This kind of access would be dangerous even in the hands of principled and well-meaning people. Giving it to people with glaring red flags like here is just entirely irresponsible.
This kind of access would be dangerous even in the hands of principled and well-meaning people. Giving it to people with glaring red flags like here is just entirely irresponsible.
These people have administrative access, and at least in some cases network and physical access.
Once you determine they are untrustworthy and potentially malicious, you can't just rebuild the VMs, since you can no longer trust the hypervisor or even the hardware.
If they were Chinese or Mossad agents, you'd start from scratch in a different DC on supply chain audited new compute, storage, and networking hardware. And you'd compile everything from audited source. And I have NFI how you'd deal with potential malicious changes to your data and backups.
The backups should be stored on WORM tape. They can't be altered (easily or at all?). Of course they're probably wiping their asses with the backups like they are the constitution.
The concern is that the tampering has already been committed to the backups. When was the "Break Glass" password last rotated? Is it protected by one or more Yubikeys that were manufactured before they fixed that nasty exploit? What other attack vectors are baked in through malfeasance or human error?
What will happen when PIIs of every individual with dealings with the Treasury gets leaked?
Then there is going to be thousands of hours of meetings to review various processes...
May...
https://www.washingtonpost.com/nation/2025/02/06/elon-musk-d...
We see what happens when big companies leak personal data - almost nothing. Maybe they give you 3 months of 'credit monitoring' or 'identity theft monitoring' service, maybe they write an apology press release. We've seen how Trump presents things, he quite realistically could say either "it was Democrats weak security, we're fixing it" or "hackers must have got it, we'll clean it up" or even "fake news" and then ... do nothing, we never hear about it again and the affected people deal with it as best they can. Why would you expect more than that to happen - a newspaper writes a damning article, lawsuits are filed, the news moves on in 24 hours.
We saw how he reacted to COVID, it wasn't a world class good reaction.
When you reply, don't use the word "bleach" or "UV"
is it because you wanted to say bleach and UV?
edit: "look what UK and denmark did!" is so completely irrelevant that it's ... not "good" faith to suggest it.
Click the link and imagine me asking "Was that because the US is so big? Or because the US has such a large population?" about every point. Including, but not limited to, these:
> May 2018 - The Trump Administration disbands the White House pandemic response team.
> July 2019 The Centers for Disease Control (CDC) epidemiologist embedded in China’s disease control agency left the post, and the Trump Administration eliminated the role.
> June 30-July 6, 2020 The U.S. has just 4% of the global population, ... and the second-highest death rate per capita.
> May 29, 2020 “We will be today terminating our relationship with the World Health Organization”
And these, imagine me asking why Trump is more concerned about the stock market, his image, finding people to blame:
> Feb. 24, 2020 “The Coronavirus is very much under control in the USA… the Stock Market starting to look very good to me!”
> March 20, 2020 [Response to reporter’s question: "What do you say to Americans who are watching you right now who are scared?"] “I say that you're a terrible reporter, that's what I say. I think it's a very nasty question"
> July 28, 2020 "He [Fauci]'s got this high approval rating. So why don't I have a high approval rating with respect -- and the administration -- with respect to the virus?"
> Aug 19, 2020 "We’ve got all the damn cases...I want to do what Mexico does. They don’t give you a test till you get to the emergency room and you’re vomiting,”
> Sept. 10, 2020 "This is nobody's fault but China.”
and:
> May 6, 2020 The Brookings Institution reports that children were “experiencing food insecurity to an extent unprecedented in modern times” and “40.9 percent of mothers with children ages 12 and under reported household food insecurity since the onset of the COVID-19 pandemic.” Republicans block proposals to expand food stamps.
Thanks Obama.
Remember when New York's morgues were overloaded[1] with 800 people dying there every day[1] and they were burying people in mass graves on Hart Island[2]? That was April 2020 when medical advisors were saying people should wear masks and Trump was announcing to the world that he was feeling good and "I think wearing a face mask as I greet presidents, prime ministers, dictators, kings, queens, I don’t know, somehow I don’t see it for myself. I just don’t." and then Trump's fanbase picked them up as "face-panties" for "wimps"? How many lives could he have saved if he just encouraged people to take it seriously and calmly and modelled that behaviour himself?
