Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

131–140 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#131

Earlier quoted context omitted.

regardless of the KPI perspective, do you agree that $3.3B is a bit much for a facility that can only host up the 3k? For reference, look up some of the Giga factory costs (With Capital expenditure for production). They are similiar in expenditures.

I haven't looked at the contract in detail, but no, $3B over 5 years for 3000 people including construction costs sounds reasonably in line with prison costs (the closest comparison). Certainly not the order of magnitude too high like you're suggesting, which surely someone would have undercut on the bid if it were easy. You can look at the bid requirements yourself and determine whether you think it's reasonable for…

This was awarded sole source. There were no vendors able to compete.

I also find their J&A unconvincing, and there's no way it passes the smell test required in Far part 6.

There was really no other vendor in the world, besides Family Care to be able to do this? They aren't even a construction company.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#132

Earlier quoted context omitted.

In law we shouldn't be focused on ignorance and cluelessness. The outcome of what they have allowed is the crime. All the DOGE dudes need life without parole.

Do you actually believe that? Do you not think that at least SOME OF THEM, are working their asses off to save american tax payer dollars? Can you point to any of the contracts in the wall of savings that have saved billions of dollars and disagree with any of them? https://doge.gov/savings

You can't trust their claimed savings either. https://www.nytimes.com/2025/04/13/us/politics/doge-contract...

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#133
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

Hanlon's razor is overused and abused. Quite often, it is actually a malice and if you are willing to look at the situation dispassionately, it is quite visible.

Hanlon's razor was originally a joke. Not a scientific observation how world works, but a funny sentence about there being a lot of incompetence in the world.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#134

Earlier quoted context omitted.

Hanlon's razor

This is not an invincible decision making tool. It does not mean that literally every thing that can be explained by idiocy must be. We might start by leaning towards idiocy as an explanation but we are allowed to adjust our opinion as we see more and more information.

Hanlon's razor was originally a joke. Not like, serious observation about how world works.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#135
post #100

Earlier quoted context omitted.

If I did highly secure work (which I don’t), I’d set up a few honeypot machines and input my “secure credentials” (with a bogus password) into that repeatedly.

Yeah, inputing "secure credentials" traceable directly to you with what you'd hope is a bogus password is a very bad idea, especially if you're doing highly secure work.

"Hope"? Generate random text, repeatedly type it in with AutoHotKey on honeypot machine, whatever rootkits are on there get garbled, useless data.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#136
post #101

Earlier quoted context omitted.

They're linking to the original source of the news, which literally names "the sites".

No it does not. What sites appeared in the "stealer logs" with his email?

Ah, I thought you meant what sites list the stolen credentials. The exact overlap of websites across four separate stealer logs is enough to leak an email address pretty reliably. The only thing that's "telling" for is that they're not willing to dox this person.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#137
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

Hanlon's razor

Hanlon's razor has been weaponized against good-faith applications

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#138
post #100

Earlier quoted context omitted.

Yeah, inputing "secure credentials" traceable directly to you with what you'd hope is a bogus password is a very bad idea, especially if you're doing highly secure work.

"Hope"? Generate random text, repeatedly type it in with AutoHotKey on honeypot machine, whatever rootkits are on there get garbled, useless data.

These aren't local credentials, these are credentials from various third-party websites that made their way into stealer logs. Garbled or not, using your personal email address for both legitimate purposes (e.g. Google Calendar, as the article points out) and honeypots isn't the best idea.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#139

Earlier quoted context omitted.

Did you look through that page before posting it? Currently, the default list of biggest savings is topped by things like eliminating a refugee intake facility, various HHS programs making sure public housing meets basic standards of habitability, and eradicating polio. Is the argument that government was so efficient before that eliminating these seemingly useful programs was the best and only way to save taxpayer d…

I guess we just disagree on what's important. $2.9B for 3,000 children. That's 967K per child. What in the actual fuck? https://www.fpds.gov/common/jsp/LaunchWebPage.jsp?command=ex... Edit: the contract was 3.3B, so that changes the calculus to 1,109,966.78 per child. Haven't seen the facility, but i highly doubt they are staying in million dollar condos, but if they are... there are better ways to do that. $1,136,43…

> there are better ways to do that.

That's the crux, for sure. The problem with DOGE though is that instead of creating better ways of doing anything, they just seem to eliminate doing those things at all.

Now we not only don't have a better way of doing a thing that might have been necessary, but we don't even have the sub-optimal way of doing that thing, so now it's not getting done at all.

Edit: Bringing it back to the article, if a person with access to 'a "core financial management system" belonging to the Federal Emergency Management Agency' was foolish enough to let their system get hacked, are we really finding a better way to do things, or are we being a little too careless?

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#140
post #86

Earlier quoted context omitted.

I oppose corruption and treason regardless of party affiliation.

[flagged]

charitably, you have fallen for the myth that americans can only engage in politics from one of two sports-fan positions. this is not true and the sooner we stop engaging with this myth, the better.

uncharitably, you are pushing a stupid narrative on purpose with ill intent.

Post reply on HN