Whistleblower: Doge came in, data went out, and Russians started to login
threadreaderapp.com
Whistleblower: Doge came in, data went out, and Russians started to login
1–10 of 11 posts
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#2Has some of the protected disclosure document from the whistleblower.
https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e
Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presumably to try to cover their tracks.
This is bad. These guys are looking like bad actors, with State-level authorization for access to everything.
Also looks like they're kids and don't have the hang of security, and the professional Russian State run APTs have hacked them.
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#3Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#4But it doesn't dig as deep as this thread.
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#5Re: Whistleblower: Doge came in, data went out, and Russians started to login
#6Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…
According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled.
The only thing which prevented that to happen was a luckily still enabled security policy restricting access to US IPs only (!) and flagging suspicious activity.
Believe me you'll need to have to know a shit ton about how Azure security works to pull something like that off without leaving evidence. I've got quite some experience in making sure this kind of shit doesn't happen.
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#7Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…
> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…
Making it secure is the hard part.
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#8Earlier quoted context omitted.
> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…
It's straightforward to make something insecure :-) Making it secure is the hard part.
That's my point.
Same applies to properly hardened AWS and GCP tenants aswell.
Re: Whistleblower: Doge came in, data went out, and Russians started to login
#9Re: Whistleblower: Doge came in, data went out, and Russians started to login
#10Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…
> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…