11 ms·
DOGE engineer's credentials found in past public leaks from info-stealer malware
- chneu 1y ago[flagged]
- soco 1y agoLeaked? Maybe they even "leaked" it willingly, to prove their grip, their superiority, you name it.
- deleted 1y ago[deleted]
- ndsipa_pomu 1y agoDoes the USA have an authority that can deny privileged data access to someone that has such poor operational security? Revoke security clearances, that kind of thing.
- actionfromafar 1y agoThe DOGE staff have no security clearance to revoke, as far as I can tell.
- zombot 1y agoHow come they get to fumble and botch everything then?
- actionfromafar 1y agoReason: Congress has decided to not to ask that question of the Presidents Office.
- watwut 1y agoWhy so abstract? It is because republicans in the Congress are supporting Trump policies. They are doing nothing, because they want this to happen.
- blitzar 1y agoWhy don't people rise up against dictators in other parts of the world?
- redeux 1y agoThey always do - eventually
- anonymars 1y agoI think the point was to refute "they are doing nothing therefore they want this to happen" Related: https://www.newsweek.com/lisa-murkowski-donald-trump-retaliation-republican-2061115 https://www.newsweek.com/lisa-murkowski-donald-trump-retalia...
- lesuorac 1y agoI mean if so many of them are scared they can just caucus with the nearly (but not actually) 50% of congress members that are democrats [1]. It's really just republicans are only unified in presenting a unified front so when it comes to actually doing something like electing a speaker [2] [3] the lack of alignment becomes obvious. So they aren't doing anything to counteract trump because they aren't as a whole unified in that it's something they want but they're unified in not fracturing and helping democrats. [1]: https://en.wikipedia.org/wiki/United_States_Congress https://en.wikipedia.org/wiki/United_States_Congress [2]: https://en.wikipedia.org/wiki/January_2023_Speaker_of_the_United_States_House_of_Representatives_election https://en.wikipedia.org/wiki/January_2023_Speaker_of_the_Un... [3]: https://en.wikipedia.org/wiki/October_2023_Speaker_of_the_United_States_House_of_Representatives_election https://en.wikipedia.org/wiki/October_2023_Speaker_of_the_Un...
- withinboredom 1y agoSecurity levels of documents and clearances are technically controlled by the office of the President (IIRC), but this is often delegated to the agencies themselves. The military, for example, has it's own system for classified things, while it looks like maybe DOGE does not.
- vntok 1y agoIf the story is published on arstechnica, be assured the relevant agencies are obviously well aware. They are choosing not to act.
- thot_experiment 1y agoYes in theory, however it's 2025 and I think it's likely that most of what they're doing falls afoul of data storage/recordkeeping laws anyway and there's basically zero chance that the perpetrators will face consequences.
- raverbashing 1y agoWho needs authority when you have ~vibes~
- arp242 1y agoIn principle? Perhaps. De-facto? Not as long as they're performing Trumpllatio.
- dragonwriter 1y agoYes, but all such authorities are subordinate to the President, and the President can issue security clearance by fiat, bypassing normal procedures and exempting people from them .
- marak830 1y agoWell that's something that should be looked into.
- Spackonewz 1y ago[dead]
- withinboredom 1y agoThat's how it is -- by design.
- bregma 1y agoThat kind of punishment is currently only considered appropriate for perpetrators of lese majeste.
- dev_l1x_be 1y ago> a strong indication that devices belonging to him have been hacked in recent years. I like these kind of speculative articles. The click bait title states something with certanity than the first sentence clarifies that it is a speculation. I am not sure why we are falling for this click baity garbage, over and over.
- worldsayshi 1y ago> I am not sure why we are falling for this click baity garbage, over and over. Because it's easier to create and broadcast bait than to filter it.
- bmacho 1y agoUntil HN improves, I propose that we flag moronic titles (misleading, clickbait, just annoyingly moronic, and so on). In the long term HN should do something about it, e.g. editoralized titles.
- gchamonlive 1y agoThis is something that already happens. When there is a strong general opinion questioning the quality of the title, even if it's the same as the original title, if it's against HN directives they do get changed. Unfortunately I don't remember exactly these cases, but if you've been to HN long enough you've surely seen these changes.
- tomhow 1y agoI've updated the title to something less sensationalist and more representative of the article's content. HN does have a policy of using the original title from the submitted article, unless it is misleading or linkbait, and we try to be rigorous in enforcing it. Users can help us by emailing us (hn@ycombinator.com) when they see a case where a title seems to be misleading or linkbait.
