Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

291–300 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#291

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

I would have thought that a Russian state sponsored attack would trivially mask the IP to originate from within the USA. This is just brazen.

Re: DOGE worker’s code supports NLRB whistleblower

#292

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

This just seems odd.

Why would they attempt a login from Russia (if it was indeed Russians)?

It is incredibly cheap to use a VPN with a US residential IP.

Re: DOGE worker’s code supports NLRB whistleblower

#293
post #198

Earlier quoted context omitted.

I agree with the script kiddies comment- which is basically what the reporting has shown... but in a way isn't that part of the point? That they can save billions of dollars just by having a couple of relatively normal comp sci kids (who can't even rent a car) review the most basic financial information of our government departments. These guys aren't supposed to be "delta force" they are supposed to be the interns.…

> I would really like my tax money used more efficiently Except by most accounts so far it was being used efficiently by the federal workforce. This whole debacle will end up costing the US tax payer more money. See cutting the IRS or USAID which will probably lead the US to bailing out farmers. And if they privatize, then it'll be even more expensive.

I mean if they privatize USAID it’s a tremendous opportunity to loot on a scale we have not seen. Same thing if they privatize the IRS or Social Security. Think about all the money that could be invested in their friends’ enterprises out of the treasury float or the SS trust fund.

Re: DOGE worker’s code supports NLRB whistleblower

#294
post #198

Earlier quoted context omitted.

I agree with the script kiddies comment- which is basically what the reporting has shown... but in a way isn't that part of the point? That they can save billions of dollars just by having a couple of relatively normal comp sci kids (who can't even rent a car) review the most basic financial information of our government departments. These guys aren't supposed to be "delta force" they are supposed to be the interns.…

> I would really like my tax money used more efficiently. This is immature thinking, because, who wouldn't? The contention comes from differing opinions on what is waste.

A lot of people seem to consider anything that doesn’t personally, immediately, and directly benefit them to be a waste of their tax dollars. God forbid you use their property taxes to build schools their adult children don’t go to.

Re: DOGE worker’s code supports NLRB whistleblower

#295
post #243

Earlier quoted context omitted.

It's only "bizarre" if you "ignore who this marko guy is." It's not a coincidence, it's somebody pointing out that DOGE's "cracked coders" are wearing no clothes.

Well yeah they're junior developers. By all account from good schools but literally everyone here has dealt with junior developer brain. I would say that Elmo picked a bunch of junior devs because they don't have enough maturity to talk back and will do anything they're asked but I think that's too charitable. I think he actually went this route because Elmo is a sad man in his 50s who is desperately trying to preten…

Not just junior developers, but zoomer junior developers. I'm guessing Marko was just following Grok's advice.

Re: DOGE worker’s code supports NLRB whistleblower

#297

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Best case scenario those kids were duped into giving out credentials to the wrong (Russian) people.

Re: DOGE worker’s code supports NLRB whistleblower

#298

Earlier quoted context omitted.

Sometimes, depending on the situation. My company retains all e-mails for at least 5 years, for audit purposes. But if some troublemaker were to e-mail child porn to an employee, we'd need to remove that from the audit records, because the laws against possessing child porn don't have an exception for corporate audit records. So there's essentially always some account with the power to erase things from the audit rec…

It sounds like you haven't actually had to face that situation, because it is more complicated than just having to delete an offending attachment. You would still have an audit log of the deletion of that email record by the superuser, even if the content is deleted. And there would be other records generated to document the deletion, like I'm sure a long email or slack thread from this getting discovered and sent up…

Yeah, superuser accounts? Of course you need them to exist. Superuser accounts that produce no logs? There is never a reason for that. Anyone who claims they should have a superuser with no logging is up to no good.

Re: DOGE worker’s code supports NLRB whistleblower

#299

Earlier quoted context omitted.

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

I would have thought that a Russian state sponsored attack would trivially mask the IP to originate from within the USA. This is just brazen.

Sometimes getting caught isn’t a bad thing. If you are trying to seed division between to groups, acting in a way that divides them - e.g., getting caught helping one side - is more effective than what you gain by not getting caught.

I struggle to see what Russia would gain with nlrb data, but getting caught “helping doge” furthers distrust between the two sides of our country - which is something they gain from

Re: DOGE worker’s code supports NLRB whistleblower

#300
post #215
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

That's straight up traitorous.

DOGE needs to be shutdown and everyone of them held as a flight risk while the whole thing is investigated.

Post reply on HN