Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

71–80 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#71
post #62

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

[flagged]

I oppose corruption and treason regardless of party affiliation.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#72
post #19

Earlier quoted context omitted.

The first sentence is actually: > Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware Does not sound like clickbait for me.

The Ars Technica article is a bit confusing, if you click through to the original article, the case they make is much clearer. It's not that his credentials were found on Have I Been Pwned, which is the case for most people through no fault of their own. Instead, it's this: >But some of the datasets that Schutt is included in are much more concerning than normal data breaches because they're from stealer logs. Logs f…

"Well-known" email addresses (e.g: gaben@valvesoftware.com, president@whitehouse.gov) also seem to show up in these mentioned stealer logs on https://haveibeenpwned.com/ - which makes me suspect addresses are extracted from keypresses even if just typed in the To field of an email, for instance, and do not necessarily indicate the owner of the email has malware on their machine or has had their account/password compromised.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#73
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

>Good point. Is it a good point? How so? Without any proof or arguments, to me that Mastodon comment is just your average brain rot social media conspiracy slop, especially when you examine the profile of the user who wrote it. Is this what journalism has now become? Parroting othe people's unhinged takes off social media, then upvoting it on HN?

But it's coming from the right/good side so any conspiracy instead of panic and dehumanization is plausible and not worth discussing further.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#74
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Is the point good enough to elaborate further preferably with actual proof instead of just opinion?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#75
post #39

Honestly, stuff like this always makes me double check my own passwords and habits. Bunch of people just roll with the same easy setup for years and act surprised later. Gotta be careful, for real.

I've rolled with the same set up for years, what should I be doing instead?

If your setup includes a password manager, generated unique passwords and enabling 2FA everywhere you can, there's not much else to do.

Just use a unique complex root password for your password manager and check semi-regularly that it hasn't leaked on haveibeenpwnd.

Bonus points if your password manager automatically checks your stored passwords for leaks and scores them (eg. LastPass)

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#76

Earlier quoted context omitted.

[flagged]

Yeah, sure. Seeing a conspiracy and 4d chess in everything is a proof of having an enlightened mind. I work in this space and many actors, including nation state actors, are just incompetent. You may not believe me, that's OK.

This isn't an example of incompetence. DOGE staff broke laws when they connected their personal computers to classified system. They knew better, plenty of people told them not to do this and they still did it.

They could have followed OpSec rules and still done their work. They chose not to do so. Their willful disobedience of the laws and OpSec might stem from multiple rationals, but it doesn't matter, because their actions are criminal and their negligence is beyond incompetence.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#77
post #67
post #45

Earlier quoted context omitted.

Why don't people rise up against dictators in other parts of the world?

They always do - eventually

I think the point was to refute "they are doing nothing therefore they want this to happen"

Related: https://www.newsweek.com/lisa-murkowski-donald-trump-retalia...

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#78
All thee DOGE dudes are destined to spend life imprisoned on Alcatraz. The scope of the antics done by these people and the downright disregard for security, ethics, law, and the Constitution, all make them the right people to make examples of.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#79
post #61

Earlier quoted context omitted.

Hanlon's razor

The caveat is that intentional stupidity is indistinguishable from malice.

In law we shouldn't be focused on ignorance and cluelessness. The outcome of what they have allowed is the crime. All the DOGE dudes need life without parole.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#80
post #19

> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.

The first sentence is actually: > Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware Does not sound like clickbait for me.

At one point I was a contractor for a government department and at another I was at a government sponsored NGO.

My credentials are in the various leaks, like the Adobe one.

“Login credentials belonging to a Department of Defense contractor, who previously had worked at a government-sponsored media outlet, have appeared in multiple public credential leaks.”

Post reply on HN