- aweiher 1y agoThe first sentence is actually: > Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware Does not sound like clickbait for me.
- whacko_quacko 1y agoI don't see any evidence that this should be the case. My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? Actually critisizing DOGE for their major gaffes (like putting up easily defaceable websites, or their incompetence when it comes to reading numbers accurately) is important, but this kind of article is just sad and diminishes the credibility of news journalism
- alxlaz 1y ago> My email appears in dumps on haveibeenpwnd too, because of database dumps. How is that evidence that there's a key logger on my system? If your password is in the dumps, too, like this person's passwords, then yeah, you might want to look into it.
- buckle8017 1y agoMany website still store plaintext passwords. Indeed the ones getting hacked are more likely to.
- alxlaz 1y agoFrom the linked article: > user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. So this isn't from website dumps with plaintext passwords.
- trollbridge 1y agoIf I did highly secure work (which I don’t), I’d set up a few honeypot machines and input my “secure credentials” (with a bogus password) into that repeatedly.
- alxlaz 1y agoYeah, inputing "secure credentials" traceable directly to you with what you'd hope is a bogus password is a very bad idea, especially if you're doing highly secure work.
- hereme888 1y ago[flagged]
- joejoo 1y agoNow imagine how many normie, computer-illiterate federal employees in fairly sensitive roles have had various credentials leaked over the past few years.
- calgoo 1y agoThere are safe guards for information not to leak. Those safe guards make it very hard to get the info, not impossible, but very hard. Walking into a government office and plugging in your personal Macbook, and running whatever software you want with "god" powers on the network makes it a lot easier to gain access to whatever data is required. Even if its unintentional (big if) from the DOGE's side, at this level you are target by state actors and they will get to your personal devices if they want.
- SkipperCat 1y agoI worked in Federal government on classified systems. There were many safeguards in place, most importantly networks that were 100% disconnected from the Internet and locked down workstations. That made sure that even the most inept user could not cause a problem like this. Everyone I worked with respected OpSec and would never do something as risky as bring in an outside laptop and connect it to the network. DOGE has been so reckless that I believe they wanted to have the system hacked, because seeing our government destroyed is their real objective.
- GuinansEyebrows 1y agoimagine holding nominally-technical staff to a higher level of information security practice
- epanchin 1y agoThis article is reaching. I’ve logged onto secondary email accounts from PC’s that weren’t mine and could well have been infected. That’s what 2FA is for. I wouldn’t use a PC which isn’t mine to login to anything sensitive. A password in a leak isn’t evidence of anything.
- piva00 1y agoDid you find stealer logs with your credentials though? Because that is certainly much more concerning than simply having your credentials leaked from some breach, and it's what happened to the DOGE guy.
- florbnit 1y ago> A password in a leak isn’t evidence of anything. It’s evidence that your password leaked. What are you on about? You think they just randomly guessed his password?
- amelius 1y ago> “At this point it's difficult not to suspect their awful 0pSec is a choice, and that there are specific people (ahem cough cough the Russians cough) to whom they're leaking secrets, with incompetence being merely plausible deniability for their true, treasonous agenda,” one critic wrote on Mastodon. Good point.
- kurtis_reed 1y agoHanlon's razor
- fspoettel 1y agoI would normally second this, but the Trump admin did order a suspension of offensive cyber operations against Russia in March. So not sure you can truly rule out malice in this case.
- sorcerer-mar 1y agoAnd also asked Russian intelligence services to hack his opponent in 2016, which they did the next day.
- conartist6 1y agoyou could not make this shit up, right!?
- SauciestGNU 1y agoThere was specifically the televised "Russia, if you're listening..." quip followed by the release of the DNC emails.
- TrapLord_Rhodo 1y ago>a suspension of offensive cyber operations against Russia in March. uhhh... why are we commiting offensive cyber operations against a nuclear power? Somewhere in your line you seems to think that it's justified? And that biden was doing the right thing by provoking a major power? Some people just want the world to burn, and when someone puts out the fire, they think that's unamerican?
- palata 1y agoSeems like people here assume that passwords were found on Have I Been Pwned. It's more than that, it's about "stealer malware": > [...] user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware. Stealer malware typically infects devices through trojanized apps, phishing, or software exploits.
- philipwhiuk 1y agoIt's not 'assume', it's literally in the text: > Lee went on to say that credentials belonging to a Gmail account known to belong to Schutt have appeared in 51 data breaches and five pastes tracked by breach notification service Have I Been Pwned. Among the breaches that supplied the credentials is one from 2013 that pilfered password data for 3 million Adobe account holders, one in a 2016 breach that stole credentials for 164 million LinkedIn users, a 2020 breach affecting 167 million users of Gravatar, and a breach last year of the conservative news site The Post Millennial. Putting this in undermines the quality of their critique.
