Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

31–40 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#31
post #7

Earlier quoted context omitted.

If I told you someone went to your bank and demanded the right to setup accounts with permissions to do everything and to have all logging of that users activity disabled, and then a whistleblower pointed out that they downloaded everyone's bank statements, you'd probably be pretty up set. After all, why do they need unfettered access? Why do they need your bank statements? Why do they need to hide what they're doing…

[flagged]

The article specifically covers this point. They exceeded their authority.

Re: DOGE worker’s code supports NLRB whistleblower

#33
I have a theory that "business ethics" is really just "following the law." In capitalism, outside a few select industries like journalism, as long as it's legal you can - and should - do anything to maximize profits. It has turned into (or perhaps always was) the govt's job to set those rules.

Now, the govt also has to create rules for itself. So it creates the Privacy Act and layers of beurocratic checks and balances. These rules are to protect the people, not to derisk or protect the govt. After all, the govt has all the power.

So when capitalist businesses leaders are given the keys to govt, the normal ways of ethical alignment don't work. If you don't follow your own rules, who cares? They're your rules! I think what we're seeing is what happens if you apply traditional capitalist business practices to govt administration.

Re: DOGE worker’s code supports NLRB whistleblower

#34

The fact that they left these packages public on GitHub.. guys you do know you can make things private right? Just shows how dumb these people are honestly

Or they are emboldened in knowing there will be absolutely no consequences.

Go look at the list of pardons this administration has handed out. These guys won’t even be charged.

Re: DOGE worker’s code supports NLRB whistleblower

#35
post #27
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

There isn't one. Anything musk's dogs claim to find cannot be taken at face value because of this. Because there is no audit, and no evidence that they can offer that they didn't doctor their findings. The next time they claim that a 170-year old person is receiving SS checks, they have no way to prove that they didn't subtract a century from that person's birthdate in some table.

Ah, this is something I haven't thought of before. This might not actually be spying, but instead just an attempt to plant fake results.

Re: DOGE worker’s code supports NLRB whistleblower

#36

Earlier quoted context omitted.

Explain please.

The complaint alleges that DOGE was able to get unlimited-permissions admin accounts that were not subject to logging. They also downloaded external repositories that gave users of those repos lots of different IPs. The complaint further alleges that the DOGE person used the combination of these things to "download... more than 10 gigabytes of data from the agency’s case files, a database that includes reams of sensi…

And they fucking illegally fired the IGs who are supposed to act as watchdogs for and light-shiners-on-of blatantly-illegal activity like this in the executive. The ones we added after Nixon's crimes. It was one of the first actions of the administration, blanket firing without actual cause, which is supposed to be required, and without the required notice-period to Congress.

That should have exhausted any benefit of the doubt right off the bat, even among those inclined to think Trump's maybe not great but also some ordinary amount of bad for a politician. You don't do that unless you fully intend to do some crimes. Not only that, they were so goddamn eager to crime that they couldn't wait the 30 days or whatever. They intended to do criminal shit immediately.

Re: DOGE worker’s code supports NLRB whistleblower

#37
post #7

Earlier quoted context omitted.

If I told you someone went to your bank and demanded the right to setup accounts with permissions to do everything and to have all logging of that users activity disabled, and then a whistleblower pointed out that they downloaded everyone's bank statements, you'd probably be pretty up set. After all, why do they need unfettered access? Why do they need your bank statements? Why do they need to hide what they're doing…

[flagged]

An obvious rebuttal is they should not have that authority, and the possible reasons for having gained it are nefarious.

Re: DOGE worker’s code supports NLRB whistleblower

#39

So what exactly is being alleged here? That these DOGE bros wrote and used “hacker” code from GitHub to bypass security limitations on NLRB data? Why would they even need to do that if they had superuser accounts in the system already?

they added a backdoor that is not audit logged. that's why.

Re: DOGE worker’s code supports NLRB whistleblower

#40
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity

Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

Post reply on HN