6 ms·
this part of the whistleblower complaint seem way worse: " On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior week. I saw
by mythrowaway49 1y ago
this part of the whistleblower complaint seem way worse:
"
On or about March 11, 2025, NxGen metrics indicated abnormal usage at points the prior
week. I saw way above baseline response times, and resource utilization showed increased
network output above anywhere it had been historically – as far back as I could look. I noted that
this lined up closely with the data out event. I also notice increased logins blocked by access
policy due to those log-ins being out of the country. For example: In the days after DOGE
accessed NLRB’s systems, we noticed a user with an IP address in Primorskiy Krai, Russia
started trying to log in. Those attempts were blocked, but they were especially alarming.
Whoever was attempting to log in was using one of the newly created accounts that were used in
the other DOGE related activities and it appeared they had the correct username and password
due to the authentication flow only stopping them due to our no-out-of-country logins policy
activating. There were more than 20 such attempts, and what is particularly concerning is that
many of these login attempts occurred within 15 minutes of the accounts being created by DOGE
engineers.
"
- superconduct123 1y agoWow that's insane
- kazinator 1y agoThe article could offer a summary of this key finding, rather than, say, the pointless paragraph near the bottom about the scraping software found in GitHub not being well written. This is the evidence which strongly suggests that the DOGE personnel are using various cloud IP addresses to scrape.
- stevenwoo 1y agoAny guesses for best possible interpretion? The Russians have infiltrated their PCs with keyloggers and DOGE are working from insecure open networks. The worst possible interpretation is straightforward - they are working for the Russians as agents and let the Russians in or installed the keyloggers for Russia.
- 0cf8612b2e1e 1y agoI would have thought that a Russian state sponsored attack would trivially mask the IP to originate from within the USA. This is just brazen.
- avs733 1y agoSometimes getting caught isn’t a bad thing. If you are trying to seed division between to groups, acting in a way that divides them - e.g., getting caught helping one side - is more effective than what you gain by not getting caught. I struggle to see what Russia would gain with nlrb data, but getting caught “helping doge” furthers distrust between the two sides of our country - which is something they gain from
- Braxton1980 1y agoWhy would the Russians do this when Trump won the election. Isn't that the best outcome for them related to Ukraine? >furthers distrust between the two sides of our country - which is something they gain from How?
- avs733 1y agoThe best outcome for them and other potential powerful forces is an America so roiled by internal conflict that it can’t now or ever do anything. Yeah Trump winning seems to help them in Ukraine but their need is disruption as much as different policy in the longer term.
- Braxton1980 1y agoWhile I'm just guessing I'd think it would be better to wait until Ukraine is done and trump is out of office. Creating mistrust in Doge only helps Democrats
- deleted 1y ago[deleted]
- bequanna 1y agoThis just seems odd. Why would they attempt a login from Russia (if it was indeed Russians)? It is incredibly cheap to use a VPN with a US residential IP.
- Pompidou 1y agoMaybe not everyone involved is quite the genius you might've been expecting.
- frumplestlatz 1y agoOccam’s razor would also suggest a hoax as one of several very credible possibilities.
- threeseed 1y agoOccam's razor would suggest someone from Russia could just use their own IP because people like you would think it's a hoax anyway.
- frumplestlatz 1y agoWhy does someone from Russia want access to NLRB data, and why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets when it would be trivially traceable back to them, and if they were in fact granted untraceable/unlogged admin credentials, could legitimately download the data themselves and simply hand it over to said Russian assets if that was their actual intention? It's not behavior that makes any sense assuming even a semi-rational/intelligent actor.
- threeseed 1y ago> Why does someone from Russia want access to NLRB data It has details of labor disputes. Which if you’re Russia who thrives on fostering conflict in the US would be an ideal data set. > Why would DOGE be immediately leaking just-granted NLRB login credentials to Russian assets Because they are young, highly inexperienced engineers who have been tasked with rolling out their LLM system as quickly as possible. Their priority is not security.
- Palmik 1y agoI wonder why the "no-out-of-country logins" block happens after verifying login credentials and not before, which would make more sense to me.
- antongribok 1y agoBecause you need to know who is logging in before you know what IP policy to enforce, no?
- mcoliver 1y agoBecause then you know that credentials have been compromised
- jabiko 1y agoSince the system is hosted on Azure, I guess we are talking about an Entra ID login. So I think they set up a Conditional Access [1] that can blocks logins based on the country IP. These policies run after authentication and can be specific to a user. [1] https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-assignment-network https://learn.microsoft.com/en-us/entra/identity/conditional...
- sReinwald 1y agoWhile blocking before authentication seems intuitive for efficiency, checking after provides crucial context that's missing if you block pre-auth: you know which specific user account just authenticated successfully. This context enables two important things: - Granular exceptions: If Alice is attending a conference in Toronto, you can say "Allow Alice to log in from Canada next week" without opening Canada-wide logins for everyone. Pre-auth geo-blocking forces you into an all-or-nothing stance. - Better threat intelligence: A valid login from an unexpected region (e.g. Moscow when Alice is normally in D.C.) is a far stronger signal of compromise than a failed attempt. Capturing "successful login + wrong location" helps you prioritize real threats. If you block pre-auth, you'd never know Alice's account was compromised. Putting geo-checks after authentication gives you precise control over whom, exactly, is logging in from where, and offers richer data for your security monitoring.
- orbital-decay 1y ago>Primorskiy Krai Probably the least expected location to connect from, if it was genuine. Not saying it necessarily isn't, but it's not usual either and doesn't make much sense.
- mananaysiempre 1y agoRight?.. Primorskiy Krai, official population 1.8M, of which the largest city of Vladivostok accounts for 600k and the next three largest cities for about 400k more, and the rest of the settlements are below 50k inhabitants each. China (Heilongjiang) to the west, North Korea to the south, Japan (Hokkaido) to the east. Literally six times closer to Tokyo than to Moscow (and only a bit closer to Moscow than to Vancouver), connected to Moscow by the longest train route in the world (six to seven days). A reputation for fierce independence and old Japanese left-hand-drive cars. That Primorskiy Krai.