Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

201–210 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#201

Earlier quoted context omitted.

https://www.bu.edu/sph/news/articles/2025/tracking-anticipat... https://www.impactcounter.com/dashboard?view=table&sort=inte... https://www.nature.com/articles/d41586-025-01191-z https://www.scientificamerican.com/article/usaid-funding-sav... This is just USAID. It's not even considering the cuts to HHS or other agencies.

[flagged]

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#202
post #162
post #113

Earlier quoted context omitted.

I think surely “we want untraceable admin accounts” should be illegal in some way. If only in regard to transparency.

[flagged]

>"Tenant-admin" isn't such a radical thing

Admin accounts without logs is extremely radical. I have literally never seen it, or had anyone request it, in my decade+ of consulting in security.

Unless you think the whistleblower, Krebs, and everyone else reporting are lying. Which, in that case, nothing anyone says is going to change your opinion (and you should just say that, if it's what you think, to save us all time).

Re: DOGE worker’s code supports NLRB whistleblower

#203

Earlier quoted context omitted.

Explain please.

If you take a step back and realize that the intent is to utterly destroy the social safety net provided by social security, Medicare, etc that we have all been paying into our entire adult lives, tell me why every citizen affected should not pursue civil and criminal charges of theft and fraud with malicious intent? And then the means to do so have involved ignoring the courts and bypassing constitutional checks and…

Not only did you not explain the original comment, you added more assertions that are significantly more extraordinary without explaining your reasoning for those either.

Re: DOGE worker’s code supports NLRB whistleblower

#205

Earlier quoted context omitted.

They're stopping congressionally mandated (i.e. legislation) payments to services, violating the Impoundment Control Act of 1974.

That doesn't sound like it would hold up in court. Which services?

I'm not sure if you've been reading the news at all, but I would guess no? The most talked about has been USAID -- namely because they started with it, which is odd because it's one of the smallest government programs and Musk promised to cut $2 trillion -- wait, sorry $1 trillion -- wait, no, $150 Billion by 2026 -- wait, the actual amount is likely much smaller [1].

1. https://www.nytimes.com/2025/04/13/us/politics/doge-contract...

Re: DOGE worker’s code supports NLRB whistleblower

#206
post #181
post #84

Earlier quoted context omitted.

root on Linux can just kill the log forwarder and erase the relevant logs, or refill them with junk.

That is a very serious design flaw, but I also believe it is a flaw that is addressed by SELinux. (Perhaps someone with a knowledge of SELinux can offer some input here.) That said, I'm not sure how widespread the use of SELinux is and doubt that it would help in this case since the people in question have or can gain physical access.

If your root, you can just turn off selinux

Re: DOGE worker’s code supports NLRB whistleblower

#207

Earlier quoted context omitted.

https://www.bu.edu/sph/news/articles/2025/tracking-anticipat... https://www.impactcounter.com/dashboard?view=table&sort=inte... https://www.nature.com/articles/d41586-025-01191-z https://www.scientificamerican.com/article/usaid-funding-sav... This is just USAID. It's not even considering the cuts to HHS or other agencies.

[flagged]

Saying something is false does not magically make it so.

Re: DOGE worker’s code supports NLRB whistleblower

#209

Earlier quoted context omitted.

astonishingly stupid sounds about right for the people leading apparatus of the state :)

What could they possibly hope to accomplish with a threatening note and drone photos other than to provide fodder for his complaint? Why would drone photos even be necessary when you’ve already demonstrated that you know where they live? What possible purpose does such a threat serve?

To intimidate. To scare into silence.

Re: DOGE worker’s code supports NLRB whistleblower

#210
post #40
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

Sometimes, depending on the situation.

My company retains all e-mails for at least 5 years, for audit purposes. But if some troublemaker were to e-mail child porn to an employee, we'd need to remove that from the audit records, because the laws against possessing child porn don't have an exception for corporate audit records.

So there's essentially always some account with the power to erase things from the audit records.

Post reply on HN