A lot of discussion, a week ago

https://news.ycombinator.com/item?id=43691142

Whistleblower details how DOGE may have taken sensitive NLRB datahttps://news.ycombinator.com/item?id=43691142

1139 points/7 days ago/528 comments

I'm glad this is still being discussed. It seems like there are 4 main threads that we have to deal with right now as a society, and the severity of each means we have no time to deal with just one.

1. Breakdown of rule of law and political systems. Executive usurped Congress and is currently usurping SCOTUS. Both parties are dead. MAGA replaced the Republican party and Democrats are in the wilderness.

2. Destruction of the federal government through DOGE, which is this thread.

3. Destruction of the economy through tariffs and usurping the Federal Reserve by firing the Fed Chair, turning America into essentially a controlled economy.

4. Destruction of non-government institutions like law firms and academima which are power centers that could resist points 1-3.

Don't forget - they are also busy replacing career military flag officers with sycophants.
Yeah that's like a 5th thing: abusing all of the Article II powers to their maximum effect. We have to follow that thread because if the trends hold, we will see the US military being deployed against the US people within the next 3 years.
RE: 4

The current Attorney General's brother is running for a seat on the Board of Governors of the Washington, DC bar. It is expected that he will carry water for Trump and Bondi and impede any sort of disciplinary action the DC bar may dole out to any attorney working for Trump.

Yet another way Trump has his lackeys putting a thumb on the scale.

This is a very important election and I'm surprised no one is talking about it. Maybe because only DC lawyers can vote but I would think dems would want national attention on this.
Only members of the DC bar can vote
That's what I said. I still think they would want eyes on the implications of this.
My brain skipped the 'because' and interpreted the statement as a question.

The responsible mental pathways have been sacked

Related: Whistleblower statement on anomalies at time of DOGE work at NLRB [pdf] - 16 hours ago, 13 comments - https://news.ycombinator.com/item?id=43755298
This whole article reads like a comedy. Hidden accounts, login attempts from Russia (they can't afford IP addresses elsewhere?), and then there is this:

"Berulis told KrebsOnSecurity he was in the process of filing a support ticket with Microsoft to request more information about the DOGE accounts when his network administrator access was restricted. Now, he’s hoping lawmakers will ask Microsoft to provide more information about what really happened with the accounts."

Why does Microsoft have login and account information for a government institution? I'd prefer a mainframe without Windows or Internet access in the basement.

  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
> Why does Microsoft have login and account information for a government institution?

Undoubtedly Office365. Difficult to run a bureaucracy without Word or Outlook.

(French/German governments investing in a replacement for this kind of reason: https://www.techspot.com/news/107225-france-germany-unveil-d... )

Russia and China run their goverment offices with their own Linux distributions for very long now.
That's why we have docx
1. "Russian IPs" give them plausible deniability for people who are Pavlovian for that soundbite. 2. Plausible deniability no longer required for an administration with components that are obviously Kremlin influenced.
Both azure and aws apparently have the government as fairly large chunks of their userbase. It does raise some questions.
apparently? JEDI and Wild and Stormy were two programs just from the DoD and NSA that were 20 billion USD.

AWS, Azure, Oracle, SUSE (via Rancher) and I am sure GCP all have confidential & classified (C/S/TS) clouds, as well as lower FedRAMP clouds to get that sweet sweet federal money.

Not sure what questions it raises, it has been a thing for decades.

Given that extra information I guess:

Who handles physical security and what sort of place is it located that it can house that kind of data?

To what degree is the federal government subsidizing Amazon's retail dominance?

> Who handles physical security and what sort of place is it located that it can house that kind of data?

In general, the cloud/systems operator, in conjunction with the launch customer will build a dedicated facility for the classified stuff, and for the controlled stuff may have a dedicated facility, or have segments of the DCs in the US with extra security. for the classified stuff, there is a pretty rigorous list of requirements for the DC, and for any NOC that operates the service.

> To what degree is the federal government subsidizing Amazon's retail dominance?

A fair bit, but they are just like any big customer - just with higher margins. I think that was part of the reasoning for breaking up JEDI after AWS got it - the administration at the time hated the AMZN leadership, so wanted to remove money firehose from them and give it to others.

https://aws.amazon.com/govcloud-us/

None of this is new, AWS' dedicated US government stuff has existed for around a decade.

> To what degree is the federal government subsidizing Amazon's retail dominance?

Not more than any other big AWS customer.

What questions? All of the major cloud operators have government offerings too.
> login attempts from Russia (they can't afford IP addresses elsewhere?)

There’s some history of Russian intelligence being rather blatant here (presumably deliberately, as a way of making a statement). Remember Guccifer 2.0? That persona not only used a Russian ip address, but one which was _assigned to the GRU headquarters building_.

Nobody has ever been fired for buying Microsoft, which is a shame.
Azure cloud.
> login attempts from Russia (they can't afford IP addresses elsewhere?)

why pretend at this point? they own all of the leadership and there won't be consequences

  • ·
  • 1 day ago
  • ·
  • [ - ]
It's interesting, because Edward Coristine was fired "cybersecurity firm Path Network in 2022 for allegedly leaking internal company information to a competitor" [1]. Seems like an ideal candidate for recruitment by a foreign espionage service. And he'd used accounts on a cybercrime social network [2]. How in the world is this person still able to work anywhere near the government?

But if Russian spies wanted to access US Gov resources, why would they use their own IPs as the origin? Unless getting caught was deliberate, to foment discord?

[1] https://en.wikipedia.org/wiki/Edward_Coristine

[2] https://krebsonsecurity.com/2025/02/teen-on-musks-doge-team-...

Just like Harvard graduates hire other Harvard graduates, criminals hire other criminals.
As a PSYOP, it’s great:

- create account

- attempt to access whatever records, don’t worry about succeeding

- wait for US news to cause fragmentation

Undermining US unity is an objective of Russian influence, as we’ve seen from the spectrum of advocacy groups they funded ads for.

- - - - -

There’s also the suspicious timing that this happened just as the US was engaged with Russia to negotiate peace in Ukraine — and that this embarrasses the regime doing so and encourages a feud with Russia. (As an indication that it may not be so simple.)

Spying is complicated.

Aptly observed. I'm not even sure if it's what I believe is the case, but there's some serious merit in this line of thought.

It could make a lot of sense even if they have better means of access, and even with this attention risking the compromise of said access, simply because of how valuable even slight furthering of any division and political incoherence is right now both mid and long term.

Still wouldn't seem the more likely Plan A, as success would obviously be even better than such an apparently close failure, but I can see it being used to justify acting. Succeed at the intended plan and you win -- fail and you still win, just a little less so.

> How in the world is this person still able to work anywhere near the government?

It's a pretty long road, but it goes like this:

1. SCOTUS gets rid of campaign finance laws, opens up billionaires buying elections.

2. The world's wealthiest billionaire, Elon Musk, bought the 2024 US presidential election, and put himself in charge of the "government efficiently" office.

3. Elon Musk chose Edward Coristine, and no one said "no" because 1) everyone who would have said "no" has already been fired or pushed out and 2) no one else at the White House could actually pass a rigorous FBI background clearance, so they're just giving them to everyone by fiat.

DOGE will be an interesting case study in the years to come to say the least. A friend was contacted by them in an attempt to recruit him to help rebuild the nations aviation systems from the ground up as a 1099 contractor reporting directly to Sean Duffy. The recruiter advertised it as a side hustle on evenings and weekends paying an abmysal hourly wage. When my friend pointed out that the comp was far below what he makes, the recruiter countered with the prestige that will come with having worked for DOGE.
  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
> prestige that will come with having worked for DOGE.

This seems like a highly fragile currency. If things continue to deteriorate a future administration may end up running its own reprisals trials against DOGE staff.

  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
I mean I think it would be a fair assumption that there’s a very very real chance that havinng worked at DOGE will come with credible threats to your safety in the future. This is a team that is currently in the process of killing peoples grandparents by cutting them off from social security, building databases of immigrants and people with autism among a million other fuckups.

People aren’t going to just let that slide. I really don’t think they should expect to live in comfort and anonymity for the rest of their days if you look at how these kinds of things have played out historically with only a few counterexamples (I.e the East German Stasi come to mind as one)

> things have played out historically with only a few counterexamples

The first counter-example that comes to mind is the "Pact of Forgetting" that happened after Franco died, where basically people agreed to let spilled blood be spilled, without spilling more. Basically hard and difficult questions were avoided in order to facilitate "national reconciliation" when the transition to democracy began in 1970s.

Depending on the political aftermath when this (pointing everywhere) is done, it's not impossible something similar could happen, to try to let things cool down. Or, it goes the way of the Nuremberg Trials, also a possibility I suppose.

I can't speak for everyone, but as far as I'm concerned, I was willing to "forgive and forget" after the first Trump term.

But then January, 6 happened. And then Trump explicitly ran on the platform of rejecting the validity of the 2020 election and persecuting his political opposition, not to mention this whole DOGE thing and nuking the economy.

So, this time around, no. Anyone who stuck with him despite all that had their chance and they blew it. And this especially pertains to people who aren't just full-throated supporters, but actually facilitated this admin directly.

This is the kind of stuff we'll need https://en.wikipedia.org/wiki/Lustration for.

That's basically what Obama did with Bush, Iraq and the GFC. I remember him claiming that a bunch of investigations would bog down his agenda.

There was also this take from the "institutionalists" that a compact to not investigate your predecessor was an important part of our tradition of peaceful transition of power. Finally there was a feeling among Democrats that the Republican use of investigations against Clinton had been dirty politics.

I do think that generation of Democrats are being pushed out and I think we'll see a new generation with different ideas. In particular I think the base is finally repulsed by people like Chuck Schumer.

  • SR2Z
  • ·
  • 1 day ago
  • ·
  • [ - ]
For the half of the country that's always hated Trump to forget, Trumpism has to go EXTINCT. Like, discredited the way that fascism was after WWII or segregation after the Civil Rights movement.

God willing, when Trump finally officially plunges the US into recession, he and his supporters will become pariahs, but my faith in my fellow citizens is so low that I'm not even sure they'd notice.

I don't think that there is much room for forgiveness in a country where 48% of folks are STILL in support of Trump. The one thing I am certain of is that democracy will not die in the US without a fight.

  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
> discredited the way that fascism was after WWII or segregation after the Civil Rights movement

Got some bad news for you there: a large part of Trumpism is explicitly segregationist revival. Those people never went away, they were just under the surface, and they got mad again when action was taken to remove celebrations of segregationists (statues, building names etc) from public life.

[dead]
> very very real chance that havinng worked at DOGE will come with credible threats to your safety in the future.

That but also depositions. Lots and lots and lots of depositions in the future for DOGE employees.

Hiring a whole bunch of contractors is almost providing cover. "No, I didn't work on the gulag candidate selection tool, I was just a FAA navigation coder".

During the downfall of ISIS there was a funny quote from a commander in the Iraqi military along the lines of "if you listen to what the prisoners said, you'd think ISIS was entirely staffed by innocent drivers and cooks and never any jihadists"

The prestige of being unable to include it on your resume if you ever want to be able to work again.
Maybe they list it as "Consulting" and list vague achievements in government cybersecurity auditing?

A bunch of them seem young enough to just leave it off and say they were in school. Maybe DOGE counts as a student cybersecurity project?

Achievements and Hobbies: Destroyed US democracy, Kayaking and Bivouacking.
Oh, I'm sure some companies admire the "move fast, break things, don't care who you hurt, just follow orders" ethos.
Yeah, the less tongue in cheek (but even more tragic) version of this is just that they will be very employable by very ideological right wing organizations, and not very employable outside that bubble (unless they write or otherwise highlight a "learned lessons and turned things around" narrative of this period of time).

But most organizations don't, and won't, want to hire people who are willing to behave lawlessly.

It's a great case study of someone having no knowledge of something coming in and saying "we can save half the budget" then, oops - saying maybe they can do 5% of the original promise, lol.

I wonder how much DOGE is going to cost at the end of the day? I hope not literally billions of dollars, so maybe the $100b-200b they save will be net positive after the lawsuits, etc..

Rebuilding something as critical as the nations’ aviation system using underpaid 1099s working nights/weekends is certainly not the way to build a robust and fault-tolerant system. Idiots!
Ah yes, we should drop $20 billion dollars to some consultant instead. Who will hire incompetent people who'll do 30 minutes of actual work per day.
but you won’t have to pay pension and benefits :)
The false dichotomy! Nice. However you still make a good point. Farming out gov work to private industry is rarely a good answer. As you stated, they are normally even less efficient and cost more!
Would doing same work being contracted via big four consultant for 1/10th of the cost with 3x more meetings while moving 5x slower be more prestigious?
  • qwery
  • ·
  • 1 day ago
  • ·
  • [ - ]
Sad to see it if this gets killed as a [dupe].

The story has been posted twice, yes. The first submission[0] is ~10 hours older and has 3 comments on it. This one has 348 comments at time of writing. If you care about having an interesting discussion, this one's clearly where it's at.

[0] https://news.ycombinator.com/item?id=43758392

  • zoba
  • ·
  • 1 day ago
  • ·
  • [ - ]
And thats exactly what happened. Insane.
We’ve seen lots of posts about DOGE get killed. It’s not far fetched to think they are actively working to keep news like this off HN’s front page.
It's important to remember that a large proportion of the community just wants to see tech stories here, and not anything perceived as political.