So let's start with an immediately better response: after being warned it is serious and spreads easily, stop telling the public to ignore it because it will miraculously go away over and over and over again. Tell people to distance, ventilate rooms, as the evidence becomes available
[1] https://www.nytimes.com/2020/04/30/nyregion/coronavirus-nyc-...
[2] https://time.com/5913151/hart-island-covid/
> edit: "look what UK and denmark did!" is so completely irrelevant that it's ... not "good" faith to suggest it.
I didn't suggest it; the UK's handling of it was not good: https://www.ft.com/content/bea342f8-9289-41cb-83ae-1e97c47e3...
> Remember when New York's morgues were overloaded[1] with 800 people dying there every day[1]
I do remember when the public health policy in this country was to intubate people with enfeebled lungs after pumping them full of opiates. I do understand that this is homicide, at least the way i define it.
Will there ever be a reckoning? i don't know. I do know a lot of outright falsehoods were told for 2 years straight. If you'd like a detailed list i'd be glad, but I'm the kind of person that is still mad that Obama joked about killing two kids with predator drones. That Clinton bombed a [medicine factory?] That Bush... both...
If everything is a shambles because of one (or 2) people then the constitution is not worth the paper it's printed on. I bet you could fetch a nice price for that paper. I'd repeat that, but it's easy to just scan back to the beginning and read it again.
I'm not worried. These people are hype-based. I get that people are suffering but people are always suffering and i got no control over that. Me yelling at people or agreeing with people like you doesn't do anything. I guarantee if i wrote an agreement this long, no-one would read it.
HT ID;
What actual facts do you have for anything?
I understand why the media is mad, why NGOs, and why liberal politicians are mad, I get why foreign countries are mad.
I’m interested in fraud and abuse, regardless of who does it. So if Musk’s team finds it, great, if they get caught committing it and have to deal with that, also great.
But right now we know there is something broken. Instead of being mad about that, you are angry about hypotheticals that have not happened.
Why is that?
So you haven't found any insights regarding this?
https://news.ycombinator.com/item?id=43003791
Lots of really good, and as of yet, unanswered questions which shed some light on why/how Musk's claims of "waste" and his method of supposed resolution don't hold up to scrutiny.
It's not up to him to make those decisions, it's up to congress. Musk is just making up bullshit (I'm surprised he didn't say he was rooting out pedophiles) to justify his jihad against the public service.
OK!
If anyone with real experience in that area could chime in. Until now I was under impression COBOL ran it all:P
Only a few years later, he was thrust into the core information systems of the United States right next to people with security clearance.
Targets like this are a dream come true for foreign adversaries looking for someone to corrupt.
Who knows how much compromising content his old peers already have on him. The chat logs revealed they’re already thinking about how much access he has to valuable secrets.
>For this employment have any of the following happened to you in the last seven (7) years?
>Fired, quit after being told you would be fired, left by mutual agreement following charges or allegations of misconduct, left by mutual agreement following notice of unsatisfactory performance.
>Provide the reason for being fired.
As the sibling comment pointed out, this is not to say that doing so is a good idea. But it's very probably legal.
Whether or not ignoring such things is a good idea is something voters must judge.
If anyone gets to judge, however, it will be SCOTUS, not voters. It's hard to guess, right now, whether that's a plus for security.
https://ourpublicservice.org/wp-content/uploads/2018/09/back...
appointees are interviewed, not vetted by the fbi like federal employs. the dowvote brigade could read the article since im rentioning a literal quote from there.
> the dowvote brigade could read the article since im rentioning a literal quote from there.
Alternately, consider that they’re recognizing that the scope of this situation is different both in terms of the level of access and nature of the work and unwillingness to follow policies. For example, when they tried to barge into the SCIF at USAID the staff who tried to stop them were under a legal obligation to do so - they’re charged with requiring everyone who enters to have a clearance. Historically, people got those and so it was never codified into law that they had to. Similarly, if people were requesting the access needed to perform their official task and using agency accounts and equipment to do so, you didn’t need an “auditor” to get approved at the level needed to be a system administrator. This is turning into a big scandal not just because it’s so highly politicized but also because bulling through so many process protections dramatically increases the potential risk.
