Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

481–490 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#481
post #248

Earlier quoted context omitted.

The repository has been deleted. In addition, 26 other repos have been removed from the account. This is in line with DOGE members' quick response scrubbing data whenever put into spotlight, as previously seen with another "teen hacker". [0] Archived repo page: https://archive.ph/LI7tt ; archived previous repo count: https://archive.ph/tgkg5 0. https://arstechnica.com/tech-policy/2025/04/i-no-longer-hack...

[flagged]

[dead]

Re: DOGE worker’s code supports NLRB whistleblower

#482
post #305

Earlier quoted context omitted.

> Setting aside legitimate (thats a matter of judgement) By definition, a judge decides what's legitimate. If DOGE expects their access to be blocked by a court judgement, and bum-rushes agencies to exfiltrate data ahead of the judgement, that's also criminal intent. I am not sure what you are getting at. "Covert" isn't how I'd describe DOGE's actions. "Brazen" maybe?

People have admitted in news interviews to destroying government data to prevent others from knowing what the government was doing. That’s likely criminal. This is a legitimate reason to get at information before people who might destroy have the opportunity. What’s happening with judges is very political. We likely won’t know what’s allowed until things have gone through the appeals process. There have been cases of…

In American system, appeal process is a very formal thing - it checks whether all the ts were crossed, whether process was followed. It is not checking the evidence, it is bringing new evidence, nothing like that.

That is how it was designed.

Re: DOGE worker’s code supports NLRB whistleblower

#483

Earlier quoted context omitted.

I have taken part in audits for several organizations over the years, and I can assure you that's not how audits are done at all. In fact, should the auditor find there is a way for them to access sensitive data without it being logged, they will flag it immediately. That would be the case even under simple financial regulation. There is absolutely the risk that the people you audit will lie to you or present you wit…

A normal audit, sure. This isn’t that. This is the prison guards flipping the mattress looking for contraband. All of the public complaining is by staff that don’t understand their new position in the pecking order. There is a King in charge and he cares not for the wailing of the petty nobles.

>This is the prison guards flipping the mattress looking for contraband.

No its not. These prison searches in fact do tend to find knives and what not and do in fact have some role in managing prison violence.

This is not about anything like that at all.

Re: DOGE worker’s code supports NLRB whistleblower

#484
post #248

Earlier quoted context omitted.

The repository has been deleted. In addition, 26 other repos have been removed from the account. This is in line with DOGE members' quick response scrubbing data whenever put into spotlight, as previously seen with another "teen hacker". [0] Archived repo page: https://archive.ph/LI7tt ; archived previous repo count: https://archive.ph/tgkg5 0. https://arstechnica.com/tech-policy/2025/04/i-no-longer-hack...

Archived repository: https://archive.softwareheritage.org/browse/origin/directory... You can download it as a Git repository from https://archive.softwareheritage.org/api/1/vault/git-bare/sw...

Legally, they're allowed to modify and use GPL code internally without redistributing the source. The only mistake was publishing the source code to a public git repo without the LICENSE file, which may be a GPL violation.

I say "may", because I'm not sure if you have internal code on a public git or FTP server, is that consider "distributing"?

Re: DOGE worker’s code supports NLRB whistleblower

#485

Earlier quoted context omitted.

They work for Trump so they'll never be held to account, even if a Democrat wins the next election (assuming even have one and it's fair and free) I never thought I'd be calling for UN observers for an election in the US but here we are

> They work for Trump so they'll never be held to account, even if a Democrat wins the next election Why? If Democrats take the House in the midterms, which looks more likely the longer Navarro and Musk have West Wing access, they can basically turn these folks' lives into a living hell of back-to-back hearings (and contempt charges down the road). And if Democrats win the next election, they'll presumably put someon…

I think Trump could simply pardon them, unfortunately.

Re: DOGE worker’s code supports NLRB whistleblower

#486

this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw way above baseline response times, and resource utilization showed increased network output above anywhere it had been historically – as far back as I could look. I noted that this lined up closely with the data out event. I also notice increased logins blocked…

Any guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.

Yeah, like the APT that compromised O365 accounts from US gov entities a year or so ago, using residential proxies to go around Conditional Access Policies..., is now logging in straight from the Kremlin. :D

Re: DOGE worker’s code supports NLRB whistleblower

#487
post #485

Earlier quoted context omitted.

> They work for Trump so they'll never be held to account, even if a Democrat wins the next election Why? If Democrats take the House in the midterms, which looks more likely the longer Navarro and Musk have West Wing access, they can basically turn these folks' lives into a living hell of back-to-back hearings (and contempt charges down the road). And if Democrats win the next election, they'll presumably put someon…

I think Trump could simply pardon them, unfortunately.

> Trump could simply pardon them

Ironically, one of the most useful things Trump could do is prosecute e.g. Hunter Bide so SCOTUS can strike down preëmptive pardons.

Re: DOGE worker’s code supports NLRB whistleblower

#488

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

The GitHub part makes it... weird.

You are only required to keep the GPL3 license if you re-distribute it. Putting it in a GitHub repo, is ambiguous whether or not it is re-distributing it, at least morally.

If you want to delete the license in a personal copy, that is perfectly valid according to the license terms. If you then happen to upload that to a private GitHub repo, also perfectly valid.

If you then happen to upload that to a public GitHub repo, because of, say, restrictions on free private repos, without intent to distribute, then what?

Re: DOGE worker’s code supports NLRB whistleblower

#489
post #215

Earlier quoted context omitted.

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

That's straight up traitorous. DOGE needs to be shutdown and everyone of them held as a flight risk while the whole thing is investigated.

Not to defend doge at be all, but the article specifically mentioned installing a bunch of proxy and scraping tools. Is this likely to be an actual Russian state attack or just extremely poor opsec / an attempt to evade internal controls, still likely very illegal. I'm all for holding all involved accountable to the fullest extent, but this is too sloppy for Russian state involvement to make me think they're on any intelligence payroll anywhere.

Re: DOGE worker’s code supports NLRB whistleblower

#490

> Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. As it happens, there is a newer version of this project that was derived or “forked” from Ge0rg3’s code — called “async-ip-rotator” — and it was committed to GitHub in January 2025 by DOGE captain Marko Elez. Original code: https://github.com/Ge0rg3/requests-ip-rotator Forked: https://github.com/markoelez/async-ip-rotator Code…

The GitHub part makes it... weird. You are only required to keep the GPL3 license if you re-distribute it. Putting it in a GitHub repo, is ambiguous whether or not it is re-distributing it, at least morally. If you want to delete the license in a personal copy, that is perfectly valid according to the license terms. If you then happen to upload that to a private GitHub repo, also perfectly valid. If you then happen t…

> If you then happen to upload that to a public GitHub repo, because of, say, restrictions on free private repos, without intent to distribute, then what?

Then you keep the license eh? Distributing without an intent to distribute is distributing.

Git is free and open source. If you want version control and collaboration and NO unintended distribution completely for free you can just use Git. It even has a built in server to share with your work buddies.

Post reply on HN