Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

371–380 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#371

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Related: https://infosec.exchange/@briankrebs/114083485241630234

Excerpt: "How much more proof do we need that this administration is completely compromised? There is zero reason for the US to relax any offensive digital actions against Russia. If anything, we should be applying more."

Re: DOGE worker’s code supports NLRB whistleblower

#372
post #178

Earlier quoted context omitted.

We'll see. The thing about the law in the US, it's slow and heavy. You'll need to be pretty mighty to move it if it catches up to you.

I would have agreed years ago, but seeing trump - who obviously should be in prison for January 6th, among other crimes - back in the WH pretty much proves the US is not a nation of laws.

Voters elected an abuser and now we're being abused.

This is what happens with the authoritarian faction, present in all societies, wins an election. The people who stand for the Constitutional order didn't do enough. Whether they weren't sufficiently positive persuasive or negatively persuasive, here we are with President Psycho in office.

The law didn't fail. Order didn't fail. The self-governed, the people, failed to support and defend the Constitution.

Re: DOGE worker’s code supports NLRB whistleblower

#374

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.” “If this were a side project, it would just be bad code,” the reviewer wrote. “But if this is representative of how you build production systems, then there are much larger concerns. This implementation is fundamentall…

The "critique" is nuts. Surely AI generated. If I didn't trust the domain, I'd assume the author to be incredible for seriously referencing something like this.

Look at the critique [0] and then look at the code [1].

[0] https://web.archive.org/web/20250423135719/https://github.co...

[1] https://github.com/ricci/async-ip-rotator/blob/master/src/as...

Re: DOGE worker’s code supports NLRB whistleblower

#375

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

> This sounds scary but I regularly request this right from large government departments and I get it granted to me. Prove it. I want you to give examples of where you did something like this.

It’s not publicly provable for many obvious reasons such as the delegation being time bound.

Re: DOGE worker’s code supports NLRB whistleblower

#376
post #181

Earlier quoted context omitted.

That is a very serious design flaw, but I also believe it is a flaw that is addressed by SELinux. (Perhaps someone with a knowledge of SELinux can offer some input here.) That said, I'm not sure how widespread the use of SELinux is and doubt that it would help in this case since the people in question have or can gain physical access.

If your root, you can just turn off selinux

Not without a reboot though, and while I haven’t done that, it should be possible to protect selinux ‘s config itself with a policy, requiring boot loader access to bypass, at which point you’re dealing with a different risk level.

I’ll agree that Linux security is quite limited and primitive if compared with, say, a mainframe, but it can be made less bad with a reasonable amount of effort.

Re: DOGE worker’s code supports NLRB whistleblower

#377
post #198

Earlier quoted context omitted.

I agree with the script kiddies comment- which is basically what the reporting has shown... but in a way isn't that part of the point? That they can save billions of dollars just by having a couple of relatively normal comp sci kids (who can't even rent a car) review the most basic financial information of our government departments. These guys aren't supposed to be "delta force" they are supposed to be the interns.…

> I would really like my tax money used more efficiently. This is immature thinking, because, who wouldn't? The contention comes from differing opinions on what is waste.

It's a manipulation technique. It implies that the opposition doesn't believe this.

Re: DOGE worker’s code supports NLRB whistleblower

#378
post #354

Earlier quoted context omitted.

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Isn't it just that the IP router happens to use IPs in Russia as part of the rotation? If they're trying to exfiltrate data, they might want to rotate through IP addresses in order to obfuscate what's going on or otherwise circumvent restrictions. Using a simple ip rotator like the post talks about would maybe be an approach they'd use. If they're not careful with the IP addresses, once in a while one might get caugh…

It uses AWS API Gateway. There is not a Russian AWS region.

Re: DOGE worker’s code supports NLRB whistleblower

#379
post #82

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

In that case, you and departments you work for are either breaking the law regularly or working with public data anyway. Besides, no one needs unmonitored write access for audit. Even less DOGE who does no audit and don't have knowledge how to do audit. Audits are supposed to he traceable.

No one needs write access, but most systems only have a read/write predefined role for tenant-wide access. If you don’t trust the department staff to give you anything but a predefined role, it’s typically the only option. Similarly if you need to fire privileged IT staff on the spot for headcount reduction you need admin-equivalent rights to lock them out. You can’t in general trust disgruntled admins to lock themselves out!

Also, in some cloud systems full read access can give you direct or indirect access to service keys / API keys which then are write equivalent permissions anyway.

Re: DOGE worker’s code supports NLRB whistleblower

#380
post #360

Earlier quoted context omitted.

I hated Elon Musk long before it was cool: I was a fan of Tesla in the early days, and when I read Musk's "super-secret master plan" for Tesla I thought "yeesh, the board chairman is an idiot, where did they find this bozo?" (I knew a bit about SpaceX but somehow didn't make the connection.) That said, I was surprised to learn much later that, by all accounts, Elon Musk was a competent and resourceful leader in Space…

> That said, I was surprised to learn much later that, by all accounts, Elon Musk was a competent and resourceful leader in SpaceX's early days. Maybe these stories are just his personality cult in action, but I found it plausible He's good at having and raising money which was what SpaceX needed, I think he was probably the same then as he is now. Reading about his early days at Tesla and the PayPal stuff, I don't r…

This is a frustrating comment. I said "I was surprised to learn" because I had the same impression you did, but then I learned something new. It seems like you're just rejecting my conclusion out of hand without bothering to learn anything.

Eric Berger's book in particular suggests that, before Falcon 1 was successful, Musk was much more humble and collaborative with the other early SpaceX hires, and typically deferred to their expertise. He was always reckless and megalomaniacal. But after Falcon 1 he became much worse.

Post reply on HN