Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

411–420 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#411

Earlier quoted context omitted.

Your argument makes sense. I still speculate they're doing malicious things.

DOGE was given a mandate by a President with unprecedented (hah) unitary power. They’re executing on that, roughly how you’d expect them to, given their instructions and the time and resources available to them. I personally feel that they’re being reckless and sloppy, uncovering “waste” that is often simply an artefact of their hubris. In doing so, they’re risking exposing the internal systems of the government to o…

1. DOGE is acting in this way to uncover the "deep state" (unironically).

2. DOGE is committing treason.

3. DOGE is humiliating those who were formerly in control.

A little of column A, B, and C in my opinion. At this point it doesn't matter what's true. I think all parties are involved to commit terrible acts, whether they're directly assets of a foreign power or just have something to gain. Inept, traitorous, opportunistic, inhumane, careless.. the whole party is here.

I hope when all is said and done, a true accounting is performed and those who committed the damage are held responsible. It won't matter what their associations or intent was. Manslaughter is manslaughter.

Re: DOGE worker’s code supports NLRB whistleblower

#412

Earlier quoted context omitted.

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

I would have thought that a Russian state sponsored attack would trivially mask the IP to originate from within the USA. This is just brazen.

May not be state sponsored. Could just be a Russian hacking group associated with the DOGE person.

Or it could be state sponsored and they didn’t think they needed to be covert as they could walk through the front door on invitation of the executive branch.

Re: DOGE worker’s code supports NLRB whistleblower

#413

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

How dumb would Russian hackers be to not use some kind of vpn? My friend who lives in Russia says that without vpn he can not access majority of USA sites so he has it always on be default. Something to is not right or these people are very very dumb.

Re: DOGE worker’s code supports NLRB whistleblower

#414

Earlier quoted context omitted.

These are government employees, you don't get to do that.

Government software can't be copywrited, but the government is under no compulsion to share it. That's what FOIA requests are for.

Actually, they are. It's really more a question of with who and of course don't apply to classified material.

But the SHARE IT act really helps formalize what was already happening. Most code is shared and made public. It's paid for by the public. Though it's usually not easily searchable as it's distributed via different platforms, means, and may even require submitting a freedom of information request first. But in more cases than not, there is obligation to share when requested.

https://www.congress.gov/bill/118th-congress/house-bill/9566

Re: DOGE worker’s code supports NLRB whistleblower

#415

Earlier quoted context omitted.

Would be a good trial of the GPL.

You only have to give GPL source to the people who you distribute software to. You can fork anything privately for yourself.

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#416
post #365

Earlier quoted context omitted.

> DOGE staffers would have been instructed not to trust any custom role, so… Tenant Admin it is. Ok, arguing with DOGE on their own terms… I confess I’m not knowledgeable with these systems, but how do you even trust it when it tells you you’re the “Tenant Admin”? Why would the deep state be unable to fabricate such a role that looks like the real one but is still lying to you? I did enough research to assume this is…

Azure for example has a built in role (actually a checkbox) that is un-fakeable by anyone that can’t MITM the portal web site. The NSA might be able to do this, but even they’d be finding it a challenge if forced to do so on short notice with someone looking over their shoulder.

Infiltrating Azure, hacking a third-world CA, or evil maiding DOGE employees’ computers would be among the easiest tasks the deep state would undertake. On one hand, sure, criminals fail at easy things all the time, but this is the supposed most powerful secret organization; you can’t assume you have a technical solution they can’t crack. Focus on data they didn’t show you just because you said “tenant admin.”

Re: DOGE worker’s code supports NLRB whistleblower

#417

Earlier quoted context omitted.

Or they are emboldened in knowing there will be absolutely no consequences. Go look at the list of pardons this administration has handed out. These guys won’t even be charged.

They were given a blanket pardon dating back to 2014. No crime even listed!

Sounds like another administration I know....

Re: DOGE worker’s code supports NLRB whistleblower

#418

Earlier quoted context omitted.

> This sounds scary but I regularly request this right from large government departments and I get it granted to me. Prove it. I want you to give examples of where you did something like this.

It’s not publicly provable for many obvious reasons such as the delegation being time bound.

Anything is publicly provable. And I think you can publicly prove it too. As another poster put it, if that's how you've dealt with systems before then either you were working with publicly available data or you were party to a crime.

Re: DOGE worker’s code supports NLRB whistleblower

#419

Earlier quoted context omitted.

> Why does someone from Russia want access to NLRB data It has details of labor disputes. Which if you’re Russia who thrives on fostering conflict in the US would be an ideal data set. > Why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets Because they are young, highly inexperienced engineers who have been tasked with rolling out their LLM system as quickly as possible. Their p…

Your argument is that they are so inexperienced and insufficiently monitored that they immediately leaked just-granted NLRB login credentials (how?) to Russia, while rolling out an LLM system (what system?), and the Russian assets that acquired those credentials were so inept that they risked their access — and had their logins rejected — by immediately attempting to use them directly from a Russian IP block? Further…

a) No one knows how Russia had the credentials but they did.

b) This system: https://www.wired.com/story/doge-is-just-getting-warmed-up-d...

c) DOGE under its current form will end in the next weeks/months as Musk moves on. So if you’re Russia the best bet is to get as much data now as you can.

Re: DOGE worker’s code supports NLRB whistleblower

#420

The fact that they left these packages public on GitHub.. guys you do know you can make things private right? Just shows how dumb these people are honestly

What? They reused public packages that have been public for years. One guy made a public fork with some changes. Is that not what open source is intended for?

You misunderstand, open source is bad actually, when the heckin cheeto man is the one doing it.

Just as its only worth complaining about geriatric geezers in office until the cheeto man brings in young hackers, then the problem is that "the old impaired people were good, actually".

Don't observe. Don't think. Merely repeat the approved message.

> The Party told you to ignore the evidence of your eyes and ears. It was their final, most essential command.

Post reply on HN