And I totally get where they're coming from (this stuff is super exhausting and depressing).

That being said, this story in particular seems squarely in the HN wheelhouse, but I can understand that others disagree.

tl;dr probably not a conspiracy, just people who think differently than you do.

So odd. The dupe detector usually works really well. 9 times out of 10 when I submit a story, it already exists, and I just get redirected there. I rely on it actually, knowing that I can submit things freely and they will either get collapsed into the existing one, or start a new story. This time it did not work? URLs are the same. Sometimes people dupe the dupe detector with an arbitrary query string ... but in this case they are truly identical. Odd.
> Berulis found that on March 3 one of the DOGE accounts created an opaque, virtual environment known as a “container,” which can be used to build and run programs or scripts without revealing its activities to the rest of the world. Berulis said the container caught his attention because he polled his colleagues and found none of them had ever used containers within the NLRB network.

This feels funny to read, for some reasons.

it's written in a way to sound nefarious but is more an admission of technical ignorance
Not at all: it says DOGE appears to have created a container in a place where containers were never created by NLRB. Tell THAT to someone who doesn't know what Docker is, and it is less informative.

Where's the technical ignorance?

  • Ukv
  • ·
  • 1 day ago
  • ·
  • [ - ]
I think it sounds a bit off in the same way as "Linux, a computer program commonly used by hackers, was found on the suspect's machine" does, though not to that extent.

It's not saying anything technically untrue, and emphasising the aspects it does arguably makes sense within the context of what the concept is being brought up for, but it comes across as an odd framing for people familiar with the concept in general (using containers for standardization/scaling/etc.)

If you installed linux in a network that didn't typically have linux machines, and then had no accountability to what was running on said machine... yes, that would be suspicious and of note.
  • Ukv
  • ·
  • 1 day ago
  • ·
  • [ - ]
My point isn't that it couldn't be of note, but rather that - even when relevant - the phrasing makes for a strange-sounding definition to people already familiar with containers/Linux in a general context (and people who weren't familiar with containers/Linux might come away with that lopsided impression of them, even while having an accurate impression of how they were relevant to the article).

I think it could potentially be improved with a more general/typical definition first ("Containers are self-contained environments that bundle all dependencies a piece of software needs to run and are commonly used to streamline deployment across different machines, but can also ...")

And this guys how you get $200 per hour consultant say "I'm on my 15th sprint, still trying to figure out how to transform a CSV using powershell. Maybe next week it will be done."
That's because the explanation isn't for you. It's for people who don't understand why a mysterious new container is an issue in a secure system.
It's only odd for people in the middle segment of "just smart enough to understand why you want containers, not experienced enough to understand how they work"

We use them for standardization and scaling exactly because they are opaque. I personally believe the explanation shows a deep understanding of the technology, but also a good grasp of what matters politically.

From the email shown in the photo, it seems like DOGE was trying to build and run a docker container using Integuru (YC W24) https://news.ycombinator.com/item?id=41983409 to scrape the system
I was wondering when Y Combinator affiliated companies were going to show up to help DOGE dismantle democracy, and it looks like we've found the first instance.
  • lima
  • ·
  • 1 day ago
  • ·
  • [ - ]
Editorialized by the reporter, not the original report.
No it’s malicious

They intentionally turned off logging. Only attackers and criminals do that.

This is a smoking gun. I'm a little shocked at how little MSM coverage this is getting and the moral gymnastics some commentators are performing to lend a veneer of innocence to this. It's an incident on par with 1950s Cambridge ring [0] and I cannot understand why an investigation team from the Pentagon are not all over this kicking-in doors and taking names?

[0] https://en.wikipedia.org/wiki/Cambridge_Five

There will be coverage, but it has little point. The information network in America is Centre, left and centre right orgs, and then there is the Hermetically sealed Fox and related ecosystem.

So even if 2/3rds of America decide this is too much, they aren’t sufficient to shift what is covered in the idea economy and the political economy.

I just found out there’s even a book that did the ground work to make this case, in 2018. (Network propaganda.)

This is the prime reason I recommend all democracies look beyond their current leaders and grapple with the structural issues caused by capture of the media ecosystem.

Do note - this isn’t an issue of bias. There’s a protectionist economy on the right, where reality is whatever storyline they need to share.

> I cannot understand why an investigation team from the Pentagon are not all over this kicking-in doors and taking names?

The same Pentagon, which is current run by this person? https://apnews.com/article/hegseth-signal-chat-houthis-attac...

Because the Pentagon has the same boss as the people conducting these activities.
Well, kind of. There are people there who don't care about that.
> I cannot understand why an investigation team from the Pentagon are not all over this kicking-in doors and taking names?

As others have said but I can't reply to, it's because the Pentagon is run by a traitor and they stop any investigations under threat of dismissal.

But I hope people are keeping notes and will come forward, so that all of these people will face the consequences.

It's hilarious how the bastions of the free press were all over her emails but suddenly become almost mum at this

Then of course they are surprised nobody takes them seriously anymore

At this point I wonder if it's fear. They were able to cover the Clinton story because they knew no harm would come to them - the government wouldn't prosecute the press. But these stories, under this government, is the sort of thing where it could end up on the wrong side of an unchecked tyrant who is increasingly vocal about their desire to ignore due process.

The media companies ate so well and grew so fat covering the rise of fascism they didn't think what would happen when it finally gained power.

Notably, Krebs just had his security clearance revoked by Trump & Co. 12 days ago for posing "risks".

https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-pr...

Nope. It's a different, unrelated Krebs

The Cybersec one is Brian Krebs

Oh wow - TIL! I wish I could edit or delete the above. Anyway thanks for correcting me.
I mean it is not hard to see federal employees leaking data just to spite musks' project.

You do not need russian attacks either, people in US leaking all sort of data every year.

Fear isn't the answer. Unionizing and supporting each other is. That's why they are going after the NLRB and unions.
If I were a journalist I don't know how much I would trust a union to stop ICE from pulling me out of bed in the middle of the night.
It's not about your union stopping them from pulling you out of bed, it's about what happens after that. Rumeysa Ozturk, the student who was abducted in Massachusetts was a member of a union and her union immediately sprang into action. Part of the reason this was national news so quickly was because her union took to the streets.
Of course it is. They’re all wondering who the first reporter is that is going to get disappeared to El Salvador.
There is a LOT of stuff to cover right now.
I think a part of it is simply that the space is absolutely flooded and the public becomes almost numb to it: This administration is so absolutely rampant with criminality, constitution shredding, and just rank incompetence that reports of more of the same just doesn't trend. I mean, it's similar to the fact that Trump lies about everything constantly -- even the most meaningless facts like his height and weight -- and soon it just isn't noteworthy that he continues lying about everything constantly. When Trump is caught in an obvious lie, which is basically a daily occurrence, he doesn't apologize, he doubles down, and this is his super power, at least among his incredibly stupid fans and base.

"But her emails" was when Hillary using a private server was actually so exceptional it was like the singular thing. Trump's crew of misfits and clowns and self-dealing grifters have turned the government into a circus. They're all insider trading, launching shitcoins, turning the WH lawn into a pathetic infomercial while your commerce secretary -- Howard "Used Car Salesman" Lutnick -- is pushing stocks.

  • zo1
  • ·
  • 1 day ago
  • ·
  • [ - ]
It's just docker containers. As a technical person I was confused reading that at least 3 times until I made the mental connection that it's docker containers. So yes you are right it's made to sound more opaque and nefarious than one would normally assume in our field. If they have a policy that says we can't run docker containers in network A or zone B then just say so but don't lie to make it sound like Russia Hackers. That's the kind of shit that makes fence sitters and reasonable people across the isle not trust your motives.

Anywho, this whole "opaque" or "untrusted" code running in a VM is the same lingo that big corporates use to gatekeep newer technologies that bypass traditional processes. E.g. "oh sorry you can't test locally because you need to use our officially licensed and expensive Oracle DB instance. Oh and BTW, you can't use the free container image that Oracle provides free of charge. It's running 'untrusted' code in our network." and endless variations of that.

[dead]
  • Havoc
  • ·
  • 1 day ago
  • ·
  • [ - ]
Wild that this isn’t squarely in treason territory
It's only treason if someone in power actually charges them for it.
Seen from afar; it seems that Trump is so close to absolute power that he can simply brush off what should be scandals with real consequences. How _everyone_ survived the Signal scandal blows my mind
I could stand in the middle of 5th Avenue and shoot somebody and I wouldn't lose voters.
  • Y_Y
  • ·
  • 1 day ago
  • ·
  • [ - ]
Same, but that's just because I don't have any voters
It's shocking how prescient this quote is turning out to be. There's a significant chunk of the US voting population that is willing to forgive effectively anything Trump might do, no matter how distasteful, illegal or unconstitutional it gets.

Using the DoJ to go after his perceived enemies. Mob boss protection rackets against universities and law firms. Revoking visas for traffic violations...or nothing at all. Putting people into a foreign prison camp without a chance for due process, and refusing to do anything about the inevitable errors and rights violations that result. Eliminating oversight roles and agencies, enabling grift, theft, and fraud for himself and his friends. Selling cars on the White House lawn. Hiring incompetent people and not firing them when they inevitably do incompetent things (looking at you, Hegseth and RFK Jr). Refusal to admit failure or error regardless of how obvious it is. Constant lies about what he has accomplished. Destroying the US economy with erratic and unstable tariff policies. And so much more...

And they eat it up.

> There's a significant chunk of the US voting population that is willing to forgive effectively anything Trump might do, no matter how distasteful, illegal or unconstitutional it gets.

One of my friends posts almost daily impassioned screeds against Trump. One, yesterday, was about him "handing our country to DOGE on a silver platter, to privatize for the benefit of his friends".

Someone replied:

> Once the systems are torn to shreds, we will need to build new systems that serve ALL of us. We may not like or agree with what is happening, but it’s more effective to come together and work toward building what you want, than it is to fight against what you don’t want.

They completely misunderstand or are in denial or have been deceived (or some combination of the above) into thinking this is the tear down, and Trump will build back something for everyone.

They are completely ignorant to the fact that there is no WE in Trump's plans, just "ME".

He would likely lose a bunch of independent voters but your point still stand if we're only talking about the MAGA crowd.
TIL thanks.
I’ve been noodling this argument ever since November, and I am pretty confident now that America has a fragile, asymmetric information economy.

Most Americans on the right live in a protected information market. I am not talking about media bias — both sides have that. The issue is deeper: on the right, the marketplace of ideas has been captured. There's no free trade between ideas, only ‘subsidized’ narratives and ‘tariffs’ on dissent. That’s how Trump — or anyone like him — thrives. Realists, by contrast, get priced out.

This isn’t culture war stuff, this is structural failure. The traditional metaphor of American free speech — the Holmesian "marketplace of ideas" — breaks down when one side captures the market.

There is no competition of ideas when there is no fair fight.

If you’ve got a couple of million bucks to spend, my guess is start buying up and supporting local news channels in the rust belt, and then let them work on whatever they want to work, as long as they can show actual independence.

Or perhaps gift people subscriptions to things like groundnews or something. I don’t know if theres any science that shows it effectively diversifies information consumption of its users.

I don’t know what the napkin math is for a tipping point, but I suspect its not as expensive as litigating an entire administration.

  • Havoc
  • ·
  • 1 day ago
  • ·
  • [ - ]
Interesting theory. I'd venture that there is an element of selection happening though rather than just a structural flaw. i.e. The people aren't so much trapped in this captured market but rather actively opt in.
I believe you would be right. The structural case is made in Network Propaganda. One of the authors has another paper/article (1) that summarizes this and supports your point. I don’t see any sustainable future for America, or any other nation, unless this market is rebuilt.

To argue the case - while there is definitely an aspect of choice, opt-in matters less if your options are limited.

1] https://www.cambridge.org/core/services/aop-cambridge-core/c...

  • frm88
  • ·
  • 1 day ago
  • ·
  • [ - ]
That was an enlightening read. Thank you for sharing.
  • zo1
  • ·
  • 1 day ago
  • ·
  • [ - ]
Yet he literally can't get existing laws to be policed and acted on by government officials. Hardly absolute power when judges brush off his work left right and center.
Not enough authoritarianism , I see.
  • zo1
  • ·
  • 1 day ago
  • ·
  • [ - ]
Definitely not enough democracy. The plebs must just rather do as they're told, I see.
  • ohgr
  • ·
  • 1 day ago
  • ·
  • [ - ]
You mean brush off the bits where he’s breaking the law right? You know the laws that were there because once they weren’t and things broke.
Like what?
Yes judges still apply the law. But so what? Trump just ignores their verdicts. And its all fine and dandy, because he is a cult leader, and his followers are now everywhere.
What would be "treason territory"? The leaking or the siphoning of case data?
Because the impeachment attempts failed, the legal cases against Trump mostly failed, the Supreme Court inoculated him from further prosecution, and he got reelected.

The checks and balances have all been used up and failed.

„Russia accessing US data using Russia IP“

Is it me or does this sound like someone trying to create a Russia connection here? Why whould Russian intelligence do this so amateurishly? As if they want to get caught. - Cui bono?

The pattern has been that they don't particularly care about getting caught. The goal is to sow chaos, rather than any specific task. They like to goad you into making mistakes.

What do they want with NLRB days in the first place? Maybe they have an idea; maybe not. The goal is "we got your data, be worried". Getting caught furthers that.

