Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

51–60 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#51
post #38

Seems like people here assume that passwords were found on Have I Been Pwned . It's more than that, it's about "stealer malware": > [...] user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. Stealer malware typically infects devices through trojanized apps, phishing, or software exploits.

It's not 'assume', it's literally in the text:

> Lee went on to say that credentials belonging to a Gmail account known to belong to Schutt have appeared in 51 data breaches and five pastes tracked by breach notification service Have I Been Pwned. Among the breaches that supplied the credentials is one from 2013 that pilfered password data for 3 million Adobe account holders, one in a 2016 breach that stole credentials for 164 million LinkedIn users, a 2020 breach affecting 167 million users of Gravatar, and a breach last year of the conservative news site The Post Millennial.

Putting this in undermines the quality of their critique.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#52
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

[flagged]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#53
post #48

Earlier quoted context omitted.

Alternative explanation - someone emailing you is infected by a stealer on their machine - they typed your email into the "to field" and that was captured by a key logger on their system.

Absolutely. Now, how do I sort things out? And eventually clear my name so people searching for my email don’t jump to conclusions regarding my OPSEC…

"By searching for his personal Gmail address (which I'm not sharing) in Have I Been Pwned, he appears in 51 data breaches and in 5 pastes. These include a 2013 breach of 153 million Adobe users, a 2016 breach of 164 million LinkedIn users, a 2020 breach of 167 million users from Gravatar, a 2024 breach of the conservative news site The Post Millennial, and many more."

Stop reading Ars and your name will be cleared. This isnt real journalism, it is Ars-washed political talking points.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#54
Under normal circumstances if that system were connected to an internal network there would be a cleanup (and the costs would be astronomical). I say normal circumstances because I fully expect these clowns to obfuscate, omit and deny everything for the next four years.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#55
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

>Good point.

Is it a good point? How so?

Without any proof or arguments, to me that Mastodon comment is just your average brain rot social media conspiracy slop, especially when you examine the profile of the user who wrote it.

Is this what journalism has now become? Parroting othe people's unhinged takes off social media, then upvoting it on HN?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#56
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

>Good point. Is it a good point? How so? Without any proof or arguments, to me that Mastodon comment is just your average brain rot social media conspiracy slop, especially when you examine the profile of the user who wrote it. Is this what journalism has now become? Parroting othe people's unhinged takes off social media, then upvoting it on HN?

Likely not the choice of the engineers, who appear not to know that they're being used as pawns in an international spy game that could send them to prison for a very long time.

I fully believe that the engineers themselves are wildly optimistic about society and their own abilities, but good security comes from realism and pessemism. Someone, probably many people, in the chain of command above them has moral and legal responsibility for choosing this course knowing it carried this risk and not caring.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#57

Earlier quoted context omitted.

I would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.

And also asked Russian intelligence services to hack his opponent in 2016, which they did the next day.

you could not make this shit up, right!?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#58

Earlier quoted context omitted.

>Good point. Is it a good point? How so? Without any proof or arguments, to me that Mastodon comment is just your average brain rot social media conspiracy slop, especially when you examine the profile of the user who wrote it. Is this what journalism has now become? Parroting othe people's unhinged takes off social media, then upvoting it on HN?

Likely not the choice of the engineers, who appear not to know that they're being used as pawns in an international spy game that could send them to prison for a very long time. I fully believe that the engineers themselves are wildly optimistic about society and their own abilities, but good security comes from realism and pessemism. Someone, probably many people, in the chain of command above them has moral and leg…

Knowing their choice of targets too (definitely not left up to the engs), by which I mean only DOGEing and compromising the security of what they consider left-leaning agencies: with that targeting and their care to cover their tracks digitally, why not choose a strategy that lets the Russians in quietly? Shortly after they compromised the security of the NRLB they were making blackmail threats by taking drone videos of people (who threatened to reveal their malfeasance) where they lived and worked. Clearly someone in the chain of command is thinking carefully about what they can learn from how Russia governs

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#59

Earlier quoted context omitted.

Yes, but all such authorities are subordinate to the President, and the President can issue security clearance by fiat, bypassing normal procedures and exempting people from them .

Well that's something that should be looked into.

[dead]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#60

Earlier quoted context omitted.

Hanlon's razor

[flagged]

Yeah, sure. Seeing a conspiracy and 4d chess in everything is a proof of having an enlightened mind.

I work in this space and many actors, including nation state actors, are just incompetent. You may not believe me, that's OK.

Post reply on HN