Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

391–400 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#391

Earlier quoted context omitted.

This Congress probably won't, but the next one might.

Most of the seats up for reelection in 2026 are Dem seats. North Carolina is the only one I can realistically see Dems flipping.

The entire House is up for reelection. They are who impeach. The Senate is who convicts.

Re: DOGE worker’s code supports NLRB whistleblower

#392

Earlier quoted context omitted.

This just seems odd. Why would they attempt a login from Russia (if it was indeed Russians)? It is incredibly cheap to use a VPN with a US residential IP.

Maybe not everyone involved is quite the genius you might've been expecting.

And/or they just dgaf because they know they or anyone else involved won't ever be held accountable.

Re: DOGE worker’s code supports NLRB whistleblower

#393

[flagged]

> Musk has installed Starlink terminals on the whitehouse rooftop, to bypass security This is confirmation bias and absolutely unsubstantiated nonsense. Hedging your bets on hyperbolic dreck like this is why people don't take the serious stuff seriously. Do you think cellphone hotspots - that everyone has in their pocket - are also part of some grand conspiracy?

Good point, why install another internet connection (starlink) when you can easily use celluar data if you wanted to avoid White House network security?

Very weird

Re: DOGE worker’s code supports NLRB whistleblower

#394
post #356

Earlier quoted context omitted.

Not parent but it’s here - https://krebsonsecurity.com/2025/04/whistleblower-doge-sipho... DOGE is a complete clusterfuck. Fwiw I think there is hard to spot fraud in the govt that should be looked at (eg price inflation at the pentagon, VA, Medicaid/Medicare, SS). They should have done the hard work of uncovering that. Instead they just went for clickbait headlines.

> DOGE is a complete clusterfuck. It depends what the objectives are. My impression is that they have been very successful pursuing their actual objectives, while providing a cover story of a 'clusterfuck'.

And conveniently gutting agencies that are or were soon to be thorns in Elon's side. FAA and EPA were annoying him around SpaceX's Starship test launches, CFPB would be annoying for his future everything app plans for Twitter, etc.

Re: DOGE worker’s code supports NLRB whistleblower

#395

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.” “If this were a side project, it would just be bad code,” the reviewer wrote. “But if this is representative of how you build production systems, then there are much larger concerns. This implementation is fundamentall…

Seeing Krebs link to this downgrades my impression of how trustworthy his assessments are.

Re: DOGE worker’s code supports NLRB whistleblower

#396
post #376

Earlier quoted context omitted.

If your root, you can just turn off selinux

Not without a reboot though, and while I haven’t done that, it should be possible to protect selinux ‘s config itself with a policy, requiring boot loader access to bypass, at which point you’re dealing with a different risk level. I’ll agree that Linux security is quite limited and primitive if compared with, say, a mainframe, but it can be made less bad with a reasonable amount of effort.

What would the mainframe be running that avoids this problem?

Re: DOGE worker’s code supports NLRB whistleblower

#397

To everyone saying 'where are the arrests?' This is all conjecture at this point and time will tell what was click bait and truth. Below is the statement from NLRB's acting press secretary. "Tim Bearese, the NLRB's acting press secretary, denied that the agency granted DOGE access to its systems and said DOGE had not requested access to the agency's systems. Bearese said the agency conducted an investigation after Be…

People should not need to be conjecturing. The federal government should have clear documented reasons for the things that it does. It should have oversight, but all of the oversight has been fired, every department headed by yesmen and fox news anchors. We are all left guessing because they are doing loads of things that seem either treasonous or performed with very little thought to the consequences.

Re: DOGE worker’s code supports NLRB whistleblower

#398

Earlier quoted context omitted.

This Congress won't impeach Trump. If they were willing to, they would've already.

This Congress probably won't, but the next one might.

They could impeach again, but senate will refuse to convict. If Jan 6 didn't motivate them to stop this, nothing will.

Re: DOGE worker’s code supports NLRB whistleblower

#399

1. DOGE employees access data they were not supposed to. This fairly clear. The story says that DOGE attained access to an account that had huge permissions into what it could see and alter. The person or persons from DOGE may have downloaded 10GB of data. The person may have used this in a manner that is illegal. Or it is illegal to start with. With the understanding that POTUS may or may not be allowed grand such a…

> I dont think POTUS can What data in a federal agency could the chief executive not have authorization to access?

I am fairly sure it would be a crime for the President to pull up someone's VA health records on a whim, or at least it would be a crime for anyone at the VA to facilitate him doing that.

We can also add to that IRS data. The articles of impeachment against Nixon included the following:

"He has, acting personally and through his subordinates and agents, endeavoured to obtain from the Internal Revenue Service, in violation of the constitutional rights of citizens, confidential information contained in income tax returns for purposes not authorized by law" (emphasis mine).

There actually are laws regulating the handling of personal data collected by the government and it generally doesn't have a "the president wants to see it" exception.

Re: DOGE worker’s code supports NLRB whistleblower

#400

Earlier quoted context omitted.

Occam's razor would suggest someone from Russia could just use their own IP because people like you would think it's a hoax anyway.

Why does someone from Russia want access to NLRB data, and why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets when it would be trivially traceable back to them, and if they were in fact granted untraceable/unlogged admin credentials, could legitimately download the data themselves and simply hand it over to said Russian assets if that was their actual intention? It's not behav…

> Why does someone from Russia want access to NLRB data

It has details of labor disputes. Which if you’re Russia who thrives on fostering conflict in the US would be an ideal data set.

> Why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets

Because they are young, highly inexperienced engineers who have been tasked with rolling out their LLM system as quickly as possible. Their priority is not security.

Post reply on HN