I'm not so sure. Look at the bargaining power in geopolitics a country gets, when they know a certain country hacked them (Dem. hacks, Clinton email hacks, by Russia). It is always better to hide your tracks or to blaim someone else. Especially if it can be done easily.
  • freen
  • ·
  • 1 day ago
  • ·
  • [ - ]
Remember: the Russians also hacked the Republican email server as well, just, those emails were never released.
I forgot about that, so what you are saying is that all these gop legislators that are suddenly pro Russia aren't true believers? That is maybe better.

The use of the nlrb data on the other hand is pretty clear. They had a number of ongoing cases against Musk's companies. Involving Russia is unnecessary to explain the motive.

The Russians assassinated someone on British soil using a radioactive agent that can only be made in nuclear reactors, and is incredibly expensive to extract and transport.

There are literally dozens of ways to kill a guy, if you must poison him, which are cheaper in every possible way and can be sourced locally by someone with the sort of basic chemistry knowledge an intelligence agency would have on payroll, or from a drunk undergrad.

Which is to say: Russia's MO has at no point been "subtlety", it's been vranyo: a lie they tell where you know they're lying, but are obliged to pretend the other party is not.

They don't care, and also, their expectation from DOGE was probably "Logging is turned off, here's the credentials, go".
There's no need to try and attempt to connect anyone, the entire thing is smelly enough.

Looking at the IP it might be a mobile connection.

> Russia

> MOW

> Moscow

> Moscow>

> 144700

> 55.7558

> 37.6173

> MegaFon

So, lets say it was one of the contracted private individuals that just happened to be travelling in RU for WHATEVER reason and wanted to test the login decided to just use their hotspot.

Given the level of incompetence here it wouldn't surprise me. But this is what whistleblowers are for, starting investigations. Now we will have to wait month and years of bureaucratic nonsense and legal challenges to every information request required for the investigation to even get started.

It's incredibly frustrating.

If one is using roaming, does it show the IP of locality they are actually in or the IP assigned to their home operator? I vaguely remember that it's the latter.
At least with European 2G/3G/4G it's the latter, their home country IP.
I honestly don't know, I am just trying to do mental gymnastics to imagine why this would even happen.

Also I haven't played with eSIM cards either and so I'm not sure their behaviour.

I don't think eSIM would make a difference here, it's job is mostly to derive a secret.
Why would you assume Ruzzian Intelligence if only IP address has been mentioned? Also, if it was such an agency, why wouldn't the supposed shiba-doge leaker/spy not provide them a warning that regional restriction firewall exists?

Go with the most probable case - one of the shiba-doge amateurs had a virus on his laptop, and after creating an account those credentials were automatically siphoned to some bot farm in the Ruzzian segment, from where a few automated attacks were initiated by a botnet, which were blocked by a regional firewall.

>Why would you assume Ruzzian Intelligence if only IP address has been mentioned?

because they have a theoretical capability to get the credentials that were being used and would love to have a database dump to figure out what to do with it later. The botnet explanation is also plausible, but not mutually exclusive.

DOGE people were brand new to the infrastructure. (That's one of the criticisms - they're doing all this wild activity without really understanding the environment they're working in.) So they very plausibly would not know about the region-restricting firewall.

And then, they tried to get it shut off as soon as they found out it existed.

I would assume that mr. Berulis would mention taking down said firewall and the subsequent successful access from the foreign IP. So far it seems that all the data was stolen by bulldoge people for the internal USA masters (Elon likely), at leas at the first step. And it makes sense, because Elon and his cronies do profit from the NLRB info and have a preexisting history attacking them. While at the same time Ruzzians probably won't have any use from the data itself, and planting backdoor to the system would be done in a more quiet way. As it stands now, that whole system would need to be sanitized after the dog invasion, and all backdoors will be destroyed most likely.
> As if they want to get caught

no. as if they don't care about being caught.

Right because they got caught before and the Supreme Court and the right side of the aisle bailed him out time and time again
My humble personal hypothesis (so this could be totally completely wrong, because it's just an hypothesis) is that this is not about information, but about chaos. For the layman it seems connecting the dots is more than sufficient to get to a conclusion. As if somewhat tech adept people have been given very powerful tools, but not the entire oversight of what their actions might cause.
It also raised my suspicion.

What I generally don't get, is that in so many hacks they state "this came from a Russina|Chinese|Iranian IP address", hinting that it came from that country probably.

Can someone in the security industry maybe elaborate if this makes sense or not?

As a technical problem to correlate # bytes @ time is just a very simple and you don't need a PhD to solve. Its a matter of how many measurement points on the network you have available.

Having said that. I doubt they checked and who cares where it landed? Its out.

Occam's Razor on doge (and the admin as a whole) points to opportunist amateurs, fraternizing on bravado & loyalty while willing to entertain treason by jumping through hoops for why it can't bother them.

Looking for deeper layers is a distraction. Nostalgic even.

I can empathize.

Something worth knowing is that "attribution" is extremely difficult.

Also "attribution engineering" is really quite easy and difficult to see through.

Often the purpose of a hack is not to exfiltrate data or sabotage systems but is exactly to direct blame (or sometimes distract/misdirect)

Indeed in vault 5 of Snowden's NSA leaks an "attribution engineering toolkit" was a interesting find. Malware is almost always engineered to throw forensic investigators off the scent.

That all said, I think this incident happening in US gov, in the current climate, without immediate urgent investigation is scandalous and in itself an indicator of deeper and very serious skulduggery.

Not really. I am not a doge supporter, but if was and I wanted to troll the left, I would route traffic through a rented vps with a Russian IP.

It’s possible to route traffic such that assuming the crypto is perfect, the actual vps is not able to decrypt data.

I also think that it I were a doge member and _wanted_ to leak data to Russia, this is the exact opposite of how I’d go about doing it.

We're firmly in the realm of 1984-type arguments: "The Party told you to reject the evidence of your eyes and ears".

It makes me sick we're even considering "trolling" as a motivation here but, given that we are, it's clear we're at the level of stupid that they would brazenly leak data to Russia. These people are not the best, they are not the brightest, and there's no reason to assume they are playing 4D chess when checkers is working for them.

That’s a naïve assumption that underestimates the capability of a party you clearly disagree and/or think poorly of. I’m not saying it’s happening, but I think it’s not an impossible scenario.

You really think DOGE as a whole couldn’t muster up the ability to route traffic via Russia? The engineers on the floor need to follow a relatively straightforward playbook.

Could they do it? Sure, it's not an impossible scenario, but what would be the reason for it outside of "trolling"? Both Occam's and Hanlon's razor fit easily here.
I think it’s reasonable to assume that a substantial portion of doge employees have roots in /pol/ which itself has roots in /b/. Elon literally carried a sink into Twitter on his first day, I’m sure there’s plenty of similar antics elsewhere.
  • freen
  • ·
  • 1 day ago
  • ·
  • [ - ]
Why go through the effort of sneaking in the back door if the front is wide open?
This administration is almost blatantly pro-Russia. I don't think there's any need for a leak, you can just... be on their side. I mean, that's what the literal president does and no America-loving cowboys seem to care.
[dead]
Is it possible to have a Russian IP with a VPN maybe ?
Yes, with a residential/mobile proxy. Russian proxies are cheap because they're blocked or heavily scrutinized by many interesting networks, due to the rampant and unpunished misbehavior of some people in Russia.

Would it make any sense at all for a government agency (DOGE) to buy shady residential proxies in order to log in to their super-admin accounts? No. Nearly every government bans foreign IP addresses from accessing internal systems. That leaves the question: why did that log-in attempt happen? There may be another explanation, but the only thing that comes to mind is that someone in Russia using a mobile internet connection tried to log in but forgot to enable his VPN before doing so.

I don't see a legitimate reason to require no logging either. If you're investigating things, you want your activities logged in a way you can't alter because it demonstrates how you found the evidence, and that you aren't just making things up.

The IP is mentioned in the article. It belongs to a cell provider. Technically possible to have a VPN endpoint on a cell network, but unlikely.
Why would a representative of a US government agency use a Russian VPN with legitimate, freshly created login credentials? I'm confident this is against all the cybersecurity rules in place.

I also don't understand why the HN comment section is full of people trying to make excuses or explanations.

Because it didn't happen?
It’s important to carefully watch which US official opens up the login policy to whitelist the region of Russia.
Assuming the policy wasn't known and it wasn'teant to be seen. But either way... Backdoors in bleb starlink access points surreptitiously added to the roof of the gsa, how would you ever begin to undo this level of compromise?
Why don't people understand how networks work?
They’ve done this before; see Guccifer 2.0.

Though also, who knows, could just be Russian script-kiddies.

The more concerning part is the use of valid username/password combinations. Unless they literally set this up as root/root (not...as implausible as it should be but from the description it seems unlikely) then how did they get them?

(and even if that is what happened, it goes back into "holy shit how did that happen?")

I mean, honestly I wouldn't be amazed if one of the DOGE peoples' personal laptops (which I assume they were using, because no-one involved in any of this seems to have the first clue what they're doing) was compromised. If they saw outside login attempts within minutes of account creation, then, as you say, unless it was root/root or similar, presumably fairly realtime data exfiltration is going on _somewhere_.

EDIT: Also, given that the attacker had correct credentials and was only stopped by an _ip address_ check, we may assume that, unless the attacker was particularly incompetent, they likely got in.

They'd use one of their gazillion Digital Ocean VM-instances located in the US.
Or a botnet with thousands of infected US computers?
Or it's a 19 year old kid in Russia the DOGE kid met online, both of which do things for the lulz and have no idea how to properly secure their footprint.

Chaos.

Why intelligence? Why not criminals?
«Never assume malice when stupidity will suffice.» - Robert J. Hanlon
I'm pretty sure it's the other way around. This way is just stupid and borderline suicidal.
Suicidal for the US - but who is going to act to make it suicidal for DOGE?
Russia has absolutely no need to hide anything. Do you think they would face any consequences at all? And given the astonishing incompetence from DOGE, that its various staff members have been thoroughly compromised isn't remotely unlikely[1]. It doesn't even have to be Russian intelligence but could be any of the many hacking groups in Russia, and the IP noted (83.149.30.186) is a well known player in intrusion attempts.

Further, saying "someone trying to create a Russia connection" sounds rather incredible. The Russia connections have been so absolutely overwhelming at every turn that it's infinitely beyond deniable now.

Russia just had to be a predominately white nation that paid lip service to Christian nationalism and that hilarious show turned them into the US far-right's best pals. It would be nice if we moved beyond pretending this is conspiratorial when it has been in the open and stated in the open repeatedly for years.

[1] DOGE is completely disregarding all security norms -- they think it's an annoying slowdown to not just install whatever they want and to open whatever ports they want, etc -- so the likelihood that vast troves of US data has been exfiltrated by enemy states is approaching 100%.

If this was the case then Russia would also admit they did it. It's weird to not hide your IP, but still deny the hack on political level.
Nah, it's the same as the "little green men" in Crimea back in the day.

Everyone knew it was Russia. They were still like "I don't know what you're talking about".

It's all power games.

The major powers are endlessly engaged in hacking operations against each other. This is just normal, and no one needs to "admit" to it for that reality to be true. The notable part of this story isn't that Russia tried to compromise a US system, but instead is that some Russian party (whether official or unofficial) apparently had DOGE credentials moments after they were created, which indicates that DOGE is thoroughly compromised. Which should surprise absolute no-one.
Look at what they did with the 2016 election. They hacked that too and didn't hide anything, but when they were accused by the US government they claimed innocence and blamed Ukraine. The allows Russian people to say "Look how awful those Ukrainians are for hacking America; and look at how awful America is for blaming Russia."

So they hack their enemy, and then use that to reinforce the false narratives they tell their own people. It's gaslighting at the national level. Russia is as if your emotionally abusive partner was your government. America is becoming the same.

  • exe34
  • ·
  • 1 day ago
  • ·
  • [ - ]
I wouldn't rule out incompetence, but after the Nazi salute during the inauguration, I'd say it's a demonstration of power - "look at what I can do, and there's nothing you can do about it".
  • kmitz
  • ·
  • 1 day ago
  • ·
  • [ - ]
How come this article has disappeared from HN front page ? Posted 2 hours ago and with 649 points
It's not flagged. Is it shadow banned? Is that a thing in hacker news?
  • kmitz
  • ·
  • 1 day ago
  • ·
  • [ - ]
I hope not. It would be such a disappointment.
It is a thing though
  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
Dang and other editors manually tweak things regularly to make sure stuff like this is not on the front page and consider that to be a feature not a bug and are not at all interested in listening to any criticism that maybe that’s not the right move in 2025.
This is false.

This story spent 18 hours on the front page seven days ago, and attracted over 1100 upvotes and over 600 comments. It also attracted dozens of community flags, but we turned off the flags in order to give the story full visibility.

https://news.ycombinator.com/item?id=43691142

  • frob
  • ·
  • 1 day ago
  • ·
  • [ - ]
It's currently showing up as flagged as a dupe and isn't anywhere on the first 3 pages.
Because today’s post is a repeat/dupe of the same story that was on the front page for 18 hours a week ago and attracted 1100 upvotes and 600+ comments. It was one of the biggest stories all year on HN:

https://news.ycombinator.com/item?id=43691142

It's bog standard HN moderation to remove duplicate stories.

