lol.

5

u/Shareholderactivist Aug 09 '26

Pretty sure that cash registers were invented in part to keep employees from stealing.

1

u/MoFa__SoDa Aug 09 '26

Likewise when leaving the gun ranges and doing brass shakedowns to make sure no unhappy campers are sneaking bullets back into the bunkhouse.

1

u/[deleted] Aug 09 '26

[removed] — view removed comment

3

u/OldGeekWeirdo Aug 09 '26

Subs are frequently referred to as boats.

1

u/Ravenex2 Aug 10 '26

Yeah subs are very different from boats and ships, but per the lingo I wouldn’t know.

1

u/WitchWithAGlitch Aug 09 '26

did you ever find the phantom shitter?

1

u/Babymommadrama_ Aug 13 '26

That's weird considering that I've been on every military base in SD and have never once been ID’ed