Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

441–450 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#441
Hello, I work in incident response and cyber forensics within the private sector and as a government contractor. I'm familiar with the government contracting company that currently holds the SOCaaS contract with the NLRB - it's MindPoint Group. They share the a SOC with the DOJ. I reviewed the whistleblower’s evidence, and I have significant doubts about his claims.

Firstly, anyone claiming that "the whole government is compromised" is being conspiratorial. Breaches of this nature are reportable to CISA (US-CERT), the DOJ, local law enforcement, and the FBI. The NLRB has its own cybersecurity incident response team, which includes legal counsel. If both the NLRB and US-CERT determined that this wasn’t a reportable incident then I trust their judgment.

Secondly, I’ve seen a lot of speculative commentary about the Russian IP allegedly logging into the DOGE account. A simple OSINT investigation reveals that this IP has had a negative reputation for over a year, specifically flagged for credential stuffing and scanning activity. Credential stuffing is a common tactic when credentials have been leaked or breached, often showing up on platforms like intelx.io, DeHashed, or BreachForums.

It's also worth noting: no serious nation-state actor would use an IP with such a known bad reputation. Doing so would risk burning any operational investment they’ve made. Nation-state actors almost always use clean infrastructure or proxy chains to conceal their activity.

The timeline the whistleblower presents spans two months, yet I find his interpretation of the activity speculative without hard evidence—especially considering he admits he does not possess the actual logs. That’s a huge red flag.

Thirdly, I tried to find the whistle blower’s official title, and it’s usually hidden in the media. In his official report he states that he is a Dev Sec Ops engineer. He also claims that he lost access to privileges – but the emails in the screen shot seemed to be a zero-trust/principle of least privileges hardening effort. That’s not suspicious to me.

Fourth, the screenshots the whistleblower provided of the Azure environment appeared extremely sparse. While I don’t know the exact size of the NLRB’s infrastructure, unless it's unusually small, I would expect to see more resources. From what I reviewed, the Azure dashboards he used had no filters applied, which raises the question—why are there no other subscriptions, VMs, load balancers, WAFs, etc., visible?

Regarding the DLP policy alerts, he could have easily shown the associated data. Interestingly, the alerts were labeled “test,” which is significant—but he chose not to address or explain that. Omitting that context makes the evidence less compelling. He also leaves out basic critical Indicators of Compromise (IOCs) like src_ip, src_port, dest_ip, dest_port, bytes, and duration. I’m not expecting him to extract mutex and environment variables but showing the basics would be convincing enough consider all they would have been accessible to him from the dashboards he screenshots in the document.

Finally, his claim that the NLRB doesn’t have a SIEM is demonstrably false. The NLRB shares a SIEM with the DOJ, which is operated by MindPoint Group under a SOCaaS contract.

Here’s my general take on the situation: The whistleblower had only been with the organization for six months and served as a mid-level DevSecOps engineer—not a security analyst, incident responder, or SOC analyst. After DOGE was announced, the NLRB began implementing Zero Trust principles and the Principle of Least Privilege. This is typical hardening. As a result, his old admin access which was over provisioned and no longer necessary for his role—was revoked. He panicked. Still having access to some Azure tools, he could have used a test or dev environment (referencing the sparse number of resources in the screenshot but he claimed it to be prod with no filter), toggled a few settings, took screenshot, and constructed a narrative around it. He escalated it to the CEO, who initially listened. However, the incident response team conducted an investigation and found nothing substantiating his claims. NLRB and US-CERT determined it to not be reportable, or which indicates that if it was a security event it was not an incident.

As for the Russian IP, it may be real—but it’s clearly tied to credential stuffing activity, not a sophisticated threat actor. If it genuinely accessed a DOGE account, that would indicate a breach on the DOGE side or weak password hygiene. But again—as mentioned earlier—he doesn’t have the logs to back this up, and his reasons for that are unconvincing. #Doubt.