  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
What is even the logic here? I understand the concept that when you have multiple threads going on about one article or story AT THE SAME TIME… then sure, the dupe option makes sense.

When you are manually putting a dupe tag on a story because someone posted it a week ago I think people feel very differently about that.

This is very literally the kind of behaviour people are referring to when they make the accusation that the mods are actively interfering with what people want to talk about.

This idea that you’re here telling me and others with a straight face that everything is above board while also doing this just doesn’t pass the credibility test, the logic makes no sense.

This is the way HN has always been moderated. Well, for at least 10 years. It's in the FAQ [1]

If a story has not had significant attention in the last year or so, a small number of reposts is ok. Otherwise we bury reposts as duplicates.

It's nothing to do with it being political. It's simply to do with being a duplicate of a story that has already been heavily discussed, just a week ago.

It's a well established convention that a topic is only eligible for further front page exposure when there is "significant new information" (SNI) [2].

There have been many instances of SNI with respect to DOGE this year, which is why there have been (I believe) more front-page stories about it on HN than anything else [3].

[1] https://news.ycombinator.com/newsfaq.html

[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

[3] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

The krebs on security detail was published just yesterday. While it's the same event, krebs is an authoritative source which has more detail than the npr source.
The threshold is Significant New Information ("SNI"), where "significant" implies that it's material enough to alter the dimensions of the story. I don't think many people were left uncertain by the NPR story.
> It also attracted dozens of community flags

I've noticed that a lot of the articles describing various Trump admin abuses (be it DOGE, or Trump crypto scams, or whatever) get flagged a lot. (While they're very relevant, nobody can tell me SBF crypto drama scams are relevant to HN, but Trump crypto scams are not). It's concerning that there are people on HN who prefer to silence such discussions...

  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
Are you really telling me with a straight face that there isn’t manual intervention every day to deemphasise political content? Like we are all watching it happen in real time. Every day the gap between what people are ACTUALLY voting for that’s only available on a hidden page (https://news.ycombinator.com/active) not linked to from anywhere on the website as far as I can tell and what is presented as the most popular content is considerable.
Dang has written about this at length several times over the years and did so again just three days ago:

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

We don't manually intervene to deemphasise content just because it's political, and indeed we often manually intervene to restore political stories to the front page when they have been automatically downweighted due to flags or flamewars.

We moderate to optimize for intellectual curiosity, nothing more.

  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
It’s an awfully convenient bit of wording where nobody can pin you down on exactly what that means but only on what actions get taken.

It’s what I’m referring to when I say that I’ve never once seen a moderator once consider their own judgement when presented with feedback. It’s always the same line. Things are running exactly as intended from your point of view it would seem.

I mean not to be difficult: just to try and understand exactly what your claim is.

If you have an example of a moderation action that you disagreed with (E.g., a particular story about DOGE or the administration that wasn't adequately discussed on HN), please share a link or something else concrete and we'll explain it or investigate it. You can post it here or email us (we have had email threads going back years with users who want to share feedback and learn about how we think about these things [1]).

There are plenty of ways of examining the data:

- https://github.com/HackerNews/API

- https://news.ycombinator.com/item?id=40644563

- https://hn.algolia.com/

- https://news.ycombinator.com/front

If you have concerns about any future stories being hidden, you could set up your own API listener, monitor for new stories and then see which ones are flagged or killed.

For the record, I routinely undertake practices for evaluating and improving my own judgement, and am happy to do so regarding any specific case. But you haven't provided me with any specific feedback to respond to.

[1] https://www.newyorker.com/news/letter-from-silicon-valley/th...

At the peak period of DOGE activity when it was the biggest political news story, I never once saw stories about it on the front page here. Someone relying on HN as their primary news aggregator would be entirely clueless to what was going on in Washington. I actually tried searching for them at last, because it seemed implausible to me that nothing was being posted and gaining traction and it was only then that I realized that there were tonnes of stories, but they were being flagged and buried.

I don't necessarily know that it's moderator malfeascence so much as people abusing HN tools to bury stories that they don't like, but I do think that there should be some consideration about how those tools are being abused and how that abuse can be effectively countered.

I get the impression that an effort is being made to correct the situation, but I've given up on the front page and only visit /active now, so I might be completely wrong.

Guys, I want to investigate this claim, but people keep making it without giving me any details to look into. If you give us a specific news item or date range, we can look at the data and see what was happening (we have access to internal and external tools that show where each story was ranked at different times).

Also: any time you know of an important story that you think should be on the front page, you can email us to let us know - hn@ycombinator.com. We'll either address it or explain why we're doing something other than what you're asking for.

> Someone relying on HN as their primary news aggregator

Who are these people who look only at HN and nothing else, expecting to be fully informed about everything that's important in the world? :)

Huh, I've never seen "active" before, it looks like one of the hidden views like pool. Can't blame people for not seeing a thread there...
Boy do I have news for you: https://news.ycombinator.com/lists

Bunch of other fun links in the footer too :)

I was just asking myself the same thing.
  • kmitz
  • ·
  • 1 day ago
  • ·
  • [ - ]
The faq says rankings can be affected by automated moderation. I'd appreciate to have this clarified by a mod if one happens to read my words. Thanks

How are stories ranked?

The basic algorithm divides points by a power of the time since a story was submitted. Comments in threads are ranked the same way.

Other factors affecting rank include user flags, anti-abuse software, software which demotes overheated discussions, account or site weighting, and moderator action.

> software which demotes overheated discussions

i'm inclined to think this is it. can't have the populous too rowdy - gotta settle them down.

Sounds like something Neville Chamberlain would have supported. We will at last have peace in our message boards.
Possibly because Y now has some of its startups involved with DOGE and other government activities. Keep in mind that much of the techn world’s anarchocapitalism ideology being implemented came from or has been the “though leaders” or their behind this website.
You guys!

Paul Graham (the only "thought leader" behind this website) loudly campaigns against the current U.S. administration almost every day on Twitter.

One YC-backed founder out of more than 10,000 is volunteering with DOGE.

A more thorough response to this trope can be found here:

https://news.ycombinator.com/item?id=43734897

  • pera
  • ·
  • 1 day ago
  • ·
  • [ - ]
Is Graham still involved in HN?

While it's true that he has spoken against Trump many times, Garry Tan is very close to Thiel, Musk, and the MAGA movement in general. Didn't he recently show support for DOGE as well?

Of course, YC is more than its current CEO and hopefully this doesn't affect the moderation of this website :)

> Is Graham still involved in HN?

He's on the board of YC, which appoints the CEO [1], and he still has a lot of influence. He still has dinner with dang from time to time to talk about HN [2].

> While it's true that he has spoken against Trump many times, Garry Tan is very close to Thiel, Musk, and the MAGA movement in general. Didn't he recently show support for DOGE as well?

I don't think that's a completely accurate characterisation. Garry continues to identify as a Democrat [3]. He works with people across the political spectrum to make the playing field fair for the earliest-stage startups, which is consistent with his roles as an early-stage investor and a partner (and now CEO) of YC for over a decade. Just a couple of weeks ago he hosted the Little Tech Competition Summit [4] in DC, featuring speakers from different sides and parts of government. One of the most notable speeches was by Cory Booker, who talked at length about the importance of making entrepreneurship accessible to people of all socioeconomic backgrounds, which is a cause Garry deeply supports, given his own life experience.

> Of course, YC is more than its current CEO and hopefully this doesn't affect the moderation of this website :)

Exactly :)

If we were making moderation decisions to serve individuals or agendas that supposedly our “salary depends on”, we'd tie ourselves in knots.

Our job is to keep HN a great place for intellectual curiosity.

[1] https://www.forbes.com.au/covers/innovation/y-combinator-sta...

[2] https://x.com/paulg/status/1758191829491859607

[3] https://x.com/search?q=from%3Agarrytan%20democrat&src=typed_...

[4] https://www.youtube.com/watch?v=yjIJOfgVgu0

> Our job is to keep HN a great place for intellectual curiosity.

Can you elaborate on that?

Dang has written about it a lot over the years:

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

It's also the core principle of HN, as stated at the beginning of the guidelines:

https://news.ycombinator.com/newsguidelines.html

Feel free to ask any further questions not answered in the links above!

Thanks!

Sure, I'll just ask directly:

Q: Do you know of any experiments of psychological or sociological nature ran on the HN platform or its participants?

Q: If you knew that such experiments take place, would you be able to confirm it publicly?

This is quite the curveball, but, sure: this would never happen. The primary guiding principle of HN moderation is that community trust and goodwill is the most precious thing we have, and any action that diminishes it would destroy HN and everything we've worked for. The community scrutinizes everything we do. I can't fathom any such experiment that would be remotely beneficial to HN/YC that would be worth diminishing community trust for. Can you?

Edit: why this question, by the way?

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

There has been some strange submissions and comments lately. Discussions feel out of place.

The expression "intellectual curiosity" grabbed my attention. Whatever is happening is definitely curious from an intellectual point of view, but it feels weird.

The world feels weird to me lately, but nothing you’re seeing is due to any secret experiments or any change in moderation policy.

We’re (always) trying to get better at finding and penalizing bad comments – but not everyone agrees on what constitutes a “bad” comment.

Everyone is welcome to email us at hn@ycombinator.com if they see any story or comment that seems off, and we’re happy to investigate or explain anything.

No, but he's (AFAIK) the Chairperson of YC itself.
His responses to these particulars are less relevant than his career of pushing ideas that have fueled the anarcho capitalist agenda where the following seems virtuous rather than destructive of equitable law and society:

If you follow the logic of his essays—especially ones like “How to Make Wealth,” “Do Things that Don’t Scale,” or “Hackers and Painters”—you end up in a world where:

• The best people ignore rules that slow them down.

• Regulation is often just cargo-cult bureaucracy.

• Wealth is proof of virtue, or at least utility. Wealth + the rest = do what you want if you think you’re right and can get away with it

• Institutions should get out of the way of smart individuals.

• And the market, not the government, should determine value.

These are interpretations that can be argued and debated (it's not appropriate for me to engage in any such debate here). But there are also major disconnects and deeply hostile disputes between key YC figures and those working with the administration.

The point is, none of it has anything to do with the way we moderate HN – which of the conflicting cues would we follow?

HN has had more front-page-visible, heavily upvoted/discussed stories about DOGE than anything else this year, along with several others relating to the administration, with the overwhelming sentiment in the articles and comments being critical.

Dang has commented at length on the matter several times:

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

I think dang, or the agglomeration of people who fill that role, are pretty good in respect to this, responsible stewards of the active commenting space. and I’m not proposing conspiracy theories about them not being upfront or honest in what they have said: it’s much simpler than active suppression to simply tweak the automated criteria by which articles are allowed to rise or fall.
'tomhow is part of that agglomeration, fwiw.
Loudly complaining on a closed platform controlled by the unelected darling of the current adminstration is less impressive than he might hope. He has high profile blog that is silent on the current administration but highlights a article critical of "Wokeness".
> Paul Graham (the only "thought leader" behind this website) loudly campaigns against the current U.S. administration almost every day on Twitter

Does he? https://x.com/paulg (maybe moderated by Musk/Twitter) only shows tweets about Gaza suffering which could be construed as criticising the current administration. On the contrary, I see multiple tweets jerking off Elon Musk (part of the current administration) and calling for compassion and personal sacrifice towards people who voted for Trump. Yes, there's "why you should vote for Kamala" tweet, but nothing critical of the current Trump regime. Let alone daily.

Perhaps you're not logged in and are only seeing the highlights from recent months? I see a steady stream of posts criticising the current administration – some of his own and some reposts of others – several in just the past few days.
Can confirm, Paul is one of the few people I still pay attention to on Twitter.
PG is a tech billionaire and I don't trust any of them more than I can throw them. They'll put on a nice "Don't be evil" face and then smash us under their heels.
Stuff gets flagged as "flamebait" or something similar (forget the exact term) on HN - I think this can be done manually and is also automated, but it can definitely be turned off manually by mods - and it gets sent to the void b/c of risk of starting unwanted conversations.
You guys! No topic has been anywhere near as heavily discussed this year on HN:

https://hn.algolia.com/?dateEnd=1745332080&dateRange=custom&...

Sorry, I didn't mean to frame this in any way, just meant to say what's going on.
  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
Or censored. Don’t present this issue as a one way street it’s very clearly not the case.
  • mdhb
  • ·
  • 1 day ago
  • ·
  • [ - ]
A weird response specifically to a statement about it one sided responses.

Show me all the flagged stories from this year along side it please.

I'm a cyber security incident responder. Firstly, let me claim my bias - I don't trust Kerbs after his FUD reporting about the CVE totally not losing funding. I started my cyber career in federal government contracting as a SOC Analyst and eventually became an incident responder.

My first doubt - the NLRB has a SOC ran by an MSSP/government contractor. Data destruction events and anomalous connections would 10000% cause security event alerts to trigger. Sentinel has OOB detection for anomalies for events that the whistle blower states in the article.

My Second doubt - CISA and US-CERT are not a bunch for scrubs. If their official statement is that it's not a security incident then I trust them.

Third doubt - If you see something suspicious then you have every right to report it to the SOC, and contain the suspicious activity to the best of your ability. If you don't have permissions then report it to the SOC. All malicious activity gets investigated (unless the MSSP is a joke but then they become liable and will get sued if it turns into an incident that results in damages).

