Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

41–50 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#41

Does the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.

That kind of punishment is currently only considered appropriate for perpetrators of lese majeste.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#42

I don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes th…

If you read the full article you'll see its not just from database dumps.

Have I Been Pwned listed me in the ALIEN TXTBASE Stealer Logs. I went through the Notify me tab, got a verification link to check for my personal records, and all I got was this lousy:

"No domains were found for your email address. Whilst your email address was found in a stealer log, no websites were found alongside it. This can be due to the way the log was formatted."

TL;DR: You could try my email in there, believe credentials were stolen, when that might be recycled leak stuffing.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#43
post #24
post #19

Earlier quoted context omitted.

The first sentence is actually: > Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware Does not sound like clickbait for me.

Yep, headline doesn't say it is his current computer or anything, just that his computer was infected. It would be clickbait if it said his current computer is actively infected. Less clickbait than now if it said one of his computers appears to have been infected at some point.

Cannot tell if it's sarcasm or not. Obviously everyone who reads the headline assumes it's his current computer, and it had some, uh, consequences. That's why they click. That's what makes it clickbait. Nobody would care otherwise.

(Also, if you are willing to be pointlessly formal, it goes in both directions, since it can be argued that a computer, which belongs to a person, who in the future will become DOGE's software engineer, but hasn't become yet, also formally isn't a "DOGE software engineer’s computer".)

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#44
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#45
post #18

Earlier quoted context omitted.

Reason: Congress has decided to not to ask that question of the Presidents Office.

Why so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.

Why don't people rise up against dictators in other parts of the world?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#46
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

I would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#47

Earlier quoted context omitted.

Hanlon's razor

I would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.

And also asked Russian intelligence services to hack his opponent in 2016, which they did the next day.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#48

Earlier quoted context omitted.

If you read the full article you'll see its not just from database dumps.

Have I Been Pwned listed me in the ALIEN TXTBASE Stealer Logs . I went through the Notify me tab, got a verification link to check for my personal records, and all I got was this lousy: "No domains were found for your email address. Whilst your email address was found in a stealer log, no websites were found alongside it. This can be due to the way the log was formatted." TL;DR: You could try my email in there, belie…

Alternative explanation - someone emailing you is infected by a stealer on their machine - they typed your email into the "to field" and that was captured by a key logger on their system.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#49
post #13

Earlier quoted context omitted.

How come they get to fumble and botch everything then?

Reason: Congress has decided to not to ask that question of the Presidents Office.

Once upon a time Congress would botch something and all one could do without getting into weeds no one cared about was blame Congress. No one wanted to hear a list of 200 assorted representatives.

In these partisan times one can always be more precise: it is either the Democratic caucus or the Republican caucus. Almost no one goes against their caucus. In this case, and in every case until the midterm elections, it is the Republican caucus.

Assign blame or merit where it is due and maybe voters will have enough shame, pride, or sense of self-preservation to fix things.

Botching security is currently a Republican project.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#50
post #48

Earlier quoted context omitted.

Have I Been Pwned listed me in the ALIEN TXTBASE Stealer Logs . I went through the Notify me tab, got a verification link to check for my personal records, and all I got was this lousy: "No domains were found for your email address. Whilst your email address was found in a stealer log, no websites were found alongside it. This can be due to the way the log was formatted." TL;DR: You could try my email in there, belie…

Alternative explanation - someone emailing you is infected by a stealer on their machine - they typed your email into the "to field" and that was captured by a key logger on their system.

Absolutely. Now, how do I sort things out? And eventually clear my name so people searching for my email don’t jump to conclusions regarding my OPSEC…
Post reply on HN