Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

81–90 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#81
post #27

Earlier quoted context omitted.

> I am not sure why we are falling for this click baity garbage, over and over. Because it's easier to create and broadcast bait than to filter it.

Until HN improves, I propose that we flag moronic titles (misleading, clickbait, just annoyingly moronic, and so on). In the long term HN should do something about it, e.g. editoralized titles.

This is something that already happens. When there is a strong general opinion questioning the quality of the title, even if it's the same as the original title, if it's against HN directives they do get changed. Unfortunately I don't remember exactly these cases, but if you've been to HN long enough you've surely seen these changes.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#82
post #39

Honestly, stuff like this always makes me double check my own passwords and habits. Bunch of people just roll with the same easy setup for years and act surprised later. Gotta be careful, for real.

I've rolled with the same set up for years, what should I be doing instead?

password manager with 2FA / yubikey, randomized passwords per account, randomized account emails if your provider supports aliasing

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#83

Earlier quoted context omitted.

Absolutely. Now, how do I sort things out? And eventually clear my name so people searching for my email don’t jump to conclusions regarding my OPSEC…

"By searching for his personal Gmail address (which I'm not sharing) in Have I Been Pwned, he appears in 51 data breaches and in 5 pastes. These include a 2013 breach of 153 million Adobe users, a 2016 breach of 164 million LinkedIn users, a 2020 breach of 167 million users from Gravatar, a 2024 breach of the conservative news site The Post Millennial, and many more." Stop reading Ars and your name will be cleared. T…

I’d be in 3 of those breaches. One of the rules working in government was never use your personal email or ID for anything.

If you had to work in the nightmare of secure systems, the computers are literally in a different room, there is no Internet access in there, and you can’t take your smartphone in there.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#84
post #37

Earlier quoted context omitted.

Many website still store plaintext passwords. Indeed the ones getting hacked are more likely to.

From the linked article: > user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware . So this isn't from website dumps with plaintext passwords.

If I did highly secure work (which I don’t), I’d set up a few honeypot machines and input my “secure credentials” (with a bogus password) into that repeatedly.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#85
post #37

Earlier quoted context omitted.

Many website still store plaintext passwords. Indeed the ones getting hacked are more likely to.

From the linked article: > user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware . So this isn't from website dumps with plaintext passwords.

Them not naming the sites is pretty telling.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#87

All thee DOGE dudes are destined to spend life imprisoned on Alcatraz. The scope of the antics done by these people and the downright disregard for security, ethics, law, and the Constitution, all make them the right people to make examples of.

Alcatraz is a tourist attraction so while perhaps not somewhere I'd choose to live it also has routine ferries that you can just leave on.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#89
post #67

Earlier quoted context omitted.

They always do - eventually

I think the point was to refute "they are doing nothing therefore they want this to happen" Related: https://www.newsweek.com/lisa-murkowski-donald-trump-retalia...

I mean if so many of them are scared they can just caucus with the nearly (but not actually) 50% of congress members that are democrats [1].

It's really just republicans are only unified in presenting a unified front so when it comes to actually doing something like electing a speaker [2] [3] the lack of alignment becomes obvious. So they aren't doing anything to counteract trump because they aren't as a whole unified in that it's something they want but they're unified in not fracturing and helping democrats.

[1]: https://en.wikipedia.org/wiki/United_States_Congress

[2]: https://en.wikipedia.org/wiki/January_2023_Speaker_of_the_Un...

[3]: https://en.wikipedia.org/wiki/October_2023_Speaker_of_the_Un...

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#90
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

This is not an invincible decision making tool. It does not mean that literally every thing that can be explained by idiocy must be. We might start by leaning towards idiocy as an explanation but we are allowed to adjust our opinion as we see more and more information.
Post reply on HN