Fourth doubt - Kerbs and the whistleblower are framing this as a sophisticated nation-state attack leveraging DOGE to exploit the NLRB. But that doesn’t add up. Nation-state actors don’t blow their cover because they proxy with clean IPs from within the target country. The IP address in question (83.149.30[.]186) has had a bad reputation in open-source intelligence for over a year, linked to credential stuffing and scanning activity. Using an IP like that in a high-level operation is like flying a spy plane into enemy airspace with inflatable tube men and disco balls strapped to the wings. Attacks of this complexity require significant time and resources—no serious actor would risk burning their investment by using an IP already flagged and based in Russia.

Last doubt - The "Security Engineer" took a screenshot of the user names then gave it to the media....You're expecting me to trust what you say while you commit a data leak - nice one.

Likewise it is difficult to take your remarks seriously, especially with -13 account karma. Your sentiments remind me of the widespread gaslighting currently occurring within the GOP.
Notice that the email from the deputy CIO mentions SCuBA.This is the "Secure Cloud Business Application Project" from CISA.If you look at two of the required policies you will find this:

"A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role."[1]

and

"Privileged users SHALL be provisioned with finer grained roles instead of Global Administrator."[2]

So at least for the agency-wide removal of security administrator roles, that would seem to be unrelated to anything DOGE was doing. The NLRB was supposed to be doing that anyway.

[1] https://www.cisa.gov/resources-tools/services/m365-entra-id#... [2] https://www.cisa.gov/resources-tools/services/m365-entra-id#...

Is this a new policy? Otherwise, why this sudden and broad implementation so that "suddenly none of the IT employees at the agency could do their jobs properly anymore" (according to the source).
It's pretty new, yes. The binding operational directive from CISA only came down in December. Agencies are in the midst of running the assessment tools and implementing the changes right now. See here: https://www.cisa.gov/news-events/directives/bod-25-01-implem....
This is about the Global Administrator role. I don't believe that the employee had this role to begin with.

Otherwise this quote wouldn't make sense:

> [...] top-tier user privileges that neither Berulis nor his boss possessed

However, my guess would be that this is the role that DOGE employees requested to be assigned as it is the role with the highest level of privileges.

The policy you linked doesn't say "agency-wide removal of security administrator roles". It discusses a limit. That says nothing about how many there were here, how it suddenly changed, how elmu's DOGE was able to gain administrator access despite these restrictions, how elmu's DOGE administrators were chosen, etc.
Yes, a limit of eight. Meaning that if there were more than eight across the agency, the rest were supposed to be removed by order of CISA. So the binding operational directive is a plausible, alternate explanation of the facts reported in the article. Again, I didn't just do a google search and come up with this; the Deputy CIO specifically mentioned SCuBA in the email that's put in the article. It's not my fault that neither Krebs (nor anyone else, apparently) decided to look into what the email meant by "SCUBA."
> Meaning that if there were more than eight...

That seems like a big "if". What I'm asking is, how many were there before elmu's DOGE started compromising systems? Was it more than 8? If not, that would not be a valid justification for the DCIO to cite.

Did elmu's DOGE make sure not to grant themselves administrative access (because that would make it more than 8)?

How many remain? Is it 8? Do the current administrators match the ones which existed before elmu's DOGE started compromising systems?

Removing admin from people who don't need it is 100% the correct thing to do according to any IT guidelines you could quote. And of course, every single user will whine that they're special and really really need it. With regards to the rest of the article, there's definitely stuff to be investigated here but I don't see the investigation yet.
"Removing admin from people who don't need it is 100% the correct thing to do"

Indeed. And if you look at the picture of the email from the deputy CIO he mentions SCuBA (see here: https://www.cisa.gov/resources-tools/services/secure-cloud-b...). Cleaning up unnecessary admin roles is exactly the kind of thing that CISA itself is requiring agencies to go in and do.

> Removing admin from people who don't need it is 100% the correct thing to do according to any IT guidelines you could quote. And of course, every single user will whine that they're special and really really need it.

You assume that "suddenly none of the IT employees at the agency could do their jobs properly anymore" is whining and not substantial?

Shouldn't be least privilege principle a culture (a standardised and automated process) and not something that happens ad hoc?

Yes I do assume that... I've worked in IT for a long time. That phrase in a ticket would be an immediate eye roll from me. A lot of the quotes in the article trigger my eye roll reflex actually. But there is some stuff in there that warrants an explanation/double check to be fair.
From my understanding, the whistleblower is one of the admins, so why he shouldn't have the rights?
Did you read the part where they kept them from reporting to the agency who would investigate?
  • ·
  • 1 day ago
  • ·
  • [ - ]
You’re focusing on the wrong thing. You’re not wrong but why is this the bone to pick? The big story here is that priv accounts were created, shortly thereafter they were being utilized from Russia, and data exfiltration occurred.
The screenshot of email from DCIO is what should be getting rolled out. This is not suspicious by itself from my perspective. SCuBA is a CISA project that improves security.

Source: https://www.cisa.gov/resources-tools/services/secure-cloud-b...

Remember: The behavior will continue until an effective negative stimulus is introduced.
3.5% of a population needs to protest and that historically predicts country wide change, I heard once.

> based on the research of political scientist Erica Chenoweth

And the only effective negative stimulus here is locking up people in jail and/or violent action.

Which no one in the opposition will allow anyone in the opposition to do. Potentially for good reason (it would make them a legitimate target for violent retribution), but which just means the war was lost before it started.

Which is why people aren’t fighting back much either - because the smart ones are looking at the score going ‘I’m just going to get murdered fighting a war you already lost because you refuse to let anyone use weapons that will work’.

Start with protesting, non violently.

Big enough protest historically predicts country wide change

We've been doing that for ten years now.

Standing in a city park with a sign that says "Dumbledore wouldn't have let this happen" isn't working. [0]

[0] https://preview.redd.it/some-of-my-favorite-photos-from-hand...

This, this right here is the shit I’m talking about.
> “Our acting chief information officer told us not to adhere to standard operating procedure with the DOGE account creation, and there was to be no logs or records made of the accounts created for DOGE employees, who required the highest level of access,” Berulis wrote of their instructions after that meeting.

How can this be true?

> How can this be true?

What exactly sounds unbelievable? Considering Berulis was an administrator and DOGE requested administrator accounts, they'd both have the ability to turn on/off logging as they wish, wouldn't they?

I mean, from a legal point of view?
>"Look," he says, "I'm sorry for reminding you of this, but if we still had laws, the Mafia would be a criminal organization."

>"But we don't have laws," she says, "so it's just another chain."

  • eCa
  • ·
  • 1 day ago
  • ·
  • [ - ]
The US president was basically bragging on live TV the other day about disregarding a 9-0 supreme court verdict against his administration.

Following laws is not exactly of the highest priority.

If you mean "how can it be legal?", I'm not sure that matters if there is no one around to enforce the laws.
There is a small but significant chance that this whole admin's activities might be revealed without doubt as sponsored and facilitated by Russia. That may or may not result in a proper war with Russia. Either way, it would be scarily devastating.
> That may or may not result in a proper war with Russia

How? The people who would need to declare war are the ones compromised. Are we still holding out hope that there's some sanity in the government's leadership, or that there's some sort of accountability to be had?

It just comes down to popular sentiment. if it pisses of the american people enough, then it will be similar to the Iraq war in terms of almost everyone in congress supporting a declaration of war.

I get what you're saying, but I like to think there are at least a majority in the US military that would desire a war in such a situation. So long as the evidence is indisputable, like Putin himself declaring what he did.

This needs to be investigated by a mainstream outlet like 60 Minutes.
I just sent it to them and I urge everyone else to do the same.
Why isn't Russia using a compromised US IP ? That shouldn't be hard to get.
  • elaus
  • ·
  • 1 day ago
  • ·
  • [ - ]
They probably do, but those instances are not noticed and therefore don't make the news.
Maybe it's someone in the US trying to trick people into thinking it was Russia who did it.
  • q3k
  • ·
  • 1 day ago
  • ·
  • [ - ]
My guess is that someone attempted to log in over Tor and they got unlucky with a Russian exit node.

Or maybe I'm giving this situation too much credit and we should call a spade by its name.

They’re bragging.
Yeah, I think this should be seriously investigated, but that detail struck me as not making sense.
  • freen
  • ·
  • 1 day ago
  • ·
  • [ - ]
They didn’t think they even needed to do that.

The door is supposed to be completely open.

I saw this around 9:15am eastern time. By 9:45am it is no longer on 1, 2 or 3rd page of HN. Why?
Ask yourself who runs this web site.
I am Dutch and know of at least one pretty harsh lawsuit against a former employee of Tesla with autism against Tesla in the Netherlands regarding the work environment, sooo...

Also baffled they can still do shit like this with Senate and Congress looking the other way...

i continue to be amazed by the l33t h4x0rs who are caught because they forgot they have russian ips
Generally, yes.

But, in this case, they have Musk's bank accounts and POTUS covering for them, so why bother with different IPs?

  • bix6
  • ·
  • 1 day ago
  • ·
  • [ - ]
Let’s give them the benefit of the doubt here.

DOGE needed to hide its activities while it collected data for the president so that the private citizens chosen by his associates can run analytics on it offsite and decide which cases to pursue. And Russia has a login because they are friendly to the new era of American interests.

It sounds so stupid, I can’t believe people still support this madness…

It's all terrible, but it pales in comparison to the fact that the government can now disappear people to a gulag in El Salvador with no due process. I know that comparative suffering isn't a good litmus test for one situation vs another, but I'll take my data being stolen over a life sentence in an offshore prison without a trial any day of the week.
Unless the stolen data is being used to compile lists of enemies of the state to send to the gulag. Like are any of these troublesome trade unionists immigrants? Time to send them to the gulag, solves two problems at one - that’s efficiency!
Fun fact to consider: when you apply for citizenship, you have to list which organizations you're a member of on the form you submit to USCIS. This includes trade unions and political parties and such. Failure to complete that form truthfully is potential grounds for denaturalization in the future (on the basis that citizenship was obtained through fraud and thus was never valid). Given that this administration has already talked about denaturalization a lot, I wouldn't put it past them to cross-reference those forms with any databases they can get their hands on.
Unfortunately close to a new lawsuit where a H1B employee at Tesla reported a serious safety issue and Musk allegedly threatened to deport her entire team..

> About a decade ago, engineer Cristina Balan called out a safety concern about a design flaw on a Tesla vehicle. Shortly after, Balan says she was forced to resign. Now, she's explaining the leverage Tesla allegedly used to get her signature.

> At Tesla CEO Elon Musk's own request, Balan went straight to the top to solve a problem in 2014, which involved floor mats in the Model S curling near the pedals, affecting braking. But instead of being granted a meeting with Musk, "HR and the legal department had another plan for me," Balan said in an interview with Times Radio over the weekend.

> "They told me that if I'm not resigning on the spot, they will deport my entire team…because the entire interior team was backing me up," said Balan, who is from Romania and has said many of her team members were waiting on green card applications. "And their plan—Tesla's plan and legal department plan—was to convince the entire team and myself to close the internal investigation that we opened in the company to fix a serious safety issue." Notably, Tesla has been among the leading employers of H-1B visa holders, who perform work in specialty occupations.

https://www.chron.com/culture/article/tesla-engineer-deporta...

  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
More evidence for the idea that H-1B visas are abusive, the tying of a work permit to a particular employer.
Yeah but these things are not unrelated. This whistleblower is now risking being disappeared, and that will affect the calculations of all the other people considering blowing the whistle on the many other baldly illegal things this administration is doing.

The fear is the point.

You think these aren't related? There are quotas to fill in El Salvador...

Also, one illegal act doesn't excuse another. It's important to not willfully move the overton window over even more.

>>It's all terrible, but it pales in comparison to the fact that the government can now disappear people to a gulag in El Salvador

90% of people who were sent to the gulags survived and came back. This is much, much worse.

>90% of people who were sent to the gulags survived and came back

You can survive brutal conditions, but you won't be the same after. And that 10% is like a million and a half of people.

Please don't trivialize suffering of people.

Saying that El Salvador prisons are worse than gulags trivializes suffering? What an odd accusation.
Musk is heavily anti Union. He’s running DOGE. They exfiltrated highly confidential data from the National Labor Relations Board, which oversees things like labor disputes.

This is all under the auspices of Trump, which is figuring out how to get away with ‘deporting’ US citizens to El Salvador without due process.

Connected the dots yet? How long do you think until union organizers are getting black-bagged in the middle of the night and disappeared to El Salvador? A month? Less?

> the government can now disappear people to a gulag in El Salvador with no due process

To be wafer-thin fair to Trump et al, that was started by Bush with Guantanamo.

It's almost like all those people who said the federal government's post 9/11 power grabs set a bad precedent and moved us incrementally further down various slippery slopes were right.
It seems they’ve learned their lessons on Guantanamo: That was too much hassle with the legal battles so now they just cut them loose with a shoulder shrug and a “no jurisdiction” fig leaf.
  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
This is true, important, and it's also important to recognize how long it was left open by both sides. "Imperial rebound" is very real. If you create a special extra-legal space which allows you to abuse people, it will expand.
Which is exactly why a lot of us thought that was a really bad idea at the time.
First they came for enemy combatants, called them terrorists, shipped them to a torture prison abroad, stripped of all rights and still keep some there despite not having them convicted. But I'm not an enemy combatant, so I didn't care.

