Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

221–230 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#221

Earlier quoted context omitted.

I think it's been used properly in a lot of instances, especially when you consider that federal law can quickly become out-of-step with modern sensibilities, so being able to relieve those harmed by laws flawed under contemporary standards is important. There's probably a better way of handling that, but it's one instance where the power of presidential and governors' pardons have been applied appropriately.

> I think it's been used properly in a lot of instances, especially when you consider that federal law can quickly become out-of-step with modern sensibilities, so being able to relieve those harmed by laws flawed under contemporary standards is important. No, that is exactly what we don't need. When law becomes out of step with modern sensibilities, the law needs to be changed. Precisely the problem we currently hav…

That's not really what I meant. Just because a law is repealed or changed, doesn't mean the people who were sentenced to prison because of its original form will receive revised sentences.

Re: DOGE worker’s code supports NLRB whistleblower

#222
post #192
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Setting aside legitimate (thats a matter of judgement)... Some previous attempts for DOGE to get data has resulted in data being deleted before they can look and requests for judges to block access to data. DOGE may be trying to be covert in order to stop these two activities from happening before they can get and review the data.

> Setting aside legitimate (thats a matter of judgement)

By definition, a judge decides what's legitimate.

If DOGE expects their access to be blocked by a court judgement, and bum-rushes agencies to exfiltrate data ahead of the judgement, that's also criminal intent.

I am not sure what you are getting at. "Covert" isn't how I'd describe DOGE's actions. "Brazen" maybe?

Re: DOGE worker’s code supports NLRB whistleblower

#224
post #84

Earlier quoted context omitted.

root on Linux can just kill the log forwarder and erase the relevant logs, or refill them with junk.

At least at places I've worked, terminating the logger would cause a security incident, and the central logging service have some general heuristics that should trigger a review if a log is filled with junk. Of course with enough time and root, there's ways to avoid that. But that's also usually why those with root are limited to a small subset of users, and assuming root usually requires a reason and is time gated.

> But that's also usually why those with root are limited to a small subset of users, and assuming root usually requires a reason and is time gated.

I mean, if we were to apply the equivalent from the article, then no they would not have had a reason nor been time gated.

Re: DOGE worker’s code supports NLRB whistleblower

#226
post #84
post #70

Earlier quoted context omitted.

Root on Linux isn’t exempt from logging. I also don’t know any enterprise that allows admin accounts to bypass logging. There is no legitimate justification for this request.

root on Linux can just kill the log forwarder and erase the relevant logs, or refill them with junk.

That still leaves highly visible log traces if you’re following most security standards (required in .gov) since you’d have the logs showing them disabling the forwarder. The difference here is that this was like an attacker but had backing from senior management to violate all of those rules which would normally get someone fired, if not criminally charged.

Re: DOGE worker’s code supports NLRB whistleblower

#227
post #171

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

The original complaint mentions: "7. March 3rd - I received a call during which an ACIO stated instructions were given that we were not to adhere to SOP with the doge account creation in regards to creating records. He specifically was told that there were to be no logs or records made of the accounts created for DOGE employees." Which part of doing an audit, or some other DOGE employee's job, requires logs or record…

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#228
post #198

The CEO of Tesla and Space-X; a self-proclaimed high IQ individual, an alleged programmer, has apparently hired a straight-up script kiddie to their elite delta force of technical government downsizers.

I agree with the script kiddies comment- which is basically what the reporting has shown... but in a way isn't that part of the point? That they can save billions of dollars just by having a couple of relatively normal comp sci kids (who can't even rent a car) review the most basic financial information of our government departments. These guys aren't supposed to be "delta force" they are supposed to be the interns.…

> I would really like my tax money used more efficiently.

This is immature thinking, because, who wouldn't?

The contention comes from differing opinions on what is waste.

Re: DOGE worker’s code supports NLRB whistleblower

#230

Earlier quoted context omitted.

astonishingly stupid sounds about right for the people leading apparatus of the state :)

What could they possibly hope to accomplish with a threatening note and drone photos other than to provide fodder for his complaint? Why would drone photos even be necessary when you’ve already demonstrated that you know where they live? What possible purpose does such a threat serve?

not sure if this is a serious question…? what would it accomplish if you were the whistleblower? if it was me, my family would be on the first flight out of the country
Post reply on HN