Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

11–20 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#11
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

Explain please.

The complaint alleges that DOGE was able to get unlimited-permissions admin accounts that were not subject to logging. They also downloaded external repositories that gave users of those repos lots of different IPs. The complaint further alleges that the DOGE person used the combination of these things to "download... more than 10 gigabytes of data from the agency’s case files, a database that includes reams of sensitive records including information about employees who want to form unions and proprietary business documents."

If this is all true, this is basically hacking sensitive data in the open. We already know the current administration has worked to hobble unions. So putting these things together, this act is not only wrong in and of itself, but the data is likely going to be used to harm americans' interests. So, deserving of punishment.

Re: DOGE worker’s code supports NLRB whistleblower

#12
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Obviously no

Re: DOGE worker’s code supports NLRB whistleblower

#13
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

Explain please.

If you take a step back and realize that the intent is to utterly destroy the social safety net provided by social security, Medicare, etc that we have all been paying into our entire adult lives, tell me why every citizen affected should not pursue civil and criminal charges of theft and fraud with malicious intent?

And then the means to do so have involved ignoring the courts and bypassing constitutional checks and balances? Please tell me how this isn’t criminal if not treasonous?

Re: DOGE worker’s code supports NLRB whistleblower

#14
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

Explain please.

Sensitive government data was (sure, allegedly) extracted to Russia via an account that was expressly created to hide / not create logs. This is treason. Allegedly.

Re: DOGE worker’s code supports NLRB whistleblower

#17
> accounts created for DOGE at the NLRB downloaded three code repositories from GitHub

Why is anything of significance on github in the first place?

Edit: It's not. They just download python libraries to do "IP rotation" to circumvent rate limits.

On the actual complaint: (https://whistlebloweraid.org/wp-content/uploads/2025/04/2025...)

It seems that the data was stored in Azure which doesn't make it any better.

Re: DOGE worker’s code supports NLRB whistleblower

#18
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Sure, to hide your tracks because you know what you intend to do isn't right.

Re: DOGE worker’s code supports NLRB whistleblower

#19
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

There is no justification for ever creating an account like that. The only purpose is nefarious.

Re: DOGE worker’s code supports NLRB whistleblower

#20
post #17

> accounts created for DOGE at the NLRB downloaded three code repositories from GitHub Why is anything of significance on github in the first place? Edit: It's not. They just download python libraries to do "IP rotation" to circumvent rate limits. On the actual complaint: ( https://whistlebloweraid.org/wp-content/uploads/2025/04/2025... ) It seems that the data was stored in Azure which doesn't make it any better.

What do you mean? It was "just" a tool to circumvent anti-scraping measures.
Post reply on HN