Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

261–270 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#261
post #260

Earlier quoted context omitted.

Like two lines up from your quote: "He specifically was told that there were to be no logs or records made of the accounts created for DOGE employees" That sure sounds like no logs. If you don't believe the whistleblower, just say that, and skip the insulting me part (and I'll know to skip the replying to you part).

[flagged]

>You are being selective in your quotation:

Rich, coming from the person who left the sentence about logs out of their comment and then said "No where in the complaint does it allege anyone asked for an audit-less account".

>Go ahead, read it again please. You have the experience to understand what this means.

Do you get some sort of weird satisfaction out of being ridiculously condescending? Do you think it makes your argument stronger? Are you just an angry person?

>This very clearly means we aren't using the normal account-creation process which itself creates logs of account creation.

You think they requested no logs about account creation, but are cool with the logging after? What on earth would the purpose of that request be?

The request was not stated in a way that implies a point-in-time request to turn off logs solely for account creation. (And, again, that would be a completely nonsense request that accomplishes literally nothing).

Anyways, I have no interest in getting into it with someone that has to throw in little personal jabs in every comment. You can believe that the DOGE team only wanted the account creation to be exempt from logs but wanted the logs turned on immediately afterwards for god knows what reason.

Re: DOGE worker’s code supports NLRB whistleblower

#262

For those genuine actors here: this theoretical outrage assumes the premise of something immoral or illegal, and completely ignores the authority structure. This looks and smells like an info operation.

Just, as an exercise, list out 3 good reasons someone might want untraceable admin accounts then list 3 really bad reasons they might want that. If you manage to find 3 good reasons does the outcome of those those outweigh the risks of the potential bad reasons?

Good: 1. The account-level below that doesn't have access to certain stuff and just happened to have untraceable stuff 2. They just said "give me the highest level of access" and didn't investigate what that meant 3. Can't think of a good third atm

Bad: 1. They want to do nefarious things untraceably 2, 3. I think 1. covers pretty much everything.

Personally, if I'm put in charge of overhauling a system I don't want to waste my time waiting on approvals for BS, I just want to be given the highest level of access I can be given to get on with work.

I'm not saying this is fine, but the information here is basically a random list of things that happened and it doesn't really tell a nefarious story to my eyes.

Re: DOGE worker’s code supports NLRB whistleblower

#263
this part of the whistleblower complaint seem way worse:

" On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked by access policy due to those log-ins being out of the country. For example: In the days after DOGE accessed NLRB’s systems, we noticed a user with an IP address in Primorskiy Krai, Russia started trying to log in. Those attempts were blocked, but they were especially alarming. Whoever was attempting to log in was using one of the newly created accounts that were used in the other DOGE related activities and it appeared they had the correct username and password due to the authentication flow only stopping them due to our no-out-of-country logins policy activating. There were more than 20 such attempts, and what is particularly concerning is that many of these login attempts occurred within 15 minutes of the accounts being created by DOGE engineers. "

Re: DOGE worker’s code supports NLRB whistleblower

#264
post #176

Earlier quoted context omitted.

If they have full access to the systems, why are they scraping them externally?

This is the big question everyone here seems to be skipping over. It seems like they're using "database" in the colloquial sense and actually mean some sort of already public data that's just rate limited (for example https://www.nlrb.gov/advanced-search ). Then depending on the order of events, either scraping didn't work well enough and were given "unlimited" (not rate limited) access, or the accounts were actually…

Or maybe, even with access, they couldn't figure out how to query the actual database, so they resorted to scraping? Even with full "tenant" access, it could take some time to figure out where to look.

Re: DOGE worker’s code supports NLRB whistleblower

#265
post #260

Earlier quoted context omitted.

[flagged]

> You are being selective in your quotation: Rich, coming from the person who left the sentence about logs out of their comment and then said "No where in the complaint does it allege anyone asked for an audit-less account". > Go ahead, read it again please. You have the experience to understand what this means. Do you get some sort of weird satisfaction out of being ridiculously condescending? Do you think it makes…

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#266
post #215
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

Citation?

Re: DOGE worker’s code supports NLRB whistleblower

#267
post #265

Earlier quoted context omitted.

> You are being selective in your quotation: Rich, coming from the person who left the sentence about logs out of their comment and then said "No where in the complaint does it allege anyone asked for an audit-less account". > Go ahead, read it again please. You have the experience to understand what this means. Do you get some sort of weird satisfaction out of being ridiculously condescending? Do you think it makes…

[flagged]

First it was logs weren't mentioned. Then it was, well, logs were mentioned, but only to be turned off for the account creation process. Now it is, well, it was someone else who requested it and everything is speculation.

>Try to apply your experience here and calm down a bit.

Had to get one more little jab in there, didn't you? Can't have just one comment without one.

We're not going to convince each other. Hope that in the future, for other people's sake, that you can tone down your condescension and insults. It's a really unpleasant experience trying to discuss important things with someone who can't make a point without belittling the person they are talking to.

Re: DOGE worker’s code supports NLRB whistleblower

#268
post #215

Earlier quoted context omitted.

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

Citation?

From the whistle blower.

> Within minutes after DOGE accessed the NLRB's systems, someone with an IP address in Russia started trying to log in, according to Berulis' disclosure.

https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-...

Re: DOGE worker’s code supports NLRB whistleblower

#269

Earlier quoted context omitted.

[flagged]

Go help them then or donate to orgs that do.

I've started donating to TB-aid organizations.

But more than just money is gone. US-led organizations formed logistical backbones of these systems. Wads of cash won't replace the networks of people and things that are able to productively bring TB meds to people who need it.

Post reply on HN