The Government's Computing Experts Say They Are Terrified
theatlantic.com
theatlantic.com
----
"I'm not sure that is accurate, and I just don't have -- I'm not, I just don't have the information necessarily," Humphreys responded.
Which is the most basic question that any audit(or) will ask and that needs to be answerable for any security certification. If you don't know who has access to your system, or how it has been (potentially) changed, how can you be sure it's still your system?
You assume it is compromised the moment they gain access.
See "A US Treasury Threat Intelligence Analysis Designates DOGE Staff as ‘Insider Threat’":
* https://www.wired.com/story/treasury-bfs-doge-insider-threat...
And "Treasury was warned DOGE access to payments marked an ‘insider threat’":
* https://www.washingtonpost.com/national-security/2025/02/07/...
* https://archive.is/https://www.washingtonpost.com/national-s...
And then he brings in a bunch of "old associates" who run around demanding all the master passwords, 2FA recovery codes, and even access to change the audit logs... or else you'll be fired.
Meanwhile, some others are gleefully talking about how their superior fresh outsider perspective will allow them to seamlessly replace That Big Old System that nobody likes but which if it vanishes the company can't serve customers or can't pay bills or gets lawsuit'ed into oblivion.
> The contractor emphasized that nobody yet knows which information DOGE has access to, or what it plans to do with it.
The most-charitable I can possibly go on this is that it will be Twitter all over again [0]: They will cherry-pick records, leak access to hand-picked pieces, and lie they've found the Loch Ness Monster of Somebody Else Being Bad, trusting that not enough people will have the inclination/access/time to check before it becomes "a fact" in supporters' minds.
[0] https://www.techdirt.com/2025/02/03/the-twitter-files-playbo...