Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

321–330 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#321
post #248

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

The repository has been deleted. In addition, 26 other repos have been removed from the account. This is in line with DOGE members' quick response scrubbing data whenever put into spotlight, as previously seen with another "teen hacker". [0] Archived repo page: https://archive.ph/LI7tt ; archived previous repo count: https://archive.ph/tgkg5 0. https://arstechnica.com/tech-policy/2025/04/i-no-longer-hack...

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#322

Earlier quoted context omitted.

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Don't forget the third option: false flag. The objective may not have been to obtain access or any useful data. The objective may have been to get the scary headlines about Russians and use the existing media and political agitprop to further destabilize the government you seek to color revolution away.

It doesn't make sense to me that an administration that by and large has been throating Putin would do that to throw more shade on Russia.

I'm not saying they didn't do that, just that it's not in line with their support for Putin and Russia. Maybe as a false flag it give Putin the cover to crack down on hacking groups that don't throat him.

Re: DOGE worker’s code supports NLRB whistleblower

#324
post #215

Earlier quoted context omitted.

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

That's straight up traitorous. DOGE needs to be shutdown and everyone of them held as a flight risk while the whole thing is investigated.

They work for Trump so they'll never be held to account, even if a Democrat wins the next election (assuming even have one and it's fair and free)

I never thought I'd be calling for UN observers for an election in the US but here we are

Re: DOGE worker’s code supports NLRB whistleblower

#325
post #115

I find the following bizarre. Ignoring who this marko guy is, why would a random person post such a "take down" of the repo? I have never randomly passed by a repo and wanted to just dunk on it. Also this critique reeks of being AI generated. > On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundament…

They took down the repository ~20 minutes after OP's comment. Archived link: https://web.archive.org/web/20250423135719/https://github.co...

Surely Elez is currently reading this thread right now too. Probably reveling in the attention like all the juvenile hacker boys.

Re: DOGE worker’s code supports NLRB whistleblower

#327

Isn't the ip rotator used to scrape from public websites to bypass rate limits? Not sure how that automatically means they are "siphoning sensitive case files".

The IP rotator was discovered in the analysis. The exfiltration of data was discovered by an NLRB employee and triggered the complaint. A member of their staff saw the spike in egress, found the source and that the audit log had been bleached.

Re: DOGE worker’s code supports NLRB whistleblower

#328

Earlier quoted context omitted.

Except that all you’d be doing is creating a trail of physical evidence demonstrating a felony conspiracy — and a frankly stupid one at that.

From recent news it seems unlikely these guys are interested in behaving rationally.

It just doesn’t pass the smell test.

- Who decided to threaten the whistleblower and why?

- Who approved such an idiotic idea?

- Who determined his home address?

- Who flew the drone, timed to capture photos of the whistleblower while on his way to/from his home?

- Who took the drone photography, printed out the images, and wrote a threatening note?

- Who then took all that and physically posted it on his door?

That’s a very involved process, with substantial risk, with no realistic upside. None of the incentives are aligned with the behavior. It simply doesn’t make sense.

Applying Occam’s razor, it seems a lot more likely to be fabricated — that’s a scenario in which incentives actually align with the behavior.

In practice, that shouldn’t make a difference to the investigation; given the physical evidence, they should investigate in great detail the origin of the threat — regardless of whether it’s a hoax or real.

Re: DOGE worker’s code supports NLRB whistleblower

#329
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

Interview with whistleblower detailing the attack and the threats directed against him:

https://www.pbs.org/newshour/show/nlrb-whistleblower-claims-...

Re: DOGE worker’s code supports NLRB whistleblower

#330

Earlier quoted context omitted.

This just seems odd. Why would they attempt a login from Russia (if it was indeed Russians)? It is incredibly cheap to use a VPN with a US residential IP.

Maybe not everyone involved is quite the genius you might've been expecting.

Occam’s razor would also suggest a hoax as one of several very credible possibilities.
Post reply on HN