Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

421–430 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#421

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

>not something you would expect DOGE people to understand or respect To be fair I see in my daily life folks who copy and paste from stack overflow or random GitHub repo and move on with their day. They ignore the Creative Commons Attribution-ShareAlike or whatever license is applied to the code they copied. I see on this very site people who will share copyrighted articles that are behind a paywall (just because it…

I'd say it's wrong in both cases, but we shouldn't ignore degrees of wrongness.

Copy pasting from stack overflow without attribution is wrong but it's also harder to claim "ownership" over single lines or small snippets. It depends how "obvious" they are. You definitely can't copyright trivial functions. There's a lot of gray here but yes attribution is always good.

But things get a lot less murky when we're talking about forking a project. That's usually nontrivial and non obvious. I think what's most important is that removing a license is an active decision. Certainly that would make a critical difference in a court [0]

Then there's further escalation by who is doing the action. The more power and influence you have the greater responsibilities. All men are not created equal. Men with more power can disproportionally do more damage and require higher accountability. So yeah, I care a fuck ton more about a government employee doing something bad especially while performing official duties more than some rando. The ability to do harm is very different.

The reason I dislike your comment is because it's dismissive of the action. "Other people do it!" Is not a defense nor excuse. It is even worse by ignoring multiple points of context.

[0] though protecting open source has been traditionally hard for many reasons. Specifically it's hard for small developers to take legal action, especially against larger bodies. But isn't this something we should want to be fixed? Credit for our own contributions?!

Re: DOGE worker’s code supports NLRB whistleblower

#424

Earlier quoted context omitted.

> I dont think POTUS can What data in a federal agency could the chief executive not have authorization to access?

I am fairly sure it would be a crime for the President to pull up someone's VA health records on a whim, or at least it would be a crime for anyone at the VA to facilitate him doing that. We can also add to that IRS data. The articles of impeachment against Nixon included the following: "He has, acting personally and through his subordinates and agents, endeavoured to obtain from the Internal Revenue Service, in viol…

I would agree with that emphasis. Misusing presidential privilege is always a possible impeachment, if congress cares.

I think that he can access a health or irs record for cause - anything which would not get him impeached.

Re: DOGE worker’s code supports NLRB whistleblower

#425

Earlier quoted context omitted.

Your argument is that they are so inexperienced and insufficiently monitored that they immediately leaked just-granted NLRB login credentials (how?) to Russia, while rolling out an LLM system (what system?), and the Russian assets that acquired those credentials were so inept that they risked their access — and had their logins rejected — by immediately attempting to use them directly from a Russian IP block? Further…

a) No one knows how Russia had the credentials but they did. b) This system: https://www.wired.com/story/doge-is-just-getting-warmed-up-d... c) DOGE under its current form will end in the next weeks/months as Musk moves on. So if you’re Russia the best bet is to get as much data now as you can.

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#426
post #394
post #356

Earlier quoted context omitted.

> DOGE is a complete clusterfuck. It depends what the objectives are. My impression is that they have been very successful pursuing their actual objectives, while providing a cover story of a 'clusterfuck'.

And conveniently gutting agencies that are or were soon to be thorns in Elon's side. FAA and EPA were annoying him around SpaceX's Starship test launches, CFPB would be annoying for his future everything app plans for Twitter, etc.

Maybe. But none of those make him as much money as Tesla which is in the dumps with all the shenanigans. From a motivation perspective it seems more like rank stupidity than Machiavellian.

Re: DOGE worker’s code supports NLRB whistleblower

#427

Earlier quoted context omitted.

> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.” “If this were a side project, it would just be bad code,” the reviewer wrote. “But if this is representative of how you build production systems, then there are much larger concerns. This implementation is fundamentall…

The "critique" is nuts. Surely AI generated. If I didn't trust the domain, I'd assume the author to be incredible for seriously referencing something like this. Look at the critique [0] and then look at the code [1]. [0] https://web.archive.org/web/20250423135719/https://github.co... [1] https://github.com/ricci/async-ip-rotator/blob/master/src/as...

Yea clearly AI with the keyword bolding, numbered arguments, and so on. Feel like lots of AI produced content follow this structured response pattern.

Re: DOGE worker’s code supports NLRB whistleblower

#428

Earlier quoted context omitted.

Government software can't be copywrited, but the government is under no compulsion to share it. That's what FOIA requests are for.

Actually, they are. It's really more a question of with who and of course don't apply to classified material. But the SHARE IT act really helps formalize what was already happening. Most code is shared and made public. It's paid for by the public. Though it's usually not easily searchable as it's distributed via different platforms, means, and may even require submitting a freedom of information request first. But in…

The "when requested" is the point I was making. FOIA is how you request such software. If you want a copy of the elisp libraries I wrote to automate creation of field devices on military fuel farm SCADA systems, you'll have to submit an FOIA request. Unless someone at the DoD decides to share it out of the goodness of their hearts, you have to ask for it.

Re: DOGE worker’s code supports NLRB whistleblower

#430
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

The Deep State! The government is filled with spies determined to "leak" the great work DOGE is doing is the press - so, of course, it needs "God mode" access. Totally legit.

That's the best I could do. LOL

Post reply on HN