Live data from Hacker News

DOGE engineer's credentials found in past public leaks from info-stealer malware

arstechnica.com

161–170 of 180 posts

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#161

Earlier quoted context omitted.

Such Biden logic that ended with us launching missiles into russia. A constant escalation with no real end in sight and always matching "tit-for-tat- instead of trying to solve the root issue. You don't think trump is actively involved in negotations with russia to stop all this madness? Don't you think that one of the first signs of good faith in negotations would be to stop attacking eachother?

You misspelled Reagan. (Though to be fair, every president since Truman has escalated things with Russia/USSR, except maybe Clinton. Reagan just did more than most.) > You don't think trump is actively involved in negotations[sic] with russia to stop all this madness? No, I think Trump is doing whatever Putin wants him to do.

No other president has given explicit permission to launch american missles and use american guidance systems to launch missles into russian territory... Besides biden. What are you talking about?

And you forgot... besides Trump. because trumps not a warmonger, people like to act like he's on the side of the russians. People have lost their minds.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#162

Earlier quoted context omitted.

>a suspension of offensive cyber operations against Russia in March. uhhh... why are we commiting offensive cyber operations against a nuclear power? Somewhere in your line you seems to think that it's justified? And that biden was doing the right thing by provoking a major power? Some people just want the world to burn, and when someone puts out the fire, they think that's unamerican?

Because when someone punches you in the face, you punch back? Also I don't know why we keep referring to Russia as a major power, their GDP is about the size of Italy's, their economy is on the rocks, their military stockpile is depleted from a failed invasion of their much, much smaller neighbor.

failed operation? Have you seen the war map? After the whole world dumped all their stockpiles to ukraine for over $500B, the russians have still taken over a 3rd of the country. Biden logic was going to lead to a american troops on the ground, and a vietnam all over again.

Russia didn't punch us in the face, they punched some dude that we barley knew in highschool half way across the world.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#163
post #38

Seems like people here assume that passwords were found on Have I Been Pwned . It's more than that, it's about "stealer malware": > [...] user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. Stealer malware typically infects devices through trojanized apps, phishing, or software exploits.

It's not 'assume', it's literally in the text: > Lee went on to say that credentials belonging to a Gmail account known to belong to Schutt have appeared in 51 data breaches and five pastes tracked by breach notification service Have I Been Pwned. Among the breaches that supplied the credentials is one from 2013 that pilfered password data for 3 million Adobe account holders, one in a 2016 breach that stole credentia…

> Putting this in undermines the quality of their critique.

I don't disagree, but the reader may show critical thinking and consider that there is more: there is mention of malware, not just a leak.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#164

Earlier quoted context omitted.

Because when someone punches you in the face, you punch back? Also I don't know why we keep referring to Russia as a major power, their GDP is about the size of Italy's, their economy is on the rocks, their military stockpile is depleted from a failed invasion of their much, much smaller neighbor.

failed operation? Have you seen the war map? After the whole world dumped all their stockpiles to ukraine for over $500B, the russians have still taken over a 3rd of the country. Biden logic was going to lead to a american troops on the ground, and a vietnam all over again. Russia didn't punch us in the face, they punched some dude that we barley knew in highschool half way across the world.

Your numbers are way off. Ukraine has not received "over $500B". According to the Kiel institute tracker, as of February, the total military support for Ukraine from all all over the world combined stands at 132 billion EUR (~148bn USD). Nor does Russia control a third of the country. Russia controls 18.3%, of which 7.05% was occupied before 2022 and 11.25% since then. The total area held by Russia peaked in the first month of the war at 25.86%, was reduced to 18% with Ukrainian counteroffensives, and has stood there since the late 2022.

Scroll to "Overall control of Ukraine": https://www.warmapper.org/stats

While looking at the chart, keep in mind that Russia currently loses around 30-45k people a month as dead and wounded and they have nothing to show for it. The last major territorial gains were during the first month of the war in March 2022. It's a total military disaster with no end in sight.

And the person you replied to is absolutely right: Russia is not fighting for the potato fields of Ukraine, but to dismantle the entire international security system that the US built after the WWII to secure commerce and influence on the world. Ukraine is one of the stepping stones. Here's the full blueprint: https://en.wikipedia.org/wiki/Foundations_of_Geopolitics#Con...

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#165

Earlier quoted context omitted.

"charitably?" "uncharitably?" Nice ad hom you got there in lieu of an actual argument. lol

i'm willing to entertain ignorance, but not malice

Me too, man. Me too.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#166
post #66
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

How bad can it be? Be pardoned by a SCOTUS immune president?

Ask Rudy Giuliani or any architect foolish enough to take a project from him. While Trump might know more about protecting people who help him than he did then, it would be out of character for him to expend the time it takes to sign something if his benefit in the transaction is over.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#167
post #105
post #43

Earlier quoted context omitted.

Cannot tell if it's sarcasm or not. Obviously everyone who reads the headline assumes it's his current computer, and it had some, uh, consequences. That's why they click. That's what makes it clickbait. Nobody would care otherwise. (Also, if you are willing to be pointlessly formal, it goes in both directions, since it can be argued that a computer, which belongs to a person, who in the future will become DOGE's soft…

> Nobody would care otherwise. If his accounts were compromised after the computer was (as article indicates), people would still care. It included Greenfield too, so potentially has password reuse risk.

autocorrect; "included credentials too"

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#168

Earlier quoted context omitted.

If it looks like a duck, walks like a duck, swims like a duck and quacks like a duck, then at some point you gotta assume it's a duck. No need to run a DNA test.

Its more like "i see something waddling and quacking, is it a mallard or gallwad"

I dont mind, its open season and neither is on the protected list.

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#169
post #66
post #34

> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people ( ahem cough cough the Russians cough ) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.

How bad can it be? Be pardoned by a SCOTUS immune president?

That won't save you from a lawsuit

Re: DOGE engineer's credentials found in past public leaks from info-stealer malware

#170

Was he using his own computer? He should surely have been using one provided by the institution. In a properly secured system he should not have needed passwords to connect to databases, they should have been secured by something like Active Directory roles and certificates. Do any of these US institutions have any idea of proper security?

DOGE didn't care to go through proper channels for anything. They just used whatever they had. It was a true train wreck let by young talentless types like "big balz" or whatever his name was; their only qualifying talent was complete loyalty to Elon Musk.
Post reply on HN