Live data from Hacker News

Whistleblower: Doge came in, data went out, and Russians started to login

threadreaderapp.com

1–10 of 11 posts

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#2
Just read of this on BSky.

Has some of the protected disclosure document from the whistleblower.

https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e

Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presumably to try to cover their tracks.

This is bad. These guys are looking like bad actors, with State-level authorization for access to everything.

Also looks like they're kids and don't have the hang of security, and the professional Russian State run APTs have hacked them.

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#3

Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…

[flagged]

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#6

Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…

> Also looks like they're kids and don't have the hang of security

According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled.

The only thing which prevented that to happen was a luckily still enabled security policy restricting access to US IPs only (!) and flagging suspicious activity.

Believe me you'll need to have to know a shit ton about how Azure security works to pull something like that off without leaving evidence. I've got quite some experience in making sure this kind of shit doesn't happen.

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#7

Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…

> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…

It's straightforward to make something insecure :-)

Making it secure is the hard part.

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#8

Earlier quoted context omitted.

> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…

It's straightforward to make something insecure :-) Making it secure is the hard part.

Yeah, but it's actually not that straightforward to successfully turn the security of a heavily hardened Azure tenant to dogshit unless you know your way around and know exactly how Azure security works and what to strip out of it.

That's my point.

Same applies to properly hardened AWS and GCP tenants aswell.

Re: Whistleblower: Doge came in, data went out, and Russians started to login

#10

Just read of this on BSky. Has some of the protected disclosure document from the whistleblower. https://bsky.app/profile/mattjay.com/post/3ln2dgoksce2e Looks like Elon's staff went in and made a copy of everything - which in this case NLRB, so sensitive stuff, but any state department going to have a ton of sensitive stuff - and sent it who knows where; this after disabling all logging and a ton of security, presuma…

> Also looks like they're kids and don't have the hang of security According to the testimony they know enough to almost completely compromise a Azure tenant to the point that a foreign actor almost, ALMOST, could gain access with high privileges with a DOGE created username/password combination without being noticed because all monitoring was disabled. The only thing which prevented that to happen was a luckily stil…

So, what would happen if they used VPNs in USA?
Post reply on HN