Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

61–70 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#61
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

I'm only really familiar with the 'tenant admin' concept from microsoft administration, it's commonly used otherwise?

Re: DOGE worker’s code supports NLRB whistleblower

#62

>Ge0rg3’s code is “open source,” in that anyone can copy it and reuse it non-commercially. A little nit-picking, but that's not what open source means, especially as it relates to the GPL in this case. If you can't use the code commercially, it's neither "open source" (as defined by OSI) nor free software (as defined by the FSF).

Right, but the original statement isn't being mutually exclusive.

Re: DOGE worker’s code supports NLRB whistleblower

#63
post #9

Earlier quoted context omitted.

[flagged]

> it's fun to watch Watching the misery of others makes me feel ill.

Don’t agree with the OP how it’s fun to watch, but you have to acknowledge how citizens of basically every other country feel after being made fun of for the past few months. I have close relatives living in the states, and I feel bad for them. But your own government has been belittling your neighbours across both of your borders and calling them weak. I’m not going to say that the government does not deserve some of the repercussions of their own actions.

Re: DOGE worker’s code supports NLRB whistleblower

#64
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

I fully believe there's a stack of pardons in Trump's drawer for everyone involved in this debacle. I can't imagine breaking so many laws all over the government if you thought you'd ever have to face consequences. The alternative to pardons in preventing the next congress & administration from cleaning this up is too dire to really contemplate.

Time to remove the pardon powder. Has it achieved anything productive in the last 100 years?

Re: DOGE worker’s code supports NLRB whistleblower

#65

I find the following bizarre. Ignoring who this marko guy is, why would a random person post such a "take down" of the repo? I have never randomly passed by a repo and wanted to just dunk on it. Also this critique reeks of being AI generated. > On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundament…

It's only "bizarre" if you "ignore who this marko guy is." It's not a coincidence, it's somebody pointing out that DOGE's "cracked coders" are wearing no clothes.

Re: DOGE worker’s code supports NLRB whistleblower

#66
post #40
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

> “We have built in roles that auditors can use and have used extensively in the past but would not give the ability to make changes or access subsystems without approval,” he continued. “The suggestion that they use these accounts was not open to discussion.”

From the previous post, they had auditor roles built in that they purposely chose to go around

Re: DOGE worker’s code supports NLRB whistleblower

#67
post #55
post #40

Earlier quoted context omitted.

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

It's the same as domain admin in active directory. You always need it to setup the system initially. It's like root on Linux: it's an implementation detail that it must be possible.

typically the admin account can createthings like super users, and super users can do anything with the data, but not sure there's a use case where a single account can do both, and why can any of them avoid logging?

Re: DOGE worker’s code supports NLRB whistleblower

#68

So what exactly is being alleged here? That these DOGE bros wrote and used “hacker” code from GitHub to bypass security limitations on NLRB data? Why would they even need to do that if they had superuser accounts in the system already?

The article is written very poorly. The disclosure itself is far more readable. https://whistlebloweraid.org/wp-content/uploads/2025/04/2025...

Yes, this is much more clear than the article.

Re: DOGE worker’s code supports NLRB whistleblower

#69

So what exactly is being alleged here? That these DOGE bros wrote and used “hacker” code from GitHub to bypass security limitations on NLRB data? Why would they even need to do that if they had superuser accounts in the system already?

DOGE downloaded libraries to assist in data exfiltration, and did exfiltrate data (obtained via the superuser accounts).

Suggest reading the complaint: https://whistlebloweraid.org/wp-content/uploads/2025/04/2025...

Re: DOGE worker’s code supports NLRB whistleblower

#70
post #55
post #40

Earlier quoted context omitted.

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

It's the same as domain admin in active directory. You always need it to setup the system initially. It's like root on Linux: it's an implementation detail that it must be possible.

Root on Linux isn’t exempt from logging. I also don’t know any enterprise that allows admin accounts to bypass logging.

There is no legitimate justification for this request.

Post reply on HN