Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

91–100 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#91
post #48

Earlier quoted context omitted.

Alternative explanation - someone emailing you is infected by a stealer on their machine - they typed your email into the "to field" and that was captured by a key logger on their system.

Absolutely. Now, how do I sort things out? And eventually clear my name so people searching for my email don’t jump to conclusions regarding my OPSEC…

You fly jets long enough, something like this happens.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#92

Earlier quoted context omitted.

I think the point was to refute "they are doing nothing therefore they want this to happen" Related: https://www.newsweek.com/lisa-murkowski-donald-trump-retalia...

I mean if so many of them are scared they can just caucus with the nearly (but not actually) 50% of congress members that are democrats [1]. It's really just republicans are only unified in presenting a unified front so when it comes to actually doing something like electing a speaker [2] [3] the lack of alignment becomes obvious. So they aren't doing anything to counteract trump because they aren't as a whole unifie…

Never interrupt your enemy when he is making a mistake.

The democrats don't have the numbers - even if they did, the more ridiculous the whole thing gets the better for them it is.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#93
post #61

Earlier quoted context omitted.

The caveat is that intentional stupidity is indistinguishable from malice.

In law we shouldn't be focused on ignorance and cluelessness. The outcome of what they have allowed is the crime. All the DOGE dudes need life without parole.

Do you actually believe that? Do you not think that at least SOME OF THEM, are working their asses off to save american tax payer dollars?

Can you point to any of the contracts in the wall of savings that have saved billions of dollars and disagree with any of them? https://doge.gov/savings

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#95

Earlier quoted context omitted.

Hanlon's razor

I would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.

>a suspension of offensive cyber operations against Russia in March.

uhhh... why are we commiting offensive cyber operations against a nuclear power? Somewhere in your line you seems to think that it's justified? And that biden was doing the right thing by provoking a major power?

Some people just want the world to burn, and when someone puts out the fire, they think that's unamerican?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#96

Earlier quoted context omitted.

I would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.

>a suspension of offensive cyber operations against Russia in March. uhhh... why are we commiting offensive cyber operations against a nuclear power? Somewhere in your line you seems to think that it's justified? And that biden was doing the right thing by provoking a major power? Some people just want the world to burn, and when someone puts out the fire, they think that's unamerican?

> why are we commiting offensive cyber operations against a nuclear power?

Maybe because they are doing it too ?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#97
post #86

Earlier quoted context omitted.

[flagged]

If the facts support those allegations, then absolutely yes.

> If the facts support those allegations, then absolutely yes

See, here's the thing: almost everyone believes this about themselves.

There is always enough difference between any given pairing of cases that one can retain their belief in their own fairness. And there is no shortage of partisan coverage that will assist you in believing that the cases are different.

And it's not like there is an incentive for holding _your own side_ accountable when the other side is not being held accountable.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#98
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Is the point good enough to elaborate further preferably with actual proof instead of just opinion?

"We don't do that here"

- T'Challa

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#100
post #37

Earlier quoted context omitted.

From the linked article: > user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware . So this isn't from website dumps with plaintext passwords.

If I did highly secure work (which I don’t), I’d set up a few honeypot machines and input my “secure credentials” (with a bogus password) into that repeatedly.

Yeah, inputing "secure credentials" traceable directly to you with what you'd hope is a bogus password is a very bad idea, especially if you're doing highly secure work.
Post reply on HN