Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

281–290 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#281
post #178

Earlier quoted context omitted.

We'll see. The thing about the law in the US, it's slow and heavy. You'll need to be pretty mighty to move it if it catches up to you.

I would have agreed years ago, but seeing trump - who obviously should be in prison for January 6th, among other crimes - back in the WH pretty much proves the US is not a nation of laws.

It's worse. SCOTUS says he's immune to any law while POTUS meaning he can have people commit crimes on his behalf and then pardon them (or simply commit them himself). See the 1/6 insurrectionists.

Re: DOGE worker’s code supports NLRB whistleblower

#282

So what exactly is being alleged here? That these DOGE bros wrote and used “hacker” code from GitHub to bypass security limitations on NLRB data? Why would they even need to do that if they had superuser accounts in the system already?

The lede is buried but the implication is downloading a huge amount of data on union organizers, which can then be given to a company to pre-emptively fire those individuals

Re: DOGE worker’s code supports NLRB whistleblower

#283

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

The article could offer a summary of this key finding, rather than, say, the pointless paragraph near the bottom about the scraping software found in GitHub not being well written.

This is the evidence which strongly suggests that the DOGE personnel are using various cloud IP addresses to scrape.

Re: DOGE worker’s code supports NLRB whistleblower

#284
post #75

Earlier quoted context omitted.

[flagged]

These aren't rules made by bureaucrats. They are laws written by Congress, a coequal branch of government, in response to the Nixon administration's abuse of executive power

And in some cases FDR's abuse of executive power. If we manage to get... Someone, I don't know who which is depressing, elected that is interested in preserving democracy above all the other current issues, I'm sure there will be a lot more laws to safeguard this happening again. Personal recommendations, nox the filibuster it creates incentive, use federal money to get all the states to switch to ranked choice voting for all federal positions. And MMP for house and electoral college. Maybe nix the filibuster as the last item of business so that the first Congress without it will have more than two parties (due to those electoral changes which lead to 4-8 parties usually).

Re: DOGE worker’s code supports NLRB whistleblower

#285

Earlier quoted context omitted.

The original author claims this is to prevent API gateway from leaking the true client IP.

To be fair the code actually creates a new API gateway server that acts as a proxy on to an already existing server and you're possibly meant to use this header with your own gateway service. So, it's set as a header, sent to a user owned proxy, then to the actual external endpoint. On the other hand I think the receiving API Gateway will be able to see and log your AWS account identifier when you do this. So your IP…

The code seems like a "creative" use of API gateway to turn it into a proxy for other external sites (single site, really, since you need one per site.) Wouldn't it be simpler to send the requests through a lambda (with a function URL) and get better control of the outbound requests?

Re: DOGE worker’s code supports NLRB whistleblower

#286

I almost can't make heads or tails of out of this scatterbrained word salad. Let's start with this: > Berulis said the new DOGE accounts had unrestricted permission to read, copy, and alter information contained in NLRB databases. > Berulis said he discovered one of the DOGE accounts had downloaded three external code libraries from GitHub What exactly does that mean? NLRB database accounts are GitHub accounts? (Sure…

The only interesting part of 2 is it looks like Doge wanted all the data. The technical details of how they scraped it mostly doesn't matter.

Plus in the whistleblower's actual report, there is evidence of them getting it, like logs of network output far above previous levels, and those accounts making accesses from various IP addresses (including geo-blocked attempts from Russia).

Re: DOGE worker’s code supports NLRB whistleblower

#287

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks.

The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Re: DOGE worker’s code supports NLRB whistleblower

#288

Earlier quoted context omitted.

Explain please.

The complaint alleges that DOGE was able to get unlimited-permissions admin accounts that were not subject to logging. They also downloaded external repositories that gave users of those repos lots of different IPs. The complaint further alleges that the DOGE person used the combination of these things to "download... more than 10 gigabytes of data from the agency’s case files, a database that includes reams of sensi…

[deleted]

Re: DOGE worker’s code supports NLRB whistleblower

#289
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

The problem with prosecuting them – they are employees of a White House office, doing what their bosses told them to do, and it is clear their bosses are carrying out the President's wishes.

If Joe Blow off the street walks into a federal agency and takes all their data – open and shut case, throw the book at them, see you in a few decades.

If someone from the White House walks into a federal agency, tells the agency leadership "the President wants me to take all your data", and the agency leadership replies "sure, go right ahead" – not a scenario people were expecting, so the existing laws haven't been crafted to clearly criminalize it. Maybe some enterprising prosecutor can find a way to map it to the crimes on the statute book, maybe it is just too hard. But even if the prosecutor overcomes that hurdle, it will be far from easy to convince the jury / trial judge / appellate courts that the legal elements of the crime are actually met – and if it actually gets as far as a conviction upheld by the appellate court, what do you think the conservative SCOTUS majority are going to do with that when they get it? And many prosecutors, foreseeing those low odds of ultimate success, will stop before they even get to an indictment.

So, I think the odds of anyone ultimately being convicted over this are low, even if Trump never pardons them.

Maybe, Congress might pass a law to make it more clearly illegal, which might make it easier to prosecute if a future administration repeats the same behavior.

EDIT: if people are downvoting this because they think my analysis of the likelihood of successful criminal prosecution is wrong, it would be great if they could reply to explain where they think I got it wrong

Re: DOGE worker’s code supports NLRB whistleblower

#290

Earlier quoted context omitted.

Laws are only as strong as the enforcement. One of the things that is being exposed by the current administration is that, even though the Judiciary is an arm of the government, and supposed to provide a check on the Executive, the reality is that the Executive has the power to pardon anyone it sees fit, voiding the power of the judiciary (the argument is that the ultimate power lies with the voters who can pass thei…

> Laws are only as strong as the enforcement. This is one of the fundamental issues that underlies our broken system in the US. The gaps between what the law actually is, what people think it is, what people want it to be, and what it in practice is, are enormous. Some of the recent deportation cases highlight this. You have cases where people were living in the US illegally for decades but faced no repercussions, an…

Bruh, do you think people are pissed about the deportations just because they’re immigrants?

Deport them all if they came here illegally and that was _proven_, but the government just skipped all due process and as we’re seeing and as the government already admitted, people are being mistakenly deported to these camps and then the same government says they can’t do anything to reverse it.

You can’t be waxing poetic about the rule of law and how we need to enforce everything when they can’t even follow due process

Post reply on HN