Live data from Hacker News

DOGE worker’s code supports NLRB whistleblower

krebsonsecurity.com

81–90 of 586 posts

Re: DOGE worker’s code supports NLRB whistleblower

#81

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

Absolute balderdash.

Re: DOGE worker’s code supports NLRB whistleblower

#82

This is much ado about nothing. The article tries to very hard to make something ordinary sound nefarious. This appears to be DOGE employees simply doing their job. You may not agree with what they’re doing in a political sense, but if you were tasked with the same problem you’d come up with a nearly identical solution. For example: “tenant admin” is probably the special role that can bypass access control (not audit…

In that case, you and departments you work for are either breaking the law regularly or working with public data anyway.

Besides, no one needs unmonitored write access for audit. Even less DOGE who does no audit and don't have knowledge how to do audit. Audits are supposed to he traceable.

Re: DOGE worker’s code supports NLRB whistleblower

#84
post #70
post #55

Earlier quoted context omitted.

It's the same as domain admin in active directory. You always need it to setup the system initially. It's like root on Linux: it's an implementation detail that it must be possible.

Root on Linux isn’t exempt from logging. I also don’t know any enterprise that allows admin accounts to bypass logging. There is no legitimate justification for this request.

root on Linux can just kill the log forwarder and erase the relevant logs, or refill them with junk.

Re: DOGE worker’s code supports NLRB whistleblower

#85

Earlier quoted context omitted.

I fully believe there's a stack of pardons in Trump's drawer for everyone involved in this debacle. I can't imagine breaking so many laws all over the government if you thought you'd ever have to face consequences. The alternative to pardons in preventing the next congress & administration from cleaning this up is too dire to really contemplate.

They are betting the system won't go after them later which is a very bad bet if they eventually give back the executive branch and an even worse bet if the power they support never gives it back. About as brilliant as being in a photo with Stalin.

Trump can wait until the last day in office then issue pardons for any possible crimes, right? Biden did something similar I believe

Re: DOGE worker’s code supports NLRB whistleblower

#86
post #75
post #8

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts. Feels like a pretty good Occa…

[flagged]

I don't think that "arguing that something is against the rules" is in the CIA sabotage manual, because it's not generally considered sabotage. Maybe if you argue things are against the rules that you know aren't, to slow things down?

Re: DOGE worker’s code supports NLRB whistleblower

#87

Earlier quoted context omitted.

I fully believe there's a stack of pardons in Trump's drawer for everyone involved in this debacle. I can't imagine breaking so many laws all over the government if you thought you'd ever have to face consequences. The alternative to pardons in preventing the next congress & administration from cleaning this up is too dire to really contemplate.

Time to remove the pardon powder. Has it achieved anything productive in the last 100 years?

it's written into the Constitution very explicitly. and it's a really bad time to hold a Constitutional Convention.

Re: DOGE worker’s code supports NLRB whistleblower

#88
post #55
post #40

Earlier quoted context omitted.

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

It's the same as domain admin in active directory. You always need it to setup the system initially. It's like root on Linux: it's an implementation detail that it must be possible.

There’s no possible need for an admin-level user that bypasses logging. If anything these users should have additional logging to external systems to make it harder to hide their use.

Re: DOGE worker’s code supports NLRB whistleblower

#89

I find the following bizarre. Ignoring who this marko guy is, why would a random person post such a "take down" of the repo? I have never randomly passed by a repo and wanted to just dunk on it. Also this critique reeks of being AI generated. > On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundament…

Why wonder? The user who wrote it seems to be a pretty well established user, and their public repositories suggest that they work in adjacent contexts, so it's entirely plausible they attempted to use async-ip-rotator in one of their projects.

It's also worth noting that Feb 6 may very well be after Marko Elez became a public figure with DOGE. The article doesn't do a great job of expanding on any of this.

Re: DOGE worker’s code supports NLRB whistleblower

#90

Earlier quoted context omitted.

Sensitive government data was (sure, allegedly) extracted to Russia via an account that was expressly created to hide / not create logs. This is treason. Allegedly.

This administration is doing a lot of things that are borderline treasonous. Hopefully they get prosecuted when they get voted out or ideally get removed form power.

Trump will blanket-pardon anyone who's still on his good side. And maybe some who aren't, just to limit the reach of investigations. And Trump himself's untouchable—while it remains technically possible to criminally prosecute a President for actions in office, it's in-practice impossible short of some unlikely hypothetical scenarios, thanks to the Supreme Court (the Roberts court loves leaving things technically intact, but actually not)
Post reply on HN