Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

121–130 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#122

Earlier quoted context omitted.

It's 2.9B for a facility that can accommodate up to 3000 children simultaneously, as well as the support services to run it and provide the medical care and social workers needed to take care of them. It's not $3B for a specific 3000 children somewhere, so it's nonsense to try counting the cost per child that way.

regardless of the KPI perspective, do you agree that $3.3B is a bit much for a facility that can only host up the 3k? For reference, look up some of the Giga factory costs (With Capital expenditure for production). They are similiar in expenditures.

I haven't looked at the contract in detail, but no, $3B over 5 years for 3000 people including construction costs sounds reasonably in line with prison costs (the closest comparison). Certainly not the order of magnitude too high like you're suggesting, which surely someone would have undercut on the bid if it were easy.

You can look at the bid requirements yourself and determine whether you think it's reasonable for the scope of the facility: https://sam.gov/opp/3726d9e2246c47e197396e805ce6bb33/view

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#123
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Is the point good enough to elaborate further preferably with actual proof instead of just opinion?

[flagged]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#124
post #75

Earlier quoted context omitted.

If your setup includes a password manager, generated unique passwords and enabling 2FA everywhere you can, there's not much else to do. Just use a unique complex root password for your password manager and check semi-regularly that it hasn't leaked on haveibeenpwnd. Bonus points if your password manager automatically checks your stored passwords for leaks and scores them (eg. LastPass)

I happen to think that having your password manager online is a mistake.

For your consideration, one does not need to have their password manager online to use HIBP; they offer [at least] two different concessions to your concerns:

- SHA1 or NTLM hash prefix matching https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR...

- actually download the HIBP db and check for yourself https://haveibeenpwned.com/API/v3#PwnedPasswordsDownload

Thus you could hash your passwords in your airgapped setup, transfer the hashes using a mechanism you trust to an Internet connected device, and then check the hashes

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#125
post #101
post #85

Earlier quoted context omitted.

Them not naming the sites is pretty telling.

They're linking to the original source of the news, which literally names "the sites".

No it does not. What sites appeared in the "stealer logs" with his email?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#126

Earlier quoted context omitted.

password manager with 2FA / yubikey, randomized passwords per account, randomized account emails if your provider supports aliasing

What provider do you suggest? I've used Gmail all my life. Recently firefox started supporting forwarding, but that's only 5 emails.

I'm on Fastmail and it has been worth every penny. They happen to also integrate their email alias generation with 1Password, which I also use, making it an extra good investment

Despite their name being fastMAIL they also have a passable calendaring implementation. My only complaint about it is that they don't offer an Android "widget" in order to see the upcoming agenda at a glance, so one has to actually launch their app to view the calendar

If such things matter to you, they have CalDAV and WebDAV offerings, the latter of which I use for backing up my ViolentMonkey scripts. I haven't used their "Google Keep" replacement because Joplin serves my needs, but it does exist. And all of this for the same yearly price

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#127
post #45
post #18

Earlier quoted context omitted.

Why so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.

Why don't people rise up against dictators in other parts of the world?

[deleted]

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#128
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Is the point good enough to elaborate further preferably with actual proof instead of just opinion?

I mean, obviously very difficult to prove, but there _is_ a level of apparent stupidity where Hanlon's razor starts to get a bit blunt.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#129

Earlier quoted context omitted.

Yes, but all such authorities are subordinate to the President, and the President can issue security clearance by fiat, bypassing normal procedures and exempting people from them .

Well that's something that should be looked into.

That's how it is -- by design.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#130
post #45
post #18

Earlier quoted context omitted.

Why so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.

Why don't people rise up against dictators in other parts of the world?

To a large extent, insofar as Trump is a dictator, it is only because Congress have decided to allow that through inaction. At least for the time being (though, see, for instance, the Weimar Republic; this may end up being a use-it-or-lose-it ability), they still do have the power to largely put him back in his box if they want to.
Post reply on HN