Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

21–30 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#21
post #7

Earlier quoted context omitted.

Explain please.

If I told you someone went to your bank and demanded the right to setup accounts with permissions to do everything and to have all logging of that users activity disabled, and then a whistleblower pointed out that they downloaded everyone's bank statements, you'd probably be pretty up set. After all, why do they need unfettered access? Why do they need your bank statements? Why do they need to hide what they're doing…

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#23
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

The people who need to see/understand this live in a different reality where uncomfortable things like this are ETL'd into righteous anger towards people they don't like.

This is the deep state they've been worried about, this is the boot that will tread on them.

EDIT: parent comment was highest ranked comment for the article and is now at the bottom?

Re: DOGE worker’s code supports NLRB whistleblower

#24
post #17

> accounts created for DOGE at the NLRB downloaded three code repositories from GitHub Why is anything of significance on github in the first place? Edit: It's not. They just download python libraries to do "IP rotation" to circumvent rate limits. On the actual complaint: ( https://whistlebloweraid.org/wp-content/uploads/2025/04/2025... ) It seems that the data was stored in Azure which doesn't make it any better.

If you continue reading, that question is answered. The GitHub repositories don't belong to the NLRB (or to DOGE), they were generic tools that were used to exfiltrate data from the NLRB.

Re: DOGE worker’s code supports NLRB whistleblower

#26
post #17

> accounts created for DOGE at the NLRB downloaded three code repositories from GitHub Why is anything of significance on github in the first place? Edit: It's not. They just download python libraries to do "IP rotation" to circumvent rate limits. On the actual complaint: ( https://whistlebloweraid.org/wp-content/uploads/2025/04/2025... ) It seems that the data was stored in Azure which doesn't make it any better.

If you continue reading, that question is answered. The GitHub repositories don't belong to the NLRB (or to DOGE), they were generic tools that were used to exfiltrate data from the NLRB.

I noticed and wanted to delete the coment but you replying made it impossible.

They downloaded "IP rotation" python libraries to circumvent rate limits.

Re: DOGE worker’s code supports NLRB whistleblower

#27
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

There isn't one.

Anything musk's dogs claim to find cannot be taken at face value because of this. Because there is no audit, and no evidence that they can offer that they didn't doctor their findings.

The next time they claim that a 170-year old person is receiving SS checks, they have no way to prove that they didn't subtract a century from that person's birthdate in some table.

Re: DOGE worker’s code supports NLRB whistleblower

#29
I almost can't make heads or tails of out of this scatterbrained word salad.

Let's start with this:

> Berulis said the new DOGE accounts had unrestricted permission to read, copy, and alter information contained in NLRB databases.

> Berulis said he discovered one of the DOGE accounts had downloaded three external code libraries from GitHub

What exactly does that mean? NLRB database accounts are GitHub accounts? (Surely not.) Or the same IP address accessed both, suggesting it was the same person? Define "account".

No coherent point being made here. This story needs to clearly separate the rhetoric about GitHub repositories from the NLRB access, and connect them together coherently.

The flow seems to be:

1. Some DOGE people obtained unbridled access to NLRB, with the ability to erase audit trails.

2. There is some sort of evidence that the same people downloaded tools from GitHub for distributed web scraping, suggesting intent to scrape massive amounts of data from somewhere (inferred to be the NLRB database).

There is no evidence cited in the article for the actual downloading of gigabytes of data; the "whistleblower" is quoted only as saying that DOGE required certain privileged accounts to be created and that the users of the accounts supposedly downloaded some web scraping software from GitHub.

At least mention some circumstantial evidence, like a suspicious increase in access activity, coming from distributed IP addresses in the Amazon cloud, following the download of those tools.

This:

> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.”

seems neither here nor there; why include that. It may be that the tools DOGE are using are not adequately safeguarding the data, but it seems like an extraneous point, and undigestable without specifics.

Re: DOGE worker’s code supports NLRB whistleblower

#30
post #17

> accounts created for DOGE at the NLRB downloaded three code repositories from GitHub Why is anything of significance on github in the first place? Edit: It's not. They just download python libraries to do "IP rotation" to circumvent rate limits. On the actual complaint: ( https://whistlebloweraid.org/wp-content/uploads/2025/04/2025... ) It seems that the data was stored in Azure which doesn't make it any better.

They are not. If I read the article right, they downloaded tools to use, mostly to do with anonymous web scraping.
Post reply on HN