Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

71–80 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#71
post #40
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

No. Never. While it’s expected to have a “root” account exempting from logging serves no honest purpose.

Re: DOGE worker’s code supports NLRB whistleblower

#72
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

I fully believe there's a stack of pardons in Trump's drawer for everyone involved in this debacle. I can't imagine breaking so many laws all over the government if you thought you'd ever have to face consequences. The alternative to pardons in preventing the next congress & administration from cleaning this up is too dire to really contemplate.

They are betting the system won't go after them later which is a very bad bet if they eventually give back the executive branch and an even worse bet if the power they support never gives it back. About as brilliant as being in a photo with Stalin.

Re: DOGE worker’s code supports NLRB whistleblower

#73
post #3

Someone needs to go to prison over this. It’s not just a misunderstanding, it is an intentional attack on every US citizen.

The people who need to see/understand this live in a different reality where uncomfortable things like this are ETL'd into righteous anger towards people they don't like. This is the deep state they've been worried about, this is the boot that will tread on them. EDIT: parent comment was highest ranked comment for the article and is now at the bottom?

A twisted justification for suggesting someone who broke serious laws not face consequences.

We live in a nation of laws, whether or not conspiracy-minded individuals prefer to follow them.

Re: DOGE worker’s code supports NLRB whistleblower

#75
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

[flagged]

Re: DOGE worker’s code supports NLRB whistleblower

#78
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

I can’t think of any. Even if you wanted to give someone broad permissions to access and modify data, you wouldn't turn off the audit logs.

Re: DOGE worker’s code supports NLRB whistleblower

#79

So what exactly is being alleged here? That these DOGE bros wrote and used “hacker” code from GitHub to bypass security limitations on NLRB data? Why would they even need to do that if they had superuser accounts in the system already?

The article is written very poorly. The disclosure itself is far more readable. https://whistlebloweraid.org/wp-content/uploads/2025/04/2025...

Thanks. So the tools downloaded from GitHub were allegedly used to scrape personally-identifiable information (PII), details about ongoing legal cases, union-related data, and corporate secrets. The whistleblower observed large spikes in outbound data traffic, suggesting that gigabytes of sensitive information were exfiltrated with logging disabled, so as not to leave a trail.

Re: DOGE worker’s code supports NLRB whistleblower

#80
post #73

Earlier quoted context omitted.

The people who need to see/understand this live in a different reality where uncomfortable things like this are ETL'd into righteous anger towards people they don't like. This is the deep state they've been worried about, this is the boot that will tread on them. EDIT: parent comment was highest ranked comment for the article and is now at the bottom?

A twisted justification for suggesting someone who broke serious laws not face consequences. We live in a nation of laws, whether or not conspiracy-minded individuals prefer to follow them.

We live in a nation of peers before we live in a nation of laws.
Post reply on HN