Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

171–180 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#171

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

The original complaint mentions:

"7. March 3rd - I received a call during which an ACIO stated instructions were given that we were not to adhere to SOP with the doge account creation in regards to creating records. He specifically was told that there were to be no logs or records made of the accounts created for DOGE employees."

Which part of doing an audit, or some other DOGE employee's job, requires logs or records not to be made of their accounts?

Another quote:

"They were to be given what are referred to as “tenant owner” level accounts, with essentially unrestricted permission to read, copy, and alter data. Note, these permissions are above even my CIO’s access level to our systems. Well above what level of access is required to pull metrics, efficiency reports, and any other details that would be needed to assess utilization or usage of systems in our agency. We have built in roles that auditors can use and have used extensively in the past but would not give the ability to make changes or access subsystems without approval. The suggestion that they use these accounts instead was not open to discussion."

Audits don't require being able to alter data.

Also, some of the data is mentioned as being sensitive. Although granting access to the data of another agency may make sense, I have trouble believing that direct access to data such as sensitive personal information of third parties would routinely be given to people from outside of the organization. Even within the organization the group of people given access to sensitive data should be as limited as possible.

Re: DOGE worker’s code supports NLRB whistleblower

#172

Earlier quoted context omitted.

Time to remove the pardon powder. Has it achieved anything productive in the last 100 years?

It's a bizarre and archaic power, which has been abused by presidents from both parties.

It's also clearly incompatible with most (all?) modern definitions of democracy.

Re: DOGE worker’s code supports NLRB whistleblower

#173
post #129
post #75

Earlier quoted context omitted.

[flagged]

This is… the most reasonable explanation I’ve heard so far for everything that is happening. God knows there must be enough normally unused rules in the federal government.

The idea that they need to operate -- on hugely sensitive data and systems -- in darkness because any sort of accountability amounts to "sabotage" is dubious.

"Rules for thee, not for me"

This is some sort of "The Deep State is trying to foil them" nonsense.

And to be clear, aside from a weird brute forcing library and the fact that all of the DOGE employees seem to be spectacularly incompetent, there are rational technical reasons someone might want logging temporarily disabled for a one-off. For instance doing an activity that is justified and legitimate and secure and reasonable, but that would yield TB of logs unnecessarily, itself which might cause operational or availability issues. But having a bunch of incompetent script kiddies using their garbage scripts makes that fringe justification unlikely, and they're likely doing very criminal things.

Re: DOGE worker’s code supports NLRB whistleblower

#174
post #155

Earlier quoted context omitted.

Whistleblowers are claiming it's sedition: https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-... > The employees grew concerned that the NLRB's confidential data could be exposed, particularly after they started detecting suspicious log-in attempts from an IP address in Russia, according to the disclosure.

[flagged]

Without making any statement on whether I believe DOGE is being seditious, it's not hard to interpret their underlying intent as being wholly compatible with the definition you pasted. DOGE intends to hurt the government in ways that cause people to trust it less, with the goal of eliminating large parts of the government.

Re: DOGE worker’s code supports NLRB whistleblower

#175

Earlier quoted context omitted.

Thing is: Everything they're doing is against the rules. Except they aren't "rules", they are laws.

The problem is, those tasked with upholding and enforcing the laws aren't doing their job (Congress), are swamped with a deluge of blatant lawbreaking but still have to maintain professional decorum to not open themselves up to attacks (the justice system), or are outright corrupt (higher level federal courts including, sadly, the Supreme Court).

conflating administrative employees with congress/senate is a hint you know nothing about your own government.

also lost of the laws being broken are civil liberties protection and separation of powers, ... the only things holding the corruption under some control, which further proves you are either extremely uninformed or malicious. or worse, an "accelerationist"

Re: DOGE worker’s code supports NLRB whistleblower

#176

Earlier quoted context omitted.

What do you mean? It was "just" a tool to circumvent anti-scraping measures.

If they have full access to the systems, why are they scraping them externally?

This is the big question everyone here seems to be skipping over. It seems like they're using "database" in the colloquial sense and actually mean some sort of already public data that's just rate limited (for example https://www.nlrb.gov/advanced-search).

Then depending on the order of events, either scraping didn't work well enough and were given "unlimited" (not rate limited) access, or the accounts were actually denied so they fell back to scraping. Or perhaps these two things are just unrelated despite what the story is claiming.

Re: DOGE worker’s code supports NLRB whistleblower

#177
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

very clear admission of guilt.

Re: DOGE worker’s code supports NLRB whistleblower

#178
post #105

Earlier quoted context omitted.

> We live in a nation of laws You stopped living in a nation of laws a while ago. Now you live in a nation of might makes right.

We'll see. The thing about the law in the US, it's slow and heavy. You'll need to be pretty mighty to move it if it catches up to you.

I would have agreed years ago, but seeing trump - who obviously should be in prison for January 6th, among other crimes - back in the WH pretty much proves the US is not a nation of laws.

Re: DOGE worker’s code supports NLRB whistleblower

#179

Earlier quoted context omitted.

Time to remove the pardon powder. Has it achieved anything productive in the last 100 years?

I think it's been used properly in a lot of instances, especially when you consider that federal law can quickly become out-of-step with modern sensibilities, so being able to relieve those harmed by laws flawed under contemporary standards is important. There's probably a better way of handling that, but it's one instance where the power of presidential and governors' pardons have been applied appropriately.

At the very least, it seems obvious there should be an asterick on the pardon power of, "you can't use it to pardon your employees/staff." Or pardon people for things they did under your direction/purview.

Re: DOGE worker’s code supports NLRB whistleblower

#180

Earlier quoted context omitted.

Laws are only as strong as the enforcement. One of the things that is being exposed by the current administration is that, even though the Judiciary is an arm of the government, and supposed to provide a check on the Executive, the reality is that the Executive has the power to pardon anyone it sees fit, voiding the power of the judiciary (the argument is that the ultimate power lies with the voters who can pass thei…

> Laws are only as strong as the enforcement. This is one of the fundamental issues that underlies our broken system in the US. The gaps between what the law actually is, what people think it is, what people want it to be, and what it in practice is, are enormous. Some of the recent deportation cases highlight this. You have cases where people were living in the US illegally for decades but faced no repercussions, an…

> But it has to be done if we want to return to a system grounded in the actual rule of law and not the rule of law enforcement.

This is never going to happen - politics aside of what you might or might not believe about the current situation.

It's about as likely to happen as every religious individual on the planet obeying every rule in their sacred book.

The reason that they don't happen is because peoples' ideas on what is acceptable and isn't in a society changes, sometimes quite rapidly - note that the current US Administration was (attempting) to use a statute from the 1700s, are you obeying all the laws (that haven't yet been repealed) from then?

edit: An obvious example is the fact that the USA exists - it's on land that was acquired via theft, and murder. Therefore every person living on that land is receiving stolen property - let me know when that law is being enforced.

Post reply on HN