Recruiter outreach is a threat model
· hiring, security, career, opinion
Last week I posted a list of complaints about recruiter outreach on LinkedIn. It travelled further than anything else I've put there this year, and the comments were the interesting part--dozens of engineers adding their own entry to the list, and a handful of recruiters saying some version of "yes, and here's why it happens."
Here's the list:
Listen up, recruiters! (you won't, but I'm posting it anyway) When soliciting someone for a job opening:
- Do not expect someone to open an arbitrary docx, pdf, or zip file (yeah, I've seen it)... just post the job description text
- If you're sending a link, it better be a reputable job board, not your rinky-dink firm's website that hasn't updated its SSL certificate in 2 years yet somehow still has eleven tracking scripts installed
- Post the salary
- Enumerate the interview steps
- No, I do not need a phone call to digest this information--is your time worth so little?
- No, I will not blindly run anything in your arbitrary GitHub repo
- Your "one-way video interview" proves nothing and saves neither you nor your client time
- Please stop arguing that Java is the same thing as JavaScript
- No, I don't have in-depth knowledge of the company after reading their name for the first time in human history
On the surface that's an etiquette complaint. A week of replies convinced me there's something more specific underneath, and most of it comes down to two questions: what am I being asked to execute, and who pays for the parts nobody wants to do.
The first half is a security list
Look at which items are actually about attachments and links:
- Don't send me an arbitrary docx, pdf, or zip
- Don't send me a link to a site with an expired certificate and eleven trackers
- I will not blindly run code from your GitHub repo
Put together, those are the three most reliable ways to get code executing on a developer's laptop, and the recruiting process has normalized all of them.
Developer-targeted fake-recruiter campaigns have been documented publicly for years, under names like Operation Dream Job and Contagious Interview. The pattern is stable because it works: a plausible recruiter reaches out about a plausible role, the conversation moves along normally, and at some point there's a take-home assignment in a private repo. You clone it. You install the dependencies. You run it.
That last step is the payload, and it's worth sitting with how good the delivery mechanism is.
A take-home coding assignment is the only context in professional life where a stranger sends you code and the expected behavior is that you execute it on your own machine without reading all of it first. You're not suspicious, because this is the normal process. You're time-pressured, because you have 48 hours and a day job. You're motivated to comply, because you want the job. And you're specifically discouraged from scrutinizing the setup, because the whole framing is "just get it running, then solve the problem."
Every property you'd want in a social engineering vector, the industry built into a standard hiring step and then trained a generation of engineers to treat as routine.
The best talk I saw at HOPE 17 this year was Winn Schwartau on what he calls metawar--cognitive security as the human-side twin of cybersecurity, and why our mental defenses deserve the same seriousness we give the silicon. This is a small, concrete instance of exactly that. My laptop's defenses are fine. The targeting runs straight through the part of me that wants to seem cooperative and employable, and that part has no endpoint protection at all.
So refusing to run code from a repo a stranger sent me is just correct, and I'll take the hit of seeming difficult over the alternative. That it reads as difficult in the first place is worth noticing.
The expired-certificate thing is the same instinct at a smaller scale. Your firm's website is probably fine. But a company that can't renew a cert while finding room for eleven tracking scripts has told me exactly what it optimizes for, and now I get to decide how much of my attention surface to hand it. That's a judgment I shouldn't have to make in order to read a job description that could have been three paragraphs of plain text in the message you already sent me.
The second half is an economics list
Four more items share a single root:
- Post the salary
- Enumerate the interview steps
- No, I don't need a phone call to digest this
- Your one-way video interview proves nothing
Every one of them is a question about who absorbs the cost of the information asymmetry.
Salary is the cleanest example. You know the band. I don't. If you post it, one of us spends zero additional time. If you withhold it, we both spend several rounds discovering whether the number makes any of this worth doing, and the entire cost of that discovery lands on the person with less information and no visibility into whether it'll pay off.
Interview steps are the same shape. You know it's six rounds including a take-home and a panel. That's real budget, and the expensive part is the specific hours I have to negotiate around a current job. Withholding it mostly buys you a candidate who discovers the cost in round four and walks, having burned your client's time along with mine.
The phone call drew the most agreement in the comments, and I think that's because it's the most legible conversion of my time into yours. There's a category of information--title, comp, stack, location, steps--that suits text perfectly. Text is skimmable, searchable, forwardable to my partner, and comparable against the four other messages in my inbox. Putting it on a scheduled call turns a two-minute read into twenty minutes on someone else's calendar, plus the scheduling round-trip, plus the context switch. The information content is identical. The cost moved.
One-way video is the purest case, because it doesn't even benefit the sender. I spend thirty minutes setting up, re-recording, and performing to a webcam with nobody on the other end. You spend four minutes scrubbing through it at 2x. Calling it an interview is generous. It's a screening artifact that costs the candidate an order of magnitude more than it costs you to consume, and it selects for comfort in front of a camera over skill at the actual work. If it saved anyone real time, it would be a defensible trade. It saves less time than reading a resume.
The third half is a competence signal
Two items don't fit either bucket. I keep them on the list because they're evidence.
- Please stop arguing that Java is the same thing as JavaScript
- No, I don't have in-depth knowledge of the company after reading their name for the first time in human history
If you're pitching me a role and you don't know the difference between two languages that share four letters, you can't evaluate my answers, you can't represent me accurately to your client, and you can't tell me anything useful about the job. Expecting company knowledge in the first message gives away something similar: the outreach is a script, and the script assumes I arrived already sold.
Both work as a cheap filter. The same lack of care that produces the Java mixup predicts the rest of the process. I have never once had a recruiter confuse Java with JavaScript and then run a tight, respectful, well-communicated hiring loop.
The honest counter-argument
Several recruiters replied in good faith, and the substance was: a lot of this isn't ours. Clients forbid posting comp. The ATS mandates the one-way video. The docx is the format the client sent. We're a volume business under quota, and personalizing every message doesn't scale.
That's all true, and it doesn't change anything.
None of it makes the cost disappear. It only settles where the cost lands, and the answer is still the candidate. "My client requires this" explains how the inefficiency got there. I'm still the one paying for it.
The strongest evidence that these constraints are softer than claimed is that good recruiters already do all of this. I've worked with a few. They send text. They lead with the band. They lay out the steps in the first message. They know what the stack actually is. They exist, they're under the same quota pressure, and they're dramatically more effective, because engineers answer them.
What good outreach looks like
Since I've spent a thousand words on complaints, here's the whole thing, in a message you can send without a single attachment:
Hi David--[Company] is hiring a [role]. Band is $X-$Y plus equity. Stack is [three or four actual technologies]. Remote/hybrid/onsite in [place]. Process is: 30-min call with me, 1-hour technical with the team lead, take-home you can skip if you'd rather pair live, final panel. Full JD below. Interested?
[job description as plain text]
No docx. No link to a domain I've never heard of. No call required to learn what the job pays. No repo to clone before anyone has confirmed we're a match.
That takes ninety seconds longer to write than the message I usually get. It'll get a reply from me every time, and we'll both know inside one round whether this is worth either of our afternoons.
What I was actually complaining about: default hiring outreach asks candidates to absorb both the security risk and the time cost of someone else's process, and then reads their reluctance as attitude.