Programmer, editor, tinkerer.
69 stories
·
0 followers

DOGE as a National Cyberattack

3 Comments and 8 Shares

In the span of just weeks, the US government has experienced what may be the most consequential security breach in its history—not through a sophisticated cyberattack or an act of foreign espionage, but through official orders by a billionaire with a poorly defined government role. And the implications for national security are profound.

First, it was reported that people associated with the newly created Department of Government Efficiency (DOGE) had accessed the US Treasury computer system, giving them the ability to collect data on and potentially control the department’s roughly $5.45 trillion in annual federal payments.

Then, we learned that uncleared DOGE personnel had gained access to classified data from the US Agency for International Development, possibly copying it onto their own systems. Next, the Office of Personnel Management—which holds detailed personal data on millions of federal employees, including those with security clearances—was compromised. After that, Medicaid and Medicare records were compromised.

Meanwhile, only partially redacted names of CIA employees were sent over an unclassified email account. DOGE personnel are also reported to be feeding Education Department data into artificial intelligence software, and they have also started working at the Department of Energy.

This story is moving very fast. On Feb. 8, a federal judge blocked the DOGE team from accessing the Treasury Department systems any further. But given that DOGE workers have already copied data and possibly installed and modified software, it’s unclear how this fixes anything.

In any case, breaches of other critical government systems are likely to follow unless federal employees stand firm on the protocols protecting national security.

 

The systems that DOGE is accessing are not esoteric pieces of our nation’s infrastructure—they are the sinews of government.

For example, the Treasury Department systems contain the technical blueprints for how the federal government moves money, while the Office of Personnel Management (OPM) network contains information on who and what organizations the government employs and contracts with.

What makes this situation unprecedented isn’t just the scope, but also the method of attack. Foreign adversaries typically spend years attempting to penetrate government systems such as these, using stealth to avoid being seen and carefully hiding any tells or tracks. The Chinese government’s 2015 breach of OPM was a significant US security failure, and it illustrated how personnel data could be used to identify intelligence officers and compromise national security.

In this case, external operators with limited experience and minimal oversight are doing their work in plain sight and under massive public scrutiny: gaining the highest levels of administrative access and making changes to the United States’ most sensitive networks, potentially introducing new security vulnerabilities in the process.

But the most alarming aspect isn’t just the access being granted. It’s the systematic dismantling of security measures that would detect and prevent misuse—including standard incident response protocols, auditing, and change-tracking mechanisms—by removing the career officials in charge of those security measures and replacing them with inexperienced operators.

The Treasury’s computer systems have such an impact on national security that they were designed with the same principle that guides nuclear launch protocols: No single person should have unlimited power. Just as launching a nuclear missile requires two separate officers turning their keys simultaneously, making changes to critical financial systems traditionally requires multiple authorized personnel working in concert.

This approach, known as “separation of duties,” isn’t just bureaucratic red tape; it’s a fundamental security principle as old as banking itself. When your local bank processes a large transfer, it requires two different employees to verify the transaction. When a company issues a major financial report, separate teams must review and approve it. These aren’t just formalities—they’re essential safeguards against corruption and error. These measures have been bypassed or ignored. It’s as if someone found a way to rob Fort Knox by simply declaring that the new official policy is to fire all the guards and allow unescorted visits to the vault.

The implications for national security are staggering. Sen. Ron Wyden said his office had learned that the attackers gained privileges that allow them to modify core programs in Treasury Department computers that verify federal payments, access encrypted keys that secure financial transactions, and alter audit logs that record system changes. Over at OPM, reports indicate that individuals associated with DOGE connected an unauthorized server into the network. They are also reportedly training AI software on all of this sensitive data.

This is much more critical than the initial unauthorized access. These new servers have unknown capabilities and configurations, and there’s no evidence that this new code has gone through any rigorous security testing protocols. The AIs being trained are certainly not secure enough for this kind of data. All are ideal targets for any adversary, foreign or domestic, also seeking access to federal data.

There’s a reason why every modification—hardware or software—to these systems goes through a complex planning process and includes sophisticated access-control mechanisms. The national security crisis is that these systems are now much more vulnerable to dangerous attacks at the same time that the legitimate system administrators trained to protect them have been locked out.

By modifying core systems, the attackers have not only compromised current operations, but have also left behind vulnerabilities that could be exploited in future attacks—giving adversaries such as Russia and China an unprecedented opportunity. These countries have long targeted these systems. And they don’t just want to gather intelligence—they also want to understand how to disrupt these systems in a crisis.

Now, the technical details of how these systems operate, their security protocols, and their vulnerabilities are now potentially exposed to unknown parties without any of the usual safeguards. Instead of having to breach heavily fortified digital walls, these parties  can simply walk through doors that are being propped open—and then erase evidence of their actions.

