Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

31–40 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#31

I don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes th…

>But some of the datasets that Schutt is included in are much more concerning than normal data breaches because they're from stealer logs.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#32

This article is reaching. I’ve logged onto secondary email accounts from PC’s that weren’t mine and could well have been infected. That’s what 2FA is for. I wouldn’t use a PC which isn’t mine to login to anything sensitive. A password in a leak isn’t evidence of anything.

Did you find stealer logs with your credentials though? Because that is certainly much more concerning than simply having your credentials leaked from some breach, and it's what happened to the DOGE guy.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#33

This article is reaching. I’ve logged onto secondary email accounts from PC’s that weren’t mine and could well have been infected. That’s what 2FA is for. I wouldn’t use a PC which isn’t mine to login to anything sensitive. A password in a leak isn’t evidence of anything.

> A password in a leak isn’t evidence of anything.

It’s evidence that your password leaked. What are you on about? You think they just randomly guessed his password?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#34
> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people (ahem cough cough the Russians cough) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon.

Good point.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#35

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

Doesn't seem speculative in the least - they have some pretty strong indicators of a problem. It's great that we're getting some tech-literate investigative journalism going - and good for our government to have a light shining here.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#36
post #25

Now imagine how many normie, computer-illiterate federal employees in fairly sensitive roles have had various credentials leaked over the past few years.

There are safe guards for information not to leak. Those safe guards make it very hard to get the info, not impossible, but very hard. Walking into a government office and plugging in your personal Macbook, and running whatever software you want with "god" powers on the network makes it a lot easier to gain access to whatever data is required. Even if its unintentional (big if) from the DOGE's side, at this level you are target by state actors and they will get to your personal devices if they want.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#37
post #20

Earlier quoted context omitted.

> My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? If your password is in the dumps, too, like this person's passwords, then yeah, you might want to look into it.

Many website still store plaintext passwords. Indeed the ones getting hacked are more likely to.

From the linked article:

> user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware.

So this isn't from website dumps with plaintext passwords.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#38
Seems like people here assume that passwords were found on Have I Been Pwned. It's more than that, it's about "stealer malware":

> [...] user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. Stealer malware typically infects devices through trojanized apps, phishing, or software exploits.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#40

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

Yes, but all such authorities are subordinate to the President, and the President can issue security clearance by fiat, bypassing normal procedures and exempting people from them .

Well that's something that should be looked into.
Post reply on HN