Then they care for immigrants, called them enemy aliens, shipped them to a torture prison, stripped them of all rights despite not having anybody convicted, but I'm not an immigrant, so I don't care.

<--- you are here right now -->

  • ·
  • 1 day ago
  • ·
  • [ - ]
On the gripping hand, just because Bush, our greatest war criminal (derogatory), did something doesn't mean that Trump should. If anything, he should have learned why it's a bad idea.
The point is that what we're witnessing is the logical end result of the preceding decades of giving the federal executive more and more unchecked power (it didn't start with Bush, either).

Trump is indeed uniquely bad in many ways, but the reason why he can do so much damage is because he was given access to the tools accumulated by previous presidential administrations.

I hope that we'll learn our lesson once this is over. But I'm also skeptical.

Sorry, I don’t follow? Why did it need to hide its activities to run analytics? What statistical analytical purpose is served by wiping logs and removing logging?

Since we’re spitballing, Why not try giving them the opposite of benefit of doubt, as well? Something like, the administration is clearly compromised by Russia and hired a bunch of low status hackers, and we’re seeing massive bombs being dropped all over our cybersecurity defenses?

We really need to come up with a commonly understood "sarcasm" character that doesn't also ruin the intended statement.
I'm pretty sure that was /s
at what point does it make sense to say “maybe you don’t deserve the benefit of the doubt” because it sincerely feels well past that point by all measures.
I read that comment as a steelman of the position that this is genuine anti-corruption activity, and pointing out via doing so that even if you give them an incredibly unwarranted amount of good faith, it still doesn’t make any remote amount of sense.
perfectly reasonable read of it, honestly. i think i'm just very tired by all of this.
> at what point does it make sense to say “maybe you don’t deserve the benefit of the doubt”

Eh. June 2018.

With everything that's going on now, explicitly adding /s helps a lot. Because I've seen worse takes written seriously...
Yeah I've seen a few HN people try and defend undefensible things, citing they are "steelmanning"... but nobody asked them to. Same with "playing devil's advocate". It's fine in philosophical debates I suppose, but it's not necessary in a lot of cases.

Second, if you are the "playing devil's advocate" type, make sure your post contains your real, own, personal opinion. You can't just go say morally objectionable things and brush it off as that.

Move fast, break things
Move fast and break unions.
While bad in sensitive systems, breaking things seems preferable to blatantly giving account information to another country.

> There were more than 20 such attempts, and what is particularly concerning is that many of these login attempts occurred within 15 minutes of the accounts being created by DOGE engineers.

Omg he only screenshot middle of screen, he didn't leak whole Powershell scripts DOGE buffoons ran, right?
Could someone outline the implications of this?
The whole thing reeks of a ploy to undermine the government for oligarchic interests, including selling it out to Russia: https://economictimes.indiatimes.com/news/international/us/d...
  • zakki
  • ·
  • 1 day ago
  • ·
  • [ - ]
If Russia accessing US data using Russia IP, that is weird. I mean why don't Russia use let's say TOR network?
Why would they even care. There will be no consequences for getting caught.
It depends, no consequences is one thing and not being detected at all is another.
It's kind of like Russians throwing their oligarchs out of windows and then saying it's suicide: everybody knows who did it, and there won't be consequences. That in itself sends a signal: 'we can do this, what are you going to do about it? Nothing.'
I feel like "Being detected, making it obvious and still no consequences" is the Russian playbook, if we look at previous instances. It seems to be on purpose as far as I can tell.
This.

Trump will pardon anyone on his team.

The existence of Presidential pardons is a disgrace. There is no pretence of the rule of law.

Presidential pardons were a crucial check on the power of the courts. The Constitution was written to curb excesses of 18th century England.

I'd say we didn't use them nearly enough. And now they're being used exclusively for crime. Yet another sound idea turned against us. There just isn't any way to govern a nation which has a majority in favor of destroying democracy.

You mean, his friends and the top levels

Make no mistake the 'kids' in doge will be the first to be thrown under the bus

Who said it was Russia?

The article only mentions a Russian IP.

  • freen
  • ·
  • 1 day ago
  • ·
  • [ - ]
Yeah, well, then DOGE employees are routing all of their traffic through Russia?

That’s a great idea!

so we would be busy arguing about the meaning, while they do something obviously terrible again
In this specific case, I think it's more likely that they want a return to these good times: https://en.wikipedia.org/wiki/List_of_worker_deaths_in_Unite...
Selling out to Russia by checks notes running a docker container
You can ship a lot of things in a container, especially in air gapped environments, including very malicious things.
it's beautiful
[flagged]
This is not about cyber security, this is about getting union activity data to the oligarchs. Russian IP's are a useful, probably unintentional, nugget that distracts people from what happened here.

Labor actions is the most powerful tool that ordinary people have and this is an effort to take that away. Citizens are already being kidnapped. Dissenter legal immigrants are being dissappeared.

Anyone that believes the administration is doing any business other than seizing more power is a useful tool.

It is also about cyber security. These people were following pretty good practices for what I'm guessing was a shoestring budget. Having this as a potential threat model is enlightening.

Edit: but yes, that is a bit in the noise compared to the attempt to end democracy in the us that is underway. If some combination of protests and judicial action manage to wake up congress to act for country instead of party, maybe we could use the momentum to do something good. I'd recommend closing the attack vector in our electoral system that creates two parties that can be so easily polarized against each other. Ranked choice voting and proportional representation or mmp for both house and electoral college would probably generate 4-8 parties and wouldn't require any amendments. Just 60 votes to allow the pr/mmp and then the hard part of convincing all the states to implement it in unison rather than delay to give their dominant party advantage.

@dang what happened to this post? It was at the top like 30 mins ago and now it seems shadow-banned.
It was flagged by community members and downweighted (correctly) by a moderator for being a dupe:

Whistleblower details how DOGE may have taken sensitive NLRB datahttps://news.ycombinator.com/item?id=43691142

1139 points/7 days ago/528 comments

  • mfkp
  • ·
  • 1 day ago
  • ·
  • [ - ]
It's a separate writeup by a separate author though, and with 500+ comments, it still seems relevant. From #1 on HN to completely disappeared. Bring it back, I say.
  • dang
  • ·
  • 1 day ago
  • ·
  • [ - ]
On HN, dupeness is more a question of whether the underlying story is substantively the same or not—or, to put it slightly differently, whether the follow-up submission is able to support a substantively different discussion or not.

In this case, the answers appear to be yes, it's substantively the same story, and no, it can't support a substantively different discussion than the previous major thread. That's why we'd treat the follow-up submission as a dupe.

This is in no way passing judgment about the importance of the story! It's just that if we weren't careful and proactive about moderating HN in this way, the frontpage would rapidly fill up with variations on the hottest stories of the moment, and avoiding repetition is a core principle here (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...).

I wrote a long explanation about exactly this the other day—if you (or anyone) is willing to take a look at that (assuming you have the stamina) and still have a question that isn't already answered there, I'd be happy to take a crack at it: https://news.ycombinator.com/item?id=43738815.

p.s. The current case is unfortunate because the follow-up/duplicate post came a week later than the original thread. If it were hours later, or a day or two later, as is more typical, we would merge the threads and in this way avoid a split discussion. But 7 days is too wide a chasm to merge across.

  • mfkp
  • ·
  • 1 day ago
  • ·
  • [ - ]
I suppose it's just a bit frustrating that HN is one of the few places left on the internet where we can have a mostly civilized discussion about politics. I had missed the discussion from 7 days ago so this was news to me (and I'm sure most of the other commenters). If you miss the one chance to discuss that one topic, it can never be discussed again on HN.

I'm not opposed to this rule for moderation, and I understand the reasoning behind it. But it seems like we're just watching the country burn and when stories like this get suppressed to make room for a new rust package manager, it makes me all nihilistic.

/rant

As one who shares your frustrations: working with the HN system, and pushing back where you feel it's appropriate, are both productive.

Dang (and earlier pg and sctb, and now I suspect tomhow) often express frustrations with the HN community's collective behaviour (a recent example: <https://news.ycombinator.com/item?id=43477305>). A key consideration is the fragility of the community and service itself (socially, not technically), as evidenced by, say, <https://news.ycombinator.com/item?id=23047709>, and even more revealingly here: <https://news.ycombinator.com/item?id=22805993>.

Your argument is likely not with their beliefs or preferences, but the embodied practices of HN moderation. Which can themselves be problematic as they have a strong status quo bias, as I've pointed out repeatedly:

<https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...>.

Which often manifests as tone policing, as again I've commented (some overlap with above search):

<https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...>

Consider reversing that bias a hacking challenge.

For what it's worth: if it's one of the few places you can still have a civilized discussion about politics, that's at least in part because we don't talk about politics very often here. Every time we do, some of the civility of the site chips away. Since the whole premise of the site is to investigate how long we can stave off Eternal September, this seems an important consideration.
  • dang
  • ·
  • 1 day ago
  • ·
  • [ - ]
> it can never be discussed again on HN

For sure it can, if and when significant new information arises. That's the main point of the principles outlined at https://news.ycombinator.com/item?id=43738815.

But yes, I hear you and I know it's frustrating. There's no important topic that HN really does justice to.

Hard to see how this whole fiasco won't end up in charges at very least for negligence. Easy to see why leadership is signaling they have nothing to do with DOGE but are letting their engineers take the heat
Nothing will happen here until the MAGA movement is destroyed. We are a degraded cluster with 2 of 3 nodes down (executive and legislative). Judiciary is holding on ... but they don't have much power to actually enforce anything.

So this type of behavior will continue unmitigated for at least the next 1,369 days.

anyone else getting a 403 on that link?
DOGE seems to be on a bit of a crime spree.
  • skc
  • ·
  • 1 day ago
  • ·
  • [ - ]
It's darkly humorous how conservative politicians keep gaslighting people by stating that this was the mandate of the people.
Yes, humor is essentially surprise, and this is a surprise!
I mean, just, Devil's Advocate, but it kind of was the consensus will of the people that voted. And we live in a democracy, so the people who didn't vote don't count.

That's the beautiful thing about democracy, you get exactly the government that you deserve.

Now I think about it, that can also be the terrifying thing about democracy as well, but you get the idea.

You deserve no better, nor any worse, than what you have.

This is a common refrain but logically empty. It implies, for example, that the minority deserves any hypothetical persecution by the majority simply for being fewer in number at the ballot box. Failing to convince the majority that your rights matter doesn't mean you deserve to be punished.
> so the people who didn't vote don't count

Democracy is about how the people (demos) in a state or other community coexist by negotiating their individual and collective needs and priorities. Reducing it down to "you didn't vote so you don't count", or worse still, "you voted for the losing side so you don't count" is a gross distortion. Its not just about the vote, its what happens after that.

> That's the beautiful thing about democracy, you get exactly the government that you deserve.

This makes no sense. There isn't something out there that renders a singular judgement on what people deserve. There's only us.

> consensus

No, it wasn't. It was what about half voted for. There was no consensus. Consensus means general agreement, not a small majority.

That they're elected by majority (never mind the indirections) is a key reason why it is important that the executive is not allowed to wield too much power unilaterally.

(And a key reason why the executive in most countries have far less power than a US president...)

Maybe in a perfectly functioning democracy, but the U.S. has been actively separating policy from politics maybe for my entire lifetime. Just for starters:

* The two-party system dominates the process, and actively excludes 3rd parties. Look into changing requirements for debate participation.

* The Democratic party argued in court that they have no obligation to use a "fair" primary to select candidates. This was in response to a lawsuit from donors claiming the party mislead them by tipping the scales against Bernie Sanders in 2016.

* Gerrymandering continues to enable parties to win large majorities in state legislatures while losing the popular vote at the state level.

* Many of our current troubles have been caused by the Supreme Court, which is not democratically elected.

* The Electoral College and Senate apportionment continue to give more power to voters in low-population states.

Everything you’ve listed here was a choice made ultimately via the process of following democratic procedures. Everything you listed can also be undone via democratic procedure. That we don’t use this democratic procedures to undo these structural impediments to fairness is a choice. A democratic choice that we make.

How, exactly, are our choices suddenly the fault of the democratic system?

Are you arguing that since voters elect representatives, voters are ultimately responsible for everything those representatives do, even if it is contrary to the interests and desires of those who voted for them? If the process is flawed, are the results not also flawed? Unless we started with a perfect system, and voters clearly chose to make it less perfect. That doesn't match the history I know.
Ah yes, "democracy", voting once every 4 or 5 years and accepting whatever the government does because "we voted for them"... while disregarding 49% of the population (+ people who changed their mind) just "because". Some people have a really limited conception of democracy... You're electing representatives, not Lords and Kings lmao.

You're just a few steps away from a russian version of democracy if you define it so loosely in the first place

Hell no. A country in which the Citizens United decision is in effect is extremely less democratic than a country without such a corrupting influence in play.

"Now I think about it..." work on that some more going forward. The country is complicated and Democracy has grades. We're getting an F at the moment.

Sigh.

There are democratic procedures by which the people can go about changing citizens United. You apparently believe those procedures are not part of democracy, but they are.

That the people won’t take the decision, and implement the process to change citizens united, is the fault of the people, not of the democracy. Democracy simply provides the procedures. You make the decisions.

For instance, a lot of right wing people spent a lot of time stacking the court to do away with roe v wade. Democracy provided that possibility through procedures it put in place. That’s only one way to do away with citizens united. There are others. None of which you choose to avail yourself of. How is that the democracy’s fault?