 

The security implications span three critical areas.

First, system manipulation: External operators can now modify operations while also altering audit trails that would track their changes. Second, data exposure: Beyond accessing personal information and transaction records, these operators can copy entire system architectures and security configurations—in one case, the technical blueprint of the country’s federal payment infrastructure. Third, and most critically, is the issue of system control: These operators can alter core systems and authentication mechanisms while disabling the very tools designed to detect such changes. This is more than modifying operations; it is modifying the infrastructure that those operations use.

To address these vulnerabilities, three immediate steps are essential. First, unauthorized access must be revoked and proper authentication protocols restored. Next, comprehensive system monitoring and change management must be reinstated—which, given the difficulty of cleaning a compromised system, will likely require a complete system reset. Finally, thorough audits must be conducted of all system changes made during this period.

This is beyond politics—this is a matter of national security. Foreign national intelligence organizations will be quick to take advantage of both the chaos and the new insecurities to steal US data and install backdoors to allow for future access.

Each day of continued unrestricted access makes the eventual recovery more difficult and increases the risk of irreversible damage to these critical systems. While the full impact may take time to assess, these steps represent the minimum necessary actions to begin restoring system integrity and security protocols.

Assuming that anyone in the government still cares.

This essay was written with Davi Ottenheimer, and originally appeared in Foreign Policy.

Read the whole story
tjkirch
6 days ago
reply
Seattle, WA
popular
6 days ago
reply
DGA51
6 days ago
This is all due to the Republican Party enforcing obedience on its elected members.
4 days ago
Learn how to invest in stocks! Invest $160 and get $6,200 In 2Hours without sending money to anyone DM ME HOW via! nute WhatsApp number:+1(332)252-4701 Text No:+1 (703) 879-8125 WhatsApp link below 👇 👇👇👇 https://wa.me/message/7L7D2AETIXNUD1
Share this story
Delete
3 public comments
fxer
6 days ago
reply
Well as long as there isn’t a private email server involved
Bend, Oregon
4 days ago
Learn how to invest in stocks! Invest $160 and get $6,200 In 2Hours without sending money to anyone DM ME HOW via! nute WhatsApp number:+1(332)252-4701 Text No:+1 (703) 879-8125 WhatsApp link below 👇 👇👇👇 https://wa.me/message/7L7D2AETIXNUD1
josephwebster
7 days ago
reply
Heil Elon
Denver, CO, USA
4 days ago
Learn how to invest in stocks! Invest $160 and get $6,200 In 2Hours without sending money to anyone DM ME HOW via! nute WhatsApp number:+1(332)252-4701 Text No:+1 (703) 879-8125 WhatsApp link below 👇 👇👇👇 https://wa.me/message/7L7D2AETIXNUD1
GaryBIshop
8 days ago
reply
The people have spoken, this is what they want. Enjoy!

Chemical Formulas

1 Comment and 4 Shares
Can you pass the nackle?
Read the whole story
tjkirch
32 days ago
reply
Seattle, WA
Share this story
Delete
1 public comment
alt_text_bot
32 days ago
reply
Can you pass the nackle?
marcrichter
32 days ago
😂

Via https://bsky.app/profile/mtsw.bsky.social/post/3lejs4dhtl22v

1 Share

Via https://bsky.app/profile/mtsw.bsky.social/post/3lejs4dhtl22v

Read the whole story
tjkirch
53 days ago
reply
Seattle, WA
Share this story
Delete

Linear Sort

5 Comments and 9 Shares
The best case is O(n), and the worst case is that someone checks why.
Read the whole story
popular
65 days ago
reply
tjkirch
65 days ago
reply
Seattle, WA
Share this story
Delete
5 public comments
jlvanderzwan
64 days ago
reply
This joke was funnier 13 years ago when some anonymous weirdo invented "sleepsort"

https://web.archive.org/web/20151231221001/http://bl0ckeduser.github.io/sleepsort/sleep_sort_trimmed.html
macr0t0r
65 days ago
reply
Well...if you want determinate time...
bcs
65 days ago
while true: pass
Groxx
65 days ago
reply
It's good to let your computer rest occasionally, to avoid burnout
Silicon Valley, CA
GaryBIshop
65 days ago
reply
I love it that it is Python!
edquartett2
65 days ago
It's not Python 😉 "length()" is just "len()" and functions begin with "def"
alt_text_bot
65 days ago
reply
The best case is O(n), and the worst case is that someone checks why.

popehat.com on The Day After

1 Share

And Yet It Moves

Nobody likes to lose. So when your side loses an election, there’s huge social and psychological pressure to change your stance, to moderate what you believe so you don’t feel like a loser. Don’t do it. Things are worth believing and fighting for.

