Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

61–70 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#61
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

The caveat is that intentional stupidity is indistinguishable from malice.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#62

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

[flagged]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#63
post #19

Earlier quoted context omitted.

The first sentence is actually: > Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware Does not sound like clickbait for me.

The Ars Technica article is a bit confusing, if you click through to the original article, the case they make is much clearer. It's not that his credentials were found on Have I Been Pwned, which is the case for most people through no fault of their own. Instead, it's this: >But some of the datasets that Schutt is included in are much more concerning than normal data breaches because they're from stealer logs. Logs f…

>reasonably good evidence that you are doing something wrong.

No need for multiple leaks, just one is enough.

And I wouldn't say "do something wrong", just getting infected with an infostealer. Happens all the time.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#64
post #43
post #24

Earlier quoted context omitted.

Yep, headline doesn't say it is his current computer or anything, just that his computer was infected. It would be clickbait if it said his current computer is actively infected. Less clickbait than now if it said one of his computers appears to have been infected at some point.

Cannot tell if it's sarcasm or not. Obviously everyone who reads the headline assumes it's his current computer, and it had some, uh, consequences. That's why they click. That's what makes it clickbait. Nobody would care otherwise. (Also, if you are willing to be pointlessly formal, it goes in both directions, since it can be argued that a computer, which belongs to a person, who in the future will become DOGE's soft…

>Nobody would care otherwise.

As long as it's a work computer, what does it matter if it's his current computer or not? Remember that we're talking about an infostealer, it got his credentials and "that's it" (that's gravely serious).

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#65
post #22

I don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes th…

This is different from haveibeenpawned leaks. These infostealer dumps mean the data is direct from a spyware/malware on a victims computer. for ex: https://hackerone.com/reports/3091909 It means the people in the leak had malware on their computer in the past, and maybe present.

[deleted]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#66
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

How bad can it be? Be pardoned by a SCOTUS immune president?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#67
post #45
post #18

Earlier quoted context omitted.

Why so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.

Why don't people rise up against dictators in other parts of the world?

They always do - eventually

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#68
post #39

Honestly, stuff like this always makes me double check my own passwords and habits. Bunch of people just roll with the same easy setup for years and act surprised later. Gotta be careful, for real.

I've rolled with the same set up for years, what should I be doing instead?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#69
post #43

Earlier quoted context omitted.

Cannot tell if it's sarcasm or not. Obviously everyone who reads the headline assumes it's his current computer, and it had some, uh, consequences. That's why they click. That's what makes it clickbait. Nobody would care otherwise. (Also, if you are willing to be pointlessly formal, it goes in both directions, since it can be argued that a computer, which belongs to a person, who in the future will become DOGE's soft…

>Nobody would care otherwise. As long as it's a work computer, what does it matter if it's his current computer or not? Remember that we're talking about an infostealer, it got his credentials and "that's it" (that's gravely serious).

Wouldn't the assumption be that some percentage of government workers have infostealers on their computers? The track record of these people is not good, pretty much since we've had the internet there have been a steady stream of minor-to-moderate scandals where information gets to places that it shouldn't be.

This might just be selection bias because there is a large crowd of angry people looking for things to fling at DOGE.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#70
post #25

Now imagine how many normie, computer-illiterate federal employees in fairly sensitive roles have had various credentials leaked over the past few years.

I worked in Federal government on classified systems. There were many safeguards in place, most importantly networks that were 100% disconnected from the Internet and locked down workstations. That made sure that even the most inept user could not cause a problem like this.

Everyone I worked with respected OpSec and would never do something as risky as bring in an outside laptop and connect it to the network. DOGE has been so reckless that I believe they wanted to have the system hacked, because seeing our government destroyed is their real objective.

Post reply on HN