When many people use the word "democracy" today, they're not referring to a system of government where laws reflect the will of the people as determined by votes. They're talking about Democracy, a civic religion where the rules match their own personal beliefs and the current-year beliefs of their class.

So in a Democracy, if the people vote for something different, that's anti-Democratic, and non-democratic methods may be required to fix Democracy.

Perhaps you'd like to put some more words in my mouth.

When I say Democracy, I mean a form of government in which political power is primarily seated within the common mass of people, as opposed to political power being with those who bribe, cheat, scheme, lie and bribe some more to achieve more political power than their fellow citizen. This tension puts democracy on a gradient, one which I believe is currently and firmly seated in corporate command of political power. I recommend you go read Democracy Incorporated to add a little more clarity and contrast to your world view.

Consider gerrymandering. It literally makes some votes count for less than others. Yet the only recourse is the courts, and if the courts are stacked, it means that minority elected by padding their votes in this manner can retain control despite will of the majority.
If you think the way Roe v. Wade was killed reflects democracy in action, I don't think we will ever see eye to eye. "Democracy provided that possibility," no Democracy as we implement it failed to resist the authoritarian attack built on broken oaths. Did you and I watch the same confirmation hearings? That wasn't democracy.

Next I suspect you'll try to tell me the Brooks Brothers riot was also "democratic procedures."

> None of which you choose to avail yourself of.

Oh piss off.

America doesn't live in a Democracy, it lives in a bipartisan and increasingly sectarian dissolution of Democracy originally based on gerrymandering, now based on establishing Unitary executive theory through force.

Red Team/Blue Team isn't Democracy, its Oligarchy with extra steps - self-evident by the recent actions of an ultra-wealthy elite to shape political decision-making in ways that increase their wealth.

You need only look as far as the inauguration of 47 to be slapped in the face by the audacity of it - flanked by the Railway Barons of Silicon Valley - Elon Musk, Jeff Bezos and Mark Zuckerberg - and bolstered by Tim Cook, Sam Altman, and Bernard Arnault.

The Fair Representation Act - which would solve a plethora of issues in one act - served to establish independent redistricting commissions in all states to prevent gerrymandering, whilst simultaneously introducing the proportional STV system of elections like we have in Ireland

https://en.wikipedia.org/wiki/Fair_Representation_Act_(Unite...

https://en.wikipedia.org/wiki/Single_transferable_vote

The “consensus” is built over more than a decade of misinformation
If enough people believe it, then you failed in your democratic duty to create an educational system that produces citizens able to separate fact from non fact. Relevance from irrelevance. And so on.

In a democracy, the educational system is a democratic practice. A civic duty. We could have changed our educational system to be better, we didn’t. That’s on us. We could change it now. We won’t. That’s a choice. A democratic choice.

The practice of democracy is not solely about voting. There are many democratic choices we make every day that concert to give us the government we deserve.

I’m sorry but in 2025 that type of thinking feels extremely naive. There is an education issue, but that’s such a detail compared to the level of propaganda, misinformation. People have been groomed by entire networks of misinformation for such a long time. It’s a complete take over of the democratic system, by nefarious actors, to their own benefit. Doing so fully in the open
The Russian IPs may also be a ploy by people at DOGE to cause doubt about the security of the NLRB to get play at a court in order to not disclose company secrets required for cases.

I guess DOGE wanted to write a report how they saw Russian IPs login in but it back fired because the people at NLRB have proof DOGE created the accounts.

EDIT: edited for clarity.

I do not understand why we should still give these people the benefit of doubt.

How many scandals we have to endure?

How many evil things need to be done?

How many people need to be unnecessarily fired?

Edit: the parent comment was edited

There is an easy (but maybe incorrect) answer. People who give benefit of doubt in the face of obvious bullshit excuse are simply okay with alleged things happening. A stronger version of this claim is -- such people don't believe the bullshit excuse at all and want alleged things to happen.
  • kubb
  • ·
  • 1 day ago
  • ·
  • [ - ]
There’s no limit. Everything Musk does can and will be given the benefit of the doubt.

It’s a matter of identity, he’s their guy and they stick to him through malpractice and treason.

The level of faith that there's in some of those communities is... Cultish.

These days I was reading on effective altruism, sbf, ftx debacle and macaskill influence on sbf. It's weird how long it is possible to go to justify someone's actions

  • kubb
  • ·
  • 1 day ago
  • ·
  • [ - ]
They’ll always stick to their team, no matter what. Anything else means losing.
And that's what scares me the most about those ideologies. With their p(doom) they basically say oh an infinite damage may happen! And to prevent an infinite damage, of course everything is allowed. And that absolutely doesn't bode well for democracy. And of course it goes well with the oligarchy at the silicon Valley because they see themselves as saviors
This is silicon valley and particularly Musk's logic put into practice in the government. Look at how they talk about driverless cars.

"Automobile deaths are bad and numerous, we want to get rid of them with driverless cars, which will kill people in the course of their development, but that's okay because remember we told you about the deaths we will prevent in the future? Therefore we can expend as many lives as we want now because by doing so we will save infinite lives. This is why we must be permitted to operate beta robots on public roads."

The rationale continues on to starship and neuralink. We have to go to Mars to save humanity, therefore you must tolerate starships exploding and destroying the ecosystem over your house. We have to invent this important medical device to save people, therefore we must conduct morally gray research on implanting devices into human brains. The justifications and rationalizations are endless.

And somehow, it's never - or always never - them those who have to bear the consequences of the hardships they cause to endure before we reach heaven

Paint me surprised

Radical utopians think the ends justifies the means. But the problem is, utopia never arrives, so we never get the ends, but we certainly get the means.

The same is (almost) true of radical anti-dystopians. The problem is that their p(doom) is... shall we say uncalibrated? It may be a case of tiger repellent. But while they're trying to prevent their "doom", the damage they do is real. And they're willing to do unlimited amounts of it, because doom is really bad.

The "almost" part is because doom is sometimes real. Hitler, for example, really happened. The problem is that in 1931, say, it wasn't obvious that Hitler was actually going to become what he became. (Yeah, I know, Mein Kampf had already been written. It wasn't obvious that Hitler was actually going to be able to pull any of it off.) So in 1931, what was p(doom)? The doom everyone was trying to avoid in 1931 was economic. They weren't worried about trivial (!) little problems like a guy with a funny mustache who once wrote a nasty book.

So the p(doom) crowd, even if they're right that doom is coming, still are often wrong about which doom is coming, and so their steps to avoid it are just causing damage, and not preventing doom at all.

"Everyone has a p(doom) until they get punched in the face"
> The problem is that in 1931, say, it wasn't obvious that Hitler was actually going to become what he became

1923 was the Beer Hall putsch. It was clear to those who knew what they were looking at and didn't agree with the goals.

In 2016 people predicted Trump wouldn't leave office peacefully, and they turned out to be right. But people said "no your p(doom) is too high, you're deranged." But they were not calculating p(doom) they were calculating p(doom | narcissistic psychopath). The posterior probability skyrockets when you factor in the person has the same personality disorder in leaders that has spelled doom countless times throughout history.

Hitler wasn't the first Hitler, people had seen his type before, and we will continue to see his type in the future. Know the signs, they're not hard to spot if you know what to look for. Pretty much if someone's main complaint is "those people" then you have a good idea what they're all about.

When they start calling "those people" murderers, drug dealers, rapists, terrorists, gang members, then it's a foregone conclusion what they're all about. Hitler told Germans who he was in 1920 when he started giving public speeches against Jews. Trump told us who he was in 2016 (and arguably for decades before). They had no excuses then, and we have no excuses this time. We see it coming.

But his suggestion that they're connecting from Russian IPs as a ploy to make the NLRB seem insecure with the plan of using that as a way to make it unable to prosecute cases, is that really giving them the benefit of the doubt?

Isn't that instead to suspect them of a nefarious plan to basically cripple labour law enforcement?

Rereading his comment, I think it has been edited and reframed in a more suspicious tone towards doge
Yeah, okay.
Cybersecurity is not my main field but this sounds beyond suspicious.

> Berulis [...] and his colleagues grew even more alarmed when they noticed nearly two dozen login attempts from a Russian Internet address (83.149.30,186) that presented valid login credentials for a DOGE employee account — one that had been created just minutes earlier. Berulis said those attempts were all blocked thanks to rules in place that prohibit logins from non-U.S. locations.

> “Whoever was attempting to log in was using one of the newly created accounts that were used in the other DOGE related activities and it appeared they had the correct username and password due to the authentication flow only stopping them due to our no-out-of-country logins policy activating,” Berulis wrote. “There were more than 20 such attempts, and what is particularly concerning is that many of these login attempts occurred within 15 minutes of the accounts being created by DOGE engineers.”

Somehow each paragraph reveals something even worse than the last.

> Berulis [...] and the associate CIO were informed that “instructions had come down to drop the US-CERT reporting and investigation and we were directed not to move forward or create an official report.” Berulis said it was at this point he decided to go public with his findings.

I think it's relevant context DOGE employees were very recently operating commercial web domains in Russia,

https://krebsonsecurity.com/2025/02/teen-on-musks-doge-team-...

- "“Tesla.Sexy LLC controls dozens of web domains, including at least two Russian-registered domains,” Wired reported. “One of those domains, which is still active, offers a service called Helfie, which is an AI bot for Discord servers targeting the Russian market. While the operation of a Russian website would not violate US sanctions preventing Americans doing business with Russian companies, it could potentially be a factor in a security clearance review.”"

edit: Here's the old HN thread,

https://news.ycombinator.com/item?id=42981756 ("Teen on Musk's DOGE team graduated from 'The Com' (krebsonsecurity.com)" — 1895 comments)

This administration colluding with Russia? I feel like we tried to get people to care about that before.
What is interesting to me is how those two things are mixing. Theoretically any one of us could own a russian domain and any one of us could get a job at NLRB (or another gov agency) but our jobs and our ownership of that domain are two entirely separate things.

What's interesting here is how these two things are seemingly mixing. At this point I have two pet theories:

- One of the DOGE staffers is a Russian agent: This one I'm putting in the camp of "highly highly unlikely" but still possible given those login attempts from Russia.

- The more likely theory is this is just some braindead attempt to "own the libs". If we look back 6-8 years to when all the Trump Russia stuff came out and turned into a nothingburger. This could be some idea like: "Yo I've got this VM in Russia, let's own the libs and make them thin the Russians are invading again!"

- It could also be completley innocouous. Like right now I have a Mullvad VPN setup on my machine that points to Algeria. Ubuntu will auto start this VPN at login. What if one of DOGE staffers just happened to have a VPN running with an exit in Russia when they tried logging in.

Especially how long does it take for them to get a non Russian ip
Russian IPs were in the pool because it never occurred to them to check where these IPs were geo registered
Yep, pretty much impossible to disentangle careless incompetence from malevolence with these goons.
Yup. That's what they're counting on.
Russian IPs are used, because russia won't help the american authorities with investigations. If I was an american and hacking into <whatever american thing>, I'd use russian IPs too.
Couldn't you route through a Russian IP for anonymity and then a US IP for access?
It's not anonymous if the US IP has a real life connection to you.
I think what the original commenter meant was a multi-hop setup like this:

You -> Russian IP -> US IP

then you'd get anonymity via the Russian hop but aren't geoblocked due to your final hop being in the US.

I'm sure there's at least one VPN service that has US IPs and takes Monero.
Mullvad
I'm almost certain US law enforcement, at least until recently, would've directly operated such a service.

In the same way that it's relatively easy to find a hitman on the dark web, it's considerably harder for them to actually not be law enforcement.

Which is fine for the attacker here. All they need is to hit the login endpoint from an IP that's geolocated to the US. They don't mind if it's possible to trace it to their Russian IP. And that's roughly all that the VPN service sees. I explicitly mentioned Monero because I believe that when used properly, it wouldn't add any extra information.
Or, very unlikely but maybe, the DOGE employee used this new account to attempt to login via a Russian VPN just to test security. Still very unlikely, because they were not interested in security at all.
DOGE's mission isn't pentesting though, there's other federal agencies for that, like the article mentions, US-CERT operated by Homeland Security.

Homeland Security and co need to step in, but they're controlled by hostile agents.

Haha, have you never worked with a prolific junior that wants power and openly questions everything you do, their role and any limitations you place on them. These kids won’t care it’s not their remit.
What is the procedure with such a hostile takeover then? Army or National Guards should intervene to re-instate national security.
Under whose authority? The president is still commander-in-chief, unless and until impeached
If the president is behind all that, there are proper command chains to deal with such a scenario. Democracy is about checks and balances. The US is by far not a democracy anymore, but still calls itself so.
The "proper chain" for this scenario is either Congress impeaching the president, or the vice president triggering the 25th Amendment.

Unfortunately, the Republicans in Congress refuse to do so and pretend that everything is fine, and the vice president is the president's lackey.

As far as I know, we don't have any other legal mechanisms to remove the president from his position as commander-in-chief. If you know of any, I'd love to hear more about them.

The article mentioned that traces of a few GitHub repos were found. One of the READMEs left behind described a tool used to create a multihop network to hide the original source.

Seems plausible that they could have used that tool when logging in and it happened to bounce off a Russian IP.