As a simple example, reports have these guys getting admin access and using personal email accounts and equipment. Consider what happens if someone emails them a PDF saying it has evidence of fraud and it has a nasty payload. If they have unnecessary levels of access or have demanded that restrictions be removed, the fallout for that will be much worse than it would be if they were following the rules. Every federal agency has people employed specifically to prevent all of those layers of failure from happening.
And for appointees that require congressional confirmation the checks have been giving to congress prior to hearings for the same reason.
They weren't required but they very much have been done for political appointees in every admin in recent history except this one.
https://www.vox.com/trump-administration/388627/fbi-backgrou...
"Trump team agrees to DoJ background checks for nominees"
* https://www.theguardian.com/us-news/2024/dec/03/trump-team-b...
"FBI background checks of presidential nominees, explained":
* https://www.npr.org/2025/01/15/nx-s1-5260953/fbi-background-...
This has been the case since Eisenhower in 1953:
* https://www.archives.gov/federal-register/codification/execu...
> much less the system root
This comments section is getting wild. Do you have any proof that DOGE team members have been granted "system root" (whatever that means)? When I Google, it is unclear how many DOGE team members have security clearance and at what level.They are flooding the zone. That's by design. At one point they had "read-only access" to records. Then later people say they had full access and have backups.
The only definitive proof we have publicly Is that a federal judge made two orders; One to restrict access to the treasury for all of DOGE except for the 2 people allegedly already working in treasury. And One to order deletion of any records they have backed up. All other reports come from first or second hand sources. AFAIK, no one truly knows DOGE did in the Treasury, and we won't know until a court proceeding later this month.
Because that seems more both their style.
If these people are scooping up this information you can imagine they might be tempted to monetize or weaponize it at some point, or use the threat of such for their own gain.
This is absolutely chilling when you think about it.
https://www.bloomberg.com/news/articles/2025-01-16/chinese-h... (https://archive.ph/xeEaO) (January 16, 2025)
I always feel like there's a Monty Hall aspect to these discussions where people forget that the past has occurred and it has a bearing on the present. The choice isn't between "observe data protections" and "don't observe data protections." Something was behind door #3.
1) a random citizen murders someone and 2) a cop murders someone on duty?
Yes, ideally the country would be safe enough that no one was killed, and you can even argue that it don't matter because the end result is the same (hell, some people would even argue whoever the police kills had it coming). But most people understand that when those entrusted with special powers for the public good abuse that trust and engage in criminal behavior, it’s a far more serious issue.
Now, of course, if your goal was to create propaganda or to install extra-legal modifications to block payments without having to follow normal processes, you might do this because you’re getting you’ll never have to defend your actions in court. That would be consistent with what we’ve seen of the “fraud” being talked up despite being quickly debunked because most of the people sharing stories don’t care whether it’s true as long as it feels right.
er, not if my role was as a consultant of the parent bank and my assignment was to close branches that were "losing money".
note: i even specified "first party" because in my mind i was envisioning a first party audit, of which i have done many as a consultant.
> I find it strange that neither activists nor politicians nor journalists cared about that enough to make it a continuous news cycle.
Because (a) that was a month ago and that's a long time given recent events. And (b), it's implicit that someone 'inappropriate' having access is a bad thing, but with Trump/Musk/DOGE it's being done on purpose.
It's the purposeful part that's at issue now.
There are people who have reportedly just graduated high school that have root-level access to things:
* https://futurism.com/elon-kids-gutting-opm-doge
Beside being party loyalists, do they have any kind of qualifications?
If you can’t understand that difference, you’re missing something very critical.
One is serious because a foreign adversary is compromising us; the other is serious because we are apparently designing the compromise ourselves via the whims of a demagogue.
You don't need read-write access for auditing. You don't need root/admin-level privileges.
So far the only evidence of that is a wired article [1] with anonymous sources, even those source were not 100% sure about it.