- palata 1y ago> Putting this in undermines the quality of their critique. I don't disagree, but the reader may show critical thinking and consider that there is more: there is mention of malware, not just a leak.
- gitroom 1y agoHonestly, stuff like this always makes me double check my own passwords and habits. Bunch of people just roll with the same easy setup for years and act surprised later. Gotta be careful, for real.
- jxjnskkzxxhx 1y agoI've rolled with the same set up for years, what should I be doing instead?
- vntok 1y agoIf your setup includes a password manager, generated unique passwords and enabling 2FA everywhere you can, there's not much else to do. Just use a unique complex root password for your password manager and check semi-regularly that it hasn't leaked on haveibeenpwnd. Bonus points if your password manager automatically checks your stored passwords for leaks and scores them (eg. LastPass)
- jxjnskkzxxhx 1y agoI happen to think that having your password manager online is a mistake.
- mdaniel 1y agoFor your consideration, one does not need to have their password manager online to use HIBP; they offer [at least] two different concessions to your concerns: - SHA1 or NTLM hash prefix matching https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByRange https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByR... - actually download the HIBP db and check for yourself https://haveibeenpwned.com/API/v3#PwnedPasswordsDownload https://haveibeenpwned.com/API/v3#PwnedPasswordsDownload Thus you could hash your passwords in your airgapped setup, transfer the hashes using a mechanism you trust to an Internet connected device, and then check the hashes
- GaryNumanVevo 1y ago
- tjpnz 1y agoUnder normal circumstances if that system were connected to an internal network there would be a cleanup (and the costs would be astronomical). I say normal circumstances because I fully expect these clowns to obfuscate, omit and deny everything for the next four years.
- sys_64738 1y agoAll thee DOGE dudes are destined to spend life imprisoned on Alcatraz. The scope of the antics done by these people and the downright disregard for security, ethics, law, and the Constitution, all make them the right people to make examples of.
- lesuorac 1y agoAlcatraz is a tourist attraction so while perhaps not somewhere I'd choose to live it also has routine ferries that you can just leave on.
- dpkirchner 1y agoTheir boss is talking about reopening Alcatraz. I suspect that's what sys_64738 is referencing.
- Incipient 1y agoHaha noice. I don't think anyone really needs to express more at this point.
- TrapLord_Rhodo 1y ago[flagged]
- mystified5016 1y agoThey're saving the government lots of money by streamlining the data exfiltration.
- ChrisArchitect 1y agoSource: DOGEs K Schutt's computer infected by malware, credentials found in stealer logs https://news.ycombinator.com/item?id=43930267 https://news.ycombinator.com/item?id=43930267
- constantcrying 1y agoThe article title suggests that this is about his current PC which he is using at the agency. That is totally false. In fact the story is that at someone point in the past at least in 2013 some credentials of his landed in multiple breaches. Some of my credentials also appear there, this of course means nothing at all about his current account security or the security of the data. I don't even know what the allegations are. Can you not ever work for a government agency when any account of yours gets compromised? Databreaches aren't that uncommon, presumably many people here have some credentials leaked, do you think these people should be excluded from working jobs in the government?
- ninalanyon 1y agoWas he using his own computer? He should surely have been using one provided by the institution. In a properly secured system he should not have needed passwords to connect to databases, they should have been secured by something like Active Directory roles and certificates. Do any of these US institutions have any idea of proper security?
- EasyMark 1y agoDOGE didn't care to go through proper channels for anything. They just used whatever they had. It was a true train wreck let by young talentless types like "big balz" or whatever his name was; their only qualifying talent was complete loyalty to Elon Musk.
- waltercool 1y ago[dead]
- guiambros 1y agoGarbage clickbait article. Buried down the text, they have the plausible deniability disclaimer: "As Lee notes, the presence of an individual’s credentials in such logs isn’t automatically an indication that the individual himself was compromised or used a weak password. In many cases, such data is exposed through database compromises that hit the service provider. The steady stream of published credentials for Schutt, however, is a clear indication that the credentials he has used over a decade or more have been publicly known at various points." Of course "credentials have been exposed": the vast majority of sites have been hacked. It doesn't mean this person used the same credentials everywhere, AND that they didn't use 2FA, AND that the credentials matter in the first place. And, of course, this has absolutely nothing to do with malware. Shame on you ARS for publishing purely speculative posts.