DOGE Is Hacking America
foreignpolicy.com
foreignpolicy.com
There is actually an information security story happening in DC, it’s not just all partisan politics!
I guess it's the opposite opinions that are no longer welcome on HN?
From 20,000ft it feels like a social engineering attack over a wall "because I said so" high.
Was there no M of N process step required? Are the barriers around data in government unenforceable, based on personal restraint only?
Or did they e.g. toss old boxes through single user, not require approval, use root privileges to reset a password or two then reboot into multi user and own an sql binding, or some other asinine approach?
This isn't asking right or wrong, it's asking what the human procedural steps were to doing this.
"The president said so" stamp on a sheet of paper?
when I was a data analyst, I rarely connected to live production DB to do Exploratory data analysis (this is what DOGE is doing). Because running OLAP queries on live OLTP system is problematic.
But having my own instance of DB with a restored backup of data was more than enough for analysis:
1. I could modify schema, create indexes to speed up my queries
2. Could create materialized view to join bunch of dimension tables
3. Could create temp tables for intermediary analysis steps, sumamries, etc etc.
If I were DOGE, I would just ask for a a yesterday's Backup database restored on a single server (isolated from PROD environment completely) and just would do all my analysis there