Since then wired has posted another article [2] claiming the access have been revoked after announcements from senior officials, which again is from anonymous sources.
I'm really skeptical of these anonymous sources tbh.
[1] https://www.wired.com/story/elon-musk-associate-bfs-federal-...
[2] https://www.wired.com/story/treasury-department-doge-marko-e...
I'm surprised you didn't throw in jabs like "racist misogynistic eugenicist" like some reports...
https://www.smithsonianmag.com/smart-news/this-21-year-old-u...
Did the ancient scrolls involved accounting ledgers? Because some kind of auditing experience would be useful to figure out how where Treasury or USAid payments went.
To be clear: I am not here to defend companies with weak cybersecurity, but the impact of these leaks is virtually nil. "One hundred million" sounds like a huge number, but it provides little insight on the realised impacts.
because they made a public show of it. That's the big difference. Meanwhile, Healhcare is already under more scutiny than ever and want to bury a lede of hacking.
Why don’t you just state your opinion instead of being vague?
No not strange, because Elon etc. will cause more damage to their corrupt careers than other security breaches.
Say what you will, but Musk has a track record of executing well at preposterous speed, so for legacy players/media this sorta of PR campaign is about the most they can muster.
At the end of the day thought, we'll all have to compare real word results versus those PR narratives and I am positive i know which way that will swing. You just can't PR bullshit you way out something like a 250ton piece of stainless sticking a landing.
I highly disagree, and these stories makes his incompetence more obvious. As well as proving various anecdoctes years ago from SpaceX/Tesla that Musk was someone you needed to work around, not with.
He has been promising Tesla full auto-pilot every year for about 9 years. Just around the corner he said. I even shelled out $10K for it on top of the price of my car, 6 years ago. He said the car would pick up the owner from the airport. That was about 5 years ago.
Musk says a lot and promises a lot. A lot of it never materializes. And he seems be going insane at a rapid pace as of late. I have been wondering if the ketamine that he says he has been taking is really turning his brain into mush.
So that data is (a) publicly available if you don't secure your VPC properly and (b) available to anyone without RBAC or request logging. This is an extraordinary degradation of the level of private and security controls.
[1] https://www.firstpost.com/tech/elon-musks-team-at-doge-feedi...
We know there's a limit of tolerance for this because Matt Gaetz didn't make it through. But "modern day Tony Stark" was fine.
This is about a specific person who has a history of bad behavior, not a generic discussion on the abilities of young people.
If you know more than someone else, two good options are (1) to share some of what you know, so we all can learn; or (2) not post. Snarky putdowns are not a good option.
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
> Light SQL skills tend to be the upper end of technical accounting
This would be the main point that would need correction if I am wrong.
Before DOGE, somebody obviously had to have this access as well, and similarly could have copied and stored. Why be concerned with DOGE but not their predecessors? Honest question.
Federal IT has tons of policies designed to prevent unauthorized access and mistakes. People go through background checks, they only work on secured networks using official devices, everything is logged and audited, and circumventing it is a crime with penalties potentially leading to jail time. Some of those policies have strong legal requirements for oversight: even if you’re not doing anything other than your job, the agency needs to be able to show how work is done to auditors, Congress, FOIA requests, etc. Anything with national security implications should be designed to avoid a single compromised person from being able to avoid detection, too, especially for people trusted with administrative access to IT systems.
These guys are widely reported to be using personal emails and devices (violating the record and transparency laws) and even if they’re acting entirely in good faith they are bypassing policies designed to contain the damage due to mistakes. For example, what happens if one of them gets an email with an attachment claiming to have evidence of politically incorrect activities and runs the payload on a device/network which has had safeguards removed by executive fiat?
My point is that there is plenty to dislike here, but if your argument against him is: he is a nazi, you have already lost, because you do not understand the sentiment out there.
Is one of the issues that an audit log of actions was created? Because it seems to me some of the levels of access given to the DOGE folks mean that auditing and traceability has now gone out the window like a Russian oligarch.
I'm a sysadmin who 'just' runs a bunch of HPC stuff—nothing 'important' like HIPAA or SOX—and even my systems have some level of auditing and logging.
