Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

11–20 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#11

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

Who needs authority when you have ~vibes~

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#12

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

> I am not sure why we are falling for this click baity garbage, over and over.

Because it's easier to create and broadcast bait than to filter it.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#13

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

The DOGE staff have no security clearance to revoke, as far as I can tell.

How come they get to fumble and botch everything then?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#14

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

In principle? Perhaps. De-facto? Not as long as they're performing Trumpllatio.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#15
post #13

Earlier quoted context omitted.

The DOGE staff have no security clearance to revoke, as far as I can tell.

How come they get to fumble and botch everything then?

Reason: Congress has decided to not to ask that question of the Presidents Office.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#16

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

Yes, but all such authorities are subordinate to the President, and the President can issue security clearance by fiat, bypassing normal procedures and exempting people from them .

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#17
I don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system?

Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes the credibility of news journalism

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#18
post #13

Earlier quoted context omitted.

How come they get to fumble and botch everything then?

Reason: Congress has decided to not to ask that question of the Presidents Office.

Why so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#19

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

The first sentence is actually:

> Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware

Does not sound like clickbait for me.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#20

I don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes th…

> My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system?

If your password is in the dumps, too, like this person's passwords, then yeah, you might want to look into it.

Post reply on HN