Re: DOGE worker’s code supports NLRB whistleblower

#442
post #305

Earlier quoted context omitted.

> Setting aside legitimate (thats a matter of judgement) By definition, a judge decides what's legitimate. If DOGE expects their access to be blocked by a court judgement, and bum-rushes agencies to exfiltrate data ahead of the judgement, that's also criminal intent. I am not sure what you are getting at. "Covert" isn't how I'd describe DOGE's actions. "Brazen" maybe?

People have admitted in news interviews to destroying government data to prevent others from knowing what the government was doing. That’s likely criminal. This is a legitimate reason to get at information before people who might destroy have the opportunity. What’s happening with judges is very political. We likely won’t know what’s allowed until things have gone through the appeals process. There have been cases of…

Citation or you're full of shit.

Re: DOGE worker’s code supports NLRB whistleblower

#443
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

The problem with prosecuting them – they are employees of a White House office, doing what their bosses told them to do, and it is clear their bosses are carrying out the President's wishes. If Joe Blow off the street walks into a federal agency and takes all their data – open and shut case, throw the book at them, see you in a few decades. If someone from the White House walks into a federal agency, tells the agency…

All public servants take the oath found in 5 USC 3331. The oath is to support and defend the Constitution of the United States. Not a person.

Re: DOGE worker’s code supports NLRB whistleblower

#444
post #248

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

The repository has been deleted. In addition, 26 other repos have been removed from the account. This is in line with DOGE members' quick response scrubbing data whenever put into spotlight, as previously seen with another "teen hacker". [0] Archived repo page: https://archive.ph/LI7tt ; archived previous repo count: https://archive.ph/tgkg5 0. https://arstechnica.com/tech-policy/2025/04/i-no-longer-hack...

Archived repository: https://archive.softwareheritage.org/browse/origin/directory...

You can download it as a Git repository from https://archive.softwareheritage.org/api/1/vault/git-bare/sw...

Re: DOGE worker’s code supports NLRB whistleblower

#445

Earlier quoted context omitted.

Yea clearly AI with the keyword bolding, numbered arguments, and so on. Feel like lots of AI produced content follow this structured response pattern.

It's uses a simple, purpose-focused template of a type that is a common recommendation for clear communication, outline numbering, and highlights keywords using monospaced text, as is common practice in technical writing. None of that is unusual for a human, especially writing something that they know is going to be high visibility, to do. Modestly competent presentation is now getting portrayed as an "AI tell".

I’m not arguing that it’s unusual for humans to write in this manner, but when you use something like chatgpt with some frequency and see that as a common response template it’s an obvious pattern..

Re: DOGE worker’s code supports NLRB whistleblower

#446

Earlier quoted context omitted.

Yea clearly AI with the keyword bolding, numbered arguments, and so on. Feel like lots of AI produced content follow this structured response pattern.

It's uses a simple, purpose-focused template of a type that is a common recommendation for clear communication, outline numbering, and highlights keywords using monospaced text, as is common practice in technical writing. None of that is unusual for a human, especially writing something that they know is going to be high visibility, to do. Modestly competent presentation is now getting portrayed as an "AI tell".

I'm relatively confident this critique is AI-powered. The dead giveaways:

1. Verbosity. Developers are busy people and security researcher devs are busy even moreso. Someone so skilled wouldn't spend more than 2-3 sentences of time in critiquing this repo.

2. Hostility. Writing bug free code is hard, even impossible for most. Unless your name is Linus Torvalds, Richard Hipp, or maybe Dan Abramov, most devs are not comfortable throwing stones while knowing they live in glass houses.

3. Ownership. "Killshot" comments like this are only ever written by frustrated gatekeepers against weak PRs that would hurt "their baby". Nobody would get emotionally invested in other people's random utility projects. This is just a single python file here without much other context.