This is basically my point and that point is the same point I make for Zuck, Thiel and others. There is already plenty of real things to complain about.
How about we focus on those?
The argument from the DOGE side is that entrenched interests are operating opaque systems and gating access to the information needed to identify inefficiencies. It's not a bad argument because it's no secret that you end up with waste in big companies or government programs and everyone should want to improve efficiency.
However, it's a bad faith argument because the public's being told they're being disenfranchised by a lack of transparency at the same time they're being told to accept a solution that has no transparency or oversight.
When you have tech billionaires with a lifelong goal of controlling payments since starting PayPal in the 90s, is it unreasonable to be skeptical of their motivations when they've managed to gain access to the government's payment system? Aren't these the same people sucking up our private information and telling us if we've got nothing to hide we've got nothing to fear? Why do they need to operate in the shadows?
<< is it unreasonable to be skeptical of their motivations when they've managed to gain access to the government's payment system? Aren't these the same people sucking up our private information and telling us if we've got nothing to hide we've got nothing to fear? Why do they need to operate in the shadows?
I don't want to argue for DOGE, because their fanbase is doing it on various fora already ( including this one ).
But to answer your question, it is not unreasonable at all. Those questions should be asked and, ideally, answered.
It is vital that the government officials are watched, their performance evaluated and our political will enforced by means we deem necessary. From where I sit, what is good for goose, is good for gander.
If I hesitate, it is around the level of emotion this generates. Some of it is warranted ( I would lie if I said I am not concerned ), but it does not help with making an appropriate response. In fact, that level of emotion actively inhibits making good choices.
You have to give it to him. It does look like Trump actually had a plan this time around.
As for the oversight requirement, it is fully and completely satisfied by: 1.) A guy who has the technical acumen, drive, and attention to detail to catch a rocket out of mid air with chopsticks. 2.) A man who won a presidential election twice (and could possibly have been 3 times if the Hunter Biden laptop story wasn't corruptly and improperly squashed).
The largest proportion of the complaints from media outlets come from defunded operations. Its in everyone's fiscal best interest for these audits to continue, and for them to be completed by people completely outside of the government's patronage (grant and funding) networks.
Every dime that the USAID spent was allocated via Congress through the budgeting process.
And many (11/12) of the published stories about supposed wasteful spending were not true:
* https://www.washingtonpost.com/politics/2025/02/07/usaid-tru...
More importantly, even if sending money to USAid is wasteful, that is Congress's prerogative. The President's job is to "take Care that the Laws be faithfully executed": if Congress wants to spend money on Foo then that's what he is supposed to do.
A thread on the general process:
> Every year, the White House (via OMB) puts together a federal budget proposal to Congress. Every federal agency (incl USAID) sends OMB their budget wishlist.
[…]
> So to be clear: every dollar that USAID requests from Congress goes through White House review.
[…]
> Once USAID gets its budget from Congress, it must go straight back to Congress again with a further level of detail on how it will satisfy the various budget directives - via "Congressional Notifications."
* https://twitter.com/JeremyKonyndyk/status/188866737886876071...
" “$32,000 for a ‘transgender comic book’ in Peru”
This is wrong. USAID did not fund this, and it was not specifically transgender. Instead, the grant says the State Department provided $32,000, under the guise of public diplomacy, to Peru’s Education Department “to cover expenses to produce a tailored-made comic, featured an LGBTQ+ hero to address social and mental health issues.” "
So the comic existed, but it was funded by another equally corrupt department? This doesn't make USAID look any better at all, it just means Trump and Elon's team need to do MORE of what they have been doing, and expand their scope further.
I don't really care that a 2500 page omnibus spending bill that no one could read in full (minus an AI) specifically said that some pork goes to some unethical and corrupt action. Its evil and it needs to stop. If the government's normal checks and balances cant fix it, the answer is not to give up and let corrupt liberals desecrate the union. The answer is to fulfill the promise of the 2nd Amendment and to break the system of government in whatever way is necessary until it is no longer tyrannical. Remember that a 2% tax on tea without sufficient and effective representation is an acceptable threshold for such actions.