Is it me or does this sound like someone trying to create a Russia connection here? Why whould Russian intelligence do this so amateurishly? As if they want to get caught. - Cui bono?
Is it me or does this sound like someone trying to create a Russia connection here? Why whould Russian intelligence do this so amateurishly? As if they want to get caught. - Cui bono?
What do they want with NLRB days in the first place? Maybe they have an idea; maybe not. The goal is "we got your data, be worried". Getting caught furthers that.
The use of the nlrb data on the other hand is pretty clear. They had a number of ongoing cases against Musk's companies. Involving Russia is unnecessary to explain the motive.
There are literally dozens of ways to kill a guy, if you must poison him, which are cheaper in every possible way and can be sourced locally by someone with the sort of basic chemistry knowledge an intelligence agency would have on payroll, or from a drunk undergrad.
Which is to say: Russia's MO has at no point been "subtlety", it's been vranyo: a lie they tell where you know they're lying, but are obliged to pretend the other party is not.
Looking at the IP it might be a mobile connection.
> Russia
> MOW
> Moscow
> Moscow>
> 144700
> 55.7558
> 37.6173
> MegaFon
So, lets say it was one of the contracted private individuals that just happened to be travelling in RU for WHATEVER reason and wanted to test the login decided to just use their hotspot.
Given the level of incompetence here it wouldn't surprise me. But this is what whistleblowers are for, starting investigations. Now we will have to wait month and years of bureaucratic nonsense and legal challenges to every information request required for the investigation to even get started.
It's incredibly frustrating.
Also I haven't played with eSIM cards either and so I'm not sure their behaviour.
Go with the most probable case - one of the shiba-doge amateurs had a virus on his laptop, and after creating an account those credentials were automatically siphoned to some bot farm in the Ruzzian segment, from where a few automated attacks were initiated by a botnet, which were blocked by a regional firewall.
And then, they tried to get it shut off as soon as they found out it existed.
because they have a theoretical capability to get the credentials that were being used and would love to have a database dump to figure out what to do with it later. The botnet explanation is also plausible, but not mutually exclusive.
no. as if they don't care about being caught.
What I generally don't get, is that in so many hacks they state "this came from a Russina|Chinese|Iranian IP address", hinting that it came from that country probably.
Can someone in the security industry maybe elaborate if this makes sense or not?
It’s possible to route traffic such that assuming the crypto is perfect, the actual vps is not able to decrypt data.
I also think that it I were a doge member and _wanted_ to leak data to Russia, this is the exact opposite of how I’d go about doing it.
It makes me sick we're even considering "trolling" as a motivation here but, given that we are, it's clear we're at the level of stupid that they would brazenly leak data to Russia. These people are not the best, they are not the brightest, and there's no reason to assume they are playing 4D chess when checkers is working for them.
You really think DOGE as a whole couldn’t muster up the ability to route traffic via Russia? The engineers on the floor need to follow a relatively straightforward playbook.
Also "attribution engineering" is really quite easy and difficult to see through.
Often the purpose of a hack is not to exfiltrate data or sabotage systems but is exactly to direct blame (or sometimes distract/misdirect)
Indeed in vault 5 of Snowden's NSA leaks an "attribution engineering toolkit" was a interesting find. Malware is almost always engineered to throw forensic investigators off the scent.
That all said, I think this incident happening in US gov, in the current climate, without immediate urgent investigation is scandalous and in itself an indicator of deeper and very serious skulduggery.
Having said that. I doubt they checked and who cares where it landed? Its out.
Occam's Razor on doge (and the admin as a whole) points to opportunist amateurs, fraternizing on bravado & loyalty while willing to entertain treason by jumping through hoops for why it can't bother them.
Looking for deeper layers is a distraction. Nostalgic even.
I can empathize.
Further, saying "someone trying to create a Russia connection" sounds rather incredible. The Russia connections have been so absolutely overwhelming at every turn that it's infinitely beyond deniable now.
Russia just had to be a predominately white nation that paid lip service to Christian nationalism and that hilarious show turned them into the US far-right's best pals. It would be nice if we moved beyond pretending this is conspiratorial when it has been in the open and stated in the open repeatedly for years.
[1] DOGE is completely disregarding all security norms -- they think it's an annoying slowdown to not just install whatever they want and to open whatever ports they want, etc -- so the likelihood that vast troves of US data has been exfiltrated by enemy states is approaching 100%.
Everyone knew it was Russia. They were still like "I don't know what you're talking about".
It's all power games.
So they hack their enemy, and then use that to reinforce the false narratives they tell their own people. It's gaslighting at the national level. Russia is as if your emotionally abusive partner was your government. America is becoming the same.
Would it make any sense at all for a government agency (DOGE) to buy shady residential proxies in order to log in to their super-admin accounts? No. Nearly every government bans foreign IP addresses from accessing internal systems. That leaves the question: why did that log-in attempt happen? There may be another explanation, but the only thing that comes to mind is that someone in Russia using a mobile internet connection tried to log in but forgot to enable his VPN before doing so.
I don't see a legitimate reason to require no logging either. If you're investigating things, you want your activities logged in a way you can't alter because it demonstrates how you found the evidence, and that you aren't just making things up.
I also don't understand why the HN comment section is full of people trying to make excuses or explanations.
Though also, who knows, could just be Russian script-kiddies.
(and even if that is what happened, it goes back into "holy shit how did that happen?")
EDIT: Also, given that the attacker had correct credentials and was only stopped by an _ip address_ check, we may assume that, unless the attacker was particularly incompetent, they likely got in.
Chaos.