Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

401–410 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#401

1. DOGE employees access data they were not supposed to. This fairly clear. The story says that DOGE attained access to an account that had huge permissions into what it could see and alter. The person or persons from DOGE may have downloaded 10GB of data. The person may have used this in a manner that is illegal. Or it is illegal to start with. With the understanding that POTUS may or may not be allowed grand such a…

> I dont think POTUS can What data in a federal agency could the chief executive not have authorization to access?

I think the question is whether employees of an advisory group that is not an actual department of the government are on the list of people to whom can he authorize access to this type of sensitive data.

Re: DOGE worker’s code supports NLRB whistleblower

#402

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

I wonder why the "no-out-of-country logins" block happens after verifying login credentials and not before, which would make more sense to me.

Re: DOGE worker’s code supports NLRB whistleblower

#403

Earlier quoted context omitted.

You have to keep git repos public as a government employee?

Would be a good trial of the GPL.

You only have to give GPL source to the people who you distribute software to.

You can fork anything privately for yourself.

Re: DOGE worker’s code supports NLRB whistleblower

#404

Earlier quoted context omitted.

Most of the seats up for reelection in 2026 are Dem seats. North Carolina is the only one I can realistically see Dems flipping.

The entire House is up for reelection. They are who impeach. The Senate is who convicts.

Without a conviction, impeachment is just performative at this point.

Re: DOGE worker’s code supports NLRB whistleblower

#406

Earlier quoted context omitted.

> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.” “If this were a side project, it would just be bad code,” the reviewer wrote. “But if this is representative of how you build production systems, then there are much larger concerns. This implementation is fundamentall…

The "critique" is nuts. Surely AI generated. If I didn't trust the domain, I'd assume the author to be incredible for seriously referencing something like this. Look at the critique [0] and then look at the code [1]. [0] https://web.archive.org/web/20250423135719/https://github.co... [1] https://github.com/ricci/async-ip-rotator/blob/master/src/as...

Lol that's so funny. Can't imagine writing that. (the critique, not the code).

Re: DOGE worker’s code supports NLRB whistleblower

#407
post #402

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

I wonder why the "no-out-of-country logins" block happens after verifying login credentials and not before, which would make more sense to me.

Because you need to know who is logging in before you know what IP policy to enforce, no?

Re: DOGE worker’s code supports NLRB whistleblower

#408
post #198

The CEO of Tesla and Space-X; a self-proclaimed high IQ individual, an alleged programmer, has apparently hired a straight-up script kiddie to their elite delta force of technical government downsizers.

I agree with the script kiddies comment- which is basically what the reporting has shown... but in a way isn't that part of the point? That they can save billions of dollars just by having a couple of relatively normal comp sci kids (who can't even rent a car) review the most basic financial information of our government departments. These guys aren't supposed to be "delta force" they are supposed to be the interns.…

At the VA medical system, they word-searched for "consulting" and cancelled contracts for.... surgical equipment sterilization, medical waste removal, stuff related to air quality that's required for hospital accreditation, and local burial services for people who die in the hospital.

Then a lot of those had to be reinstated because you simply can't operate a hospital without sanitation.

Just like they had to scramble to hire back the folks at the National Nuclear Safety Association.

Yeah, efficiency is great. But this is like ordering tacos and getting... a used tire and some dirty diapers...?

Re: DOGE worker’s code supports NLRB whistleblower

#409
post #402

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

I wonder why the "no-out-of-country logins" block happens after verifying login credentials and not before, which would make more sense to me.

Because then you know that credentials have been compromised

Re: DOGE worker’s code supports NLRB whistleblower

#410

Earlier quoted context omitted.

Why does someone from Russia want access to NLRB data, and why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets when it would be trivially traceable back to them, and if they were in fact granted untraceable/unlogged admin credentials, could legitimately download the data themselves and simply hand it over to said Russian assets if that was their actual intention? It's not behav…

> Why does someone from Russia want access to NLRB data It has details of labor disputes. Which if you’re Russia who thrives on fostering conflict in the US would be an ideal data set. > Why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets Because they are young, highly inexperienced engineers who have been tasked with rolling out their LLM system as quickly as possible. Their p…

Your argument is that they are so inexperienced and insufficiently monitored that they immediately leaked just-granted NLRB login credentials (how?) to Russia, while rolling out an LLM system (what system?), and the Russian assets that acquired those credentials were so inept that they risked their access — and had their logins rejected — by immediately attempting to use them directly from a Russian IP block?

Furthermore, that the NLRB data would somehow be of sufficient value to Russian state actors to justify risking burning their access to DOGE employees/data/credentials through frankly idiotic OPSEC, despite there being much higher value targets than the NLRB?

This even remotely doesn't pass the smell test.

Post reply on HN