Maybe they successfully identified and blocked all the attacks from Russian IPs, but not the case of other attacks
> more than 20 such attempts

If I am testing a login I don't need 20+ failed attempts to know it's not working. Sometimes the simple answer is the correct one. The series of events does not read as someone, whose job has been reported to disable security and demand root access to systems, testing the already in place login system to make sure Russian IPs (specifically) can not log in.

Lets be honest: they are compromised. Musk is compromised. Trump is compromised. They are all traitors who are selling America out. It took almost four decades but Russia is winning the cold war after all, without firing a shot.
Yes, Trump is both bought by the Russians but also holding to sanctions that cost Russia billions a year. Definite 4D chess move.
  • lukan
  • ·
  • 1 day ago
  • ·
  • [ - ]
Well, it cannot be too obvious, obviously.

Are you aware of the "krasnow" theory?

I see no proof there, but indeed strong indications to seriously look into it.

Trump is trying to get the sanctions lifted. Give him time.

https://www.reuters.com/world/white-house-seeks-plan-possibl...

He does owe Russia for the email hack and leaks that he publicly requested. Not to mention sticking it to Ukraine after they didn't find/fabricate evidence against the Biden family.

I want to know why your comment isn’t flagged but any dissenting opinion or question from yours will be…. Is that in alignment with American values? Hmm…
  • lukan
  • ·
  • 1 day ago
  • ·
  • [ - ]
If the US government would be under russian control, exposing it would likely align with american values.

Also I see no flagged other comment and some people just downvote downvotecommentors.

Freedom of Speech is freedom from the government regulating speech. No one has a constitutional right to fkup a message board with propaganda.

It is unconstitutional when the government does it, like say a president who requires unapproved language be scrubbed from public government sites.

[dead]
This sounds very weird.

If you're blocking non-US IPs, you trpically block at the IP layer, before a login attempt can even begin.

Why allow someone to even log in at all?

If the intent is to collect foreign IPs attempting login - you could block it down the chain. Lots of intelligence reasons to do this.
If you block outright an adversary has reason to try another IP. If you allow the attempt then show a standard "login failed" page they have less information to go on.
Not necessarily. One could have a gov site allowing anyone to view it, but have stricter rules on a /login path, HTTP POST, auth header, or it could have been blocked by some compny-wide safety layer that manages this stuff semi-automatically. But that's just a speculation.
maybe to detect that the valid credentials are leaked / used in the wilds?
Exactly; a valid login attempt from abroad should trigger an immediate account lock and credentials reset for sensitive systems like this.
Auth providers (like Okta for example) often do the geo-blocking at level 7 -- because if you know the login being used, you can then lock the account that is being accessed from a blocked region.
Remember these are elons are script kiddie hackers, it only occurred to disable the outer firewall, azure ad will independently geoip block all by itself
So the default behavior of a Fortigate is to allow you to apply an access policy to the VPN tunnel itself, which can easily be a geoblock, but the local-in policy where the remote is actually authenticating against the firewall is much harder to change.

Not saying this is a Fortigate or that the federal government didn't change the low effort configuration, but it's certainly not unusual, Fortinet is a huge presence.

or person forgot to switch of the vpn
What's the typical use case for a DOGE employee to have a Russian VPN setup on their work PC?
Logging on to their work account.
I can come with at least three:

- forgetting to take anti-paranoia pills

- doing it on purpose to "own the libs"

- doing it on purpose out of curiosity as to how stupid the adults can be in configuring a sensitive system

Totally an honest mistake! It’s ok because the stakes are really low; not like it’s the US government!
BigBalls has three whole years of experience as a script kiddie. He's got this.
  • ·
  • 1 day ago
  • ·
  • [ - ]
  • ·
  • 1 day ago
  • ·
  • [ - ]
  • ·
  • 1 day ago
  • ·
  • [ - ]
At this point, the number of probable explanations for antics DOGE in particular and the administration in general are close to zero.

One somewhat far fetched(till recently) explanation floated for the all out war on institutions waged by the Trump administration is that the goal is to destroy the last remaining entity in this country that is capable of standing up to corporations. The idea seemed laughable just a couple of months back. The fact that it seems very probable now shows just how bad the situation is.

At what point will Congress act? Or will they simply sit by as the country is destroyed from the inside?

  • rq1
  • ·
  • 1 day ago
  • ·
  • [ - ]
Another masterclass from the DODGY department.
How do you stop kleptocracy from destroying democracy? The USA is an authoritarian country de facto now, though there should be a lot of rail-guards, which should prevent this from happening ... Nobody cares?
Protest non violently in large numbers. We're still a country of people.

If 3.5% of protested then historically, that could motivate change, per

> based on the research of political scientist Erica Chenoweth

Protests need to be disruptive in some way to be effective, not just performative. Marching with banners doesn't do anything because, well, why should they care?
  • pjc50
  • ·
  • 1 day ago
  • ·
  • [ - ]
People want it as long as it's used against their enemies. The "anti-woke" propaganda, and the anti-immigrant propaganda, have been incredibly effective. People are demanding a police state so it can be used against "MS-13".
Influence is the enemy.

While we should not elect influential people, we want persuasive, charismatic people in office. Catch 22. But I much prefer presidential candidates I'd never heard of before the campaign cycle began to any celebrity.

But putting someone massively influential in the executive branch, so influential that they've negated the entire legislative branch, has crippled our guard-rails / checks and balances.

Just about every Republican member of congress cares more about what Trump will do if they do not fall in line. To be sure, the overall issue of partisanship does cross the aisle, and has been an issue for decades. But being quite so beholden to the President over constitutional rules and law is largely a new and devastating phenomena.

We can't stop it. All we can do is try to stay alive until they are satisfied they have extracted everything of value, and then rebuild from whatever is left.
We can stop it.

Increasingly it appears, we are the only ones who will, also.

We have to group together so that we are a recognizable entity. We.

According to political science, historically 3.5% of the population protesting non violently is a big enough we.

This was on the front page and mysteriously dropped off. I don't know the mechanism for this so it is most likely innocent and the system working as planned but I do find it odd that every post critical of the Trump administration gets flagged or gets dropped off the front page.
very odd indeed - some insight from the moderators would be appreciated.
  • freen
  • ·
  • 1 day ago
  • ·
  • [ - ]
Lots of government employees are committing real-deal, federal penitentiary crimes here. While Trump is in power, they won’t be convicted, much less investigated.

How much incentive do they have to continue to commit as much crime as possible in order to keep Trump in power?

Every single story you read about these sorts of things os not only a horrible violation of constitutional rights and the rule of law, it is the creation of an army of incredibly dangerous people who desperately want trump to remain in power and can commit crimes with impunity in order to keep him there.

  • freen
  • ·
  • 10 hours ago
  • ·
  • [ - ]
I guess you are in favor of incarcerating people convicted of marijuana possession?

That’s the overwhelming bulk of those pardons.

The other folks are people that Trump said should be in jail and/or summarily executed.

[dead]
  • ·
  • 1 day ago
  • ·
  • [ - ]
[dead]
[flagged]
Maybe adding a tariff for our comments and upvotes would solve the problem? Premium bandwidth tariffs since these bytes crossed the Atlantic to reach you.
US Politics is World Politics. Almost everything we do immediately effects the rest of the world. They have a vested interest in our governance, or lack there of.
Agree. Free speech is only reserved for non-biased US politics content.
One thing you can do is not sleep. Sleeping is totally in your hands and you can fix that
This is clearly relevant to HN (cybersecurity) and seems like a very straight-news recitation of the facts to me. Where do you see bias? It is not "biased" simply to report on what the government is doing.
No. That is not how Hacker News does things.
Actually it kind of is. View the "active" page to see.

Here are some recent HN posts that have been flagged into oblivion:

>Dow Headed for Worst April Since 1932 as Investors Send 'No Confidence' Signal (wsj.com)

>Trump's Fed Attacks, Trade War Push World to Sell Off US Assets (bloomberg.com)

>White House plagued by Signal controversy as Pentagon in "full-blown meltdown" (arstechnica.com)

>An Age of Extinction Is Coming. Here's how to survive. (nytimes.com)

>The Crypto Con: How Trump Is Looting America from the Oval Office (mitchthelawyer.substack.com)

>RFK Jr.'s autism study to amass medical records of many Americans (cbsnews.com)

HN is its community, and the community is speaking loud and clear about its allegiance.

> HN is its community, and the community is speaking loud and clear about its allegiance.

This seems to be over-simplifying. Flagging only requires some flat amount of flags for a post to be [flagged], meaning a small minority can shut down discussion on these topics even if some small subset of that minority is flagging a given post. The first tracks with all of the posts being flagged and the second tracks with moderator claims (which I personally believe) that there is not an obvious brigade of users doing the flagging.

Regardless of all of the posts being flagged, there seem to be many still who find them and think they should not have been flagged. That suggests to me that there is a sizeable portion of the community with either a more friendly allegiance or none at all.

I move past, and don't click on, articles I don't care about all the time. That approach takes a lot less time/effort than it does to click on them and post something about it. Doing that also means that they leave my mind almost instantaneously, rather than sticking around in my head after having thought about what to say.

Downvote and move on.

Something needs to be done about Trump apologists flagging non-political articles that discuss technical issues relevant to this community.
People on the east coast have been up for several hours. I am in California and have been up for an hour already.

What a weird complaint.

How dare people think the wrong way and not in the way that Dear Leader sanctioned!
[dead]
[flagged]
Lets give some benefit of doubt to this fellow with a russian wife https://krebsonsecurity.com/2025/03/who-is-the-doge-and-x-te...
  • e2le
  • ·
  • 1 day ago
  • ·
  • [ - ]
Perhaps I'm misunderstanding something but this could just mean their own equipment is compromised in some way. I wouldn't be surprised if they were using personal computers to conduct their work and downloading/executing any software they find on GitHub without regard for malicious code or supply chain attacks.
What could the Russians possibly offer Musk that he would work for them?

It's much more likely that these guys were either using a Russian VPN, or one or more of their devices were compromised.

No it is not. All it says is that they appear to not be careful enough in what they do. Maybe even childish.
Going by Occam's Razor, you'd be correct. The scenario with the least assumptions is the DOGE people are using personal devices too much, one of which had already been compromised. Which makes sense from Russian intelligence's point of view: people who ignore security because it slows them down are easier targets, and people with credentials to multiple systems are more valuable targets. They wouldn't be able to resist when those are the same people.
I think you could go the other way with Occam's Razor here. If you observe an extremely Russia-friendly administration coming in and meticulously dismantling American soft power around the world, I think to say that there's no connection would be reaching.
It seemed to me that when trying to log back in they bounced through a Russian vpn to be able to have a mildly plausible explanation. But yeah, your story is simpler and even more disturbing.
Or use a vpn.
We can debate the finer points of intent. The situation is that whoever put them there is fine with the current risk of Russian (or whoever, seems to be a party going on) infiltration.
Ignorance is not a defence. Unwilling accomplices are still accomplices. But nothing will happen to them. The reign of the oligarchy is bearing down fast.
I'm confused, are they Russian agents or wannabe oligopolists? Presumably it can't be both, as being part of the American oligopoly in an America that is subservient to Russia seems hardly worthwhile.
Nobody mentioned about subservience, simply incompetance, if contractor X is given a DOGE superuser account, while also having his entire network compromised, there is some responsibility on you for that.

My oligarchy comment stems from the fact that one of the largest private company owners in the US is seemingly allowed to take all of this potentially rival information at will, without even having to inform anyone what exactly they want to look at.

All because he's friends with the president, to me thats an oligarchy.

This entire subthread is about Musk et all "work for Moscow".

I guess I was also taking issue with your assertion that "unwitting accomplices are still accomplices", as that is generally not how it is viewed by courts of law or reasonable people.

Hmm, I’m not going to say musk is working with Russia or not, that’s a whole political thing that’s all opinion based until there are facts of course, but as for your view of the court system, INAL but there is “Federal Tort Act” that says you can sue the government for negligence but to be honest you’re probably right, nothing will happen anyway.
  • ·
  • 1 day ago
  • ·
  • [ - ]
When this story first broke, my initial thought was that Elon was using this unprecedented and probably illegal access to access case data to benefit his companies and possibly others [1], most specifically for Tesla where unionization remains a threat to profits [2].

I don't know what the Russia connection is. Blue MAGA types like to contend that Trump is a Russian asset. There are definitely some weird connections going back to Trump purchasing TVs for a hotel in the 1980s [3] and some weird timings of the movements of Viktor Orban between Putin and Trump [4] but I just don't buy the Russian asset narrative.

I consider it way more likely that individual DOGE people have been compromised by foreign actors and possibly without their knowedge (eg compromised email or computers).

We're only 3 months into this. The amount of damage that is going to be done over the next 4 years is hard to comprehend.

[1]: https://news.ycombinator.com/item?id=43701222

[2]: https://www.businessinsider.com/tesla-pay-vs-ford-gm-uaw-uni...

[3]: https://www.youtube.com/watch?v=O1FHtBu5H8w&t=36s

[4]: https://www.axios.com/2024/07/12/trump-orban-meeting-mar-a-l...

America is being hacked by Russians while the authorities are watching, and nobody is doing anything to prevent it. Trump is obviously more involved in Russia's "greatness" than America's. It seems the cloud data nightmare - "[...] What if Adolf Hitler had access to all the data that is available today [...]" - is coming true. Perhaps we are witnessing the beginning of the end of "all things cloud."