4. Author. The author is still an aspiring developer. See their starred repo highlighting adherence to SOLID/DRY principles as a primary feature of their project. Not something you'd expect to see from a seasoned security researcher. https://github.com/SSD1805/EchoFlow

5. Content. The critique is... wrong. It says the single file, utility repo is "awful" for being a "less maintainable" monolith. Hilariously, it calls the code bad because it does not need dependency injection. This was a top critique in the comment!

--

Regardless of political persuasion, I hope this trend of using AI to cyberbully people you don't like goes away.

Re: DOGE worker’s code supports NLRB whistleblower

#447
post #394

Earlier quoted context omitted.

And conveniently gutting agencies that are or were soon to be thorns in Elon's side. FAA and EPA were annoying him around SpaceX's Starship test launches, CFPB would be annoying for his future everything app plans for Twitter, etc.

Maybe. But none of those make him as much money as Tesla which is in the dumps with all the shenanigans. From a motivation perspective it seems more like rank stupidity than Machiavellian.

Their aim seems to be power, and many wealthy people in the US have jumped on the bandwagon of supporting the seizure of power while sacrificing some money. Musk will have a roof over his head regardless.

Re: DOGE worker’s code supports NLRB whistleblower

#448
post #443

Earlier quoted context omitted.

The problem with prosecuting them – they are employees of a White House office, doing what their bosses told them to do, and it is clear their bosses are carrying out the President's wishes. If Joe Blow off the street walks into a federal agency and takes all their data – open and shut case, throw the book at them, see you in a few decades. If someone from the White House walks into a federal agency, tells the agency…

All public servants take the oath found in 5 USC 3331. The oath is to support and defend the Constitution of the United States. Not a person.

That's not a counterargument to my position that successful criminal prosecution is unlikely.

If you are going to charge them with a crime, which one? CFAA?

How then to prove that access is unauthorized under the CFAA given evidence that both the President and senior agency leadership authorized it? Trying to claim that those authorizations are legally invalid gets into rather murky areas of law, and is (AFAIK) without precedent. Can you point to any previous cases of a successful CFAA prosecution where the access was authorized by a senior federal official but that authorization was declared legally void?

How do you get past the fact that the law is ultimately whatever SCOTUS says it is, and it seems more likely than not that the majority of current SCOTUS will want to say that this specific situation isn't a crime?

I feel like people are rejecting my position because they don't like it or don't want it to be true. Of course, maybe I'm wrong – maybe Thomas, Alito, Gorsuch, Kavanagh, Barrett and Roberts are all secretly dreaming of sending Musk and his minions to federal prison; or maybe they'll dispassionately follow their own judicial philosophies to the logical conclusion that doing so (using CFAA or whatever) is statutorily and constitutionally required - but that doesn't seem very likely to me, given their track records. Do you really think I'm wrong about that?

Re: DOGE worker’s code supports NLRB whistleblower

#449

Earlier quoted context omitted.

not sure if this is a serious question…? what would it accomplish if you were the whistleblower? if it was me, my family would be on the first flight out of the country

It would convince me that whoever I was whistleblowing on was so remarkably stupid as to engage in a felonious criminal conspiracy while leaving behind physical evidence thereof. I hope that the threatening note and photos have been turned over to the police, where they can be analyzed for fingerprints, printer microdots, et al, and the police can canvas the neighborhood for security camera footage. As a tactical mov…

That assumes that legal repercussions are expected. The current administration behaves as if laws are only to be followed in case of failure, and only temporarily.

They refer to "lawfare", where you do whatever you feel necessary, and only engage in legal systems where absolutely required, and only to make whatever inciting behaviour legal in retrospect.

Re: DOGE worker’s code supports NLRB whistleblower

#450

Earlier quoted context omitted.

I would have thought that a Russian state sponsored attack would trivially mask the IP to originate from within the USA. This is just brazen.

May not be state sponsored. Could just be a Russian hacking group associated with the DOGE person. Or it could be state sponsored and they didn’t think they needed to be covert as they could walk through the front door on invitation of the executive branch.

There's also a chance Musk just hired a Russian citizen to work for him.
Post reply on HN