Good, necessary rant for today.

Read the whole story
tjkirch
107 days ago
reply
Seattle, WA
Share this story
Delete

Pluralistic: You should be using an RSS reader (16 Oct 2024)

4 Comments and 15 Shares


Today's links



A rifle-bearing, bearded rebel with crossed bandoliers stands atop a mainframe. His belt bears the RSS logo. The mainframe is on a floor made of a busy, resistor-studded circuit board. The background is a halftoned RSS logo. Around the rebel is a halo of light.

You should be using an RSS reader (permalink)

No matter how hard we all wish it were otherwise, the sad fact is that there aren't really individual solutions to systemic problems. For example: your personal diligence in recycling will have no meaningful impact on the climate emergency.

I get it. People write to me all the time, they say, "What can I change about my life to fight enshittification, or, at the very least, to reduce the amount of enshittification that I, personally, experience?"

It's frustrating, but my general answer is, "Join a movement. Get involved with a union, with EFF, with the FSF. Tell your Congressional candidate to defend Lina Khan from billionaire Dem donors who want her fired. Do something systemic."

There's very little you can do as a consumer. You're not going to shop your way out of monopoly capitalism. Now that Amazon has destroyed most of the brick-and-mortar and digital stores out of business, boycotting Amazon often just means doing without. The collective action problem of leaving Twitter or Facebook is so insurmountable that you end up stuck there, with a bunch of people you love and rely on, who all love each other, all hate the platform, but can't agree on a day and time to leave or a destination to leave for and so end up stuck there.

I've been experiencing some challenging stuff in my personal life lately and yesterday, I just found myself unable to deal with my usual podcast fare so I tuned into the videos from the very last XOXO, in search of uplifting fare:

https://www.youtube.com/@xoxofest

I found it. Talks by Dan Olson, Cabel Sasser, Ed Yong and many others, especially Molly White:

https://www.youtube.com/watch?v=MTaeVVAvk-c

Molly's talk was so, so good, but when I got to her call to action, I found myself pulling a bit of a face:

But the platforms do not exist without the people, and there are a lot more of us than there are of them. The platforms have installed themselves in a position of power, but they are also vulnerable…

Are the platforms really that vulnerable? The collective action problem is so hard, the switching costs are so high – maybe the fact that "there's a lot more of us than there are of them" is a bug, not a feature. The more of us there are, the thornier our collective action problem and the higher the switching costs, after all.

And then I had a realization: the conduit through which I experience Molly's excellent work is totally enshittification-proof, and the more I use it, the easier it is for everyone to be less enshittified.

This conduit is anti-lock-in, it works for nearly the whole internet. It is surveillance-resistant, far more accessible than the web or any mobile app interface. It is my secret super-power.

It's RSS.

RSS (one of those ancient internet acronyms with multiple definitions, including, but not limited to, "Really Simple Syndication") is an invisible, automatic way for internet-connected systems to public "feeds." For example, rather than reloading the Wired homepage every day and trying to figure out which stories are new (their layout makes this very hard to do!), you can just sign up for Wired's RSS feed, and use an RSS reader to monitor the site and preview new stories the moment they're published. Wired pushes about 600 words from each article into that feed, stripped of the usual stuff that makes Wired nearly impossible to read: no 20-second delay subscription pop-up, text in a font and size of your choosing. You can follow Wired's feed without any cookies, and Wired gets no information about which of its stories you read. Wired doesn't even get to know that you're monitoring its feed.

I don't mean to pick on Wired here. This goes for every news source I follow – from CNN to the New York Times. But RSS isn't just good for the news! It's good for everything. Your friends' blogs? Every blogging platform emits an RSS feed by default. You can follow every one of them in your reader.

Not just blogs. Do you follow a bunch of substackers or other newsletters? They've all got RSS feeds. You can read those newsletters without ever registering in the analytics of the platforms that host them. The text shows up in black and white (not the sadistic, 8-point, 80% grey-on-white type these things all default to). It is always delivered, without any risk of your email provider misclassifying an update as spam:

https://pluralistic.net/2021/10/10/dead-letters/

Did you know that, by default, your email sends information to mailing list platforms about your reading activity? The platform gets to know if you opened the message, and often how far along you've read in it. On top of that, they get all the private information your browser or app leaks about you, including your location. This is unbelievably gross, and you get to bypass all of it, just by reading in RSS.

Are your friends too pithy for a newsletter, preferring to quip on social media? Unfortunately, it's pretty hard to get an RSS feed from Insta/FB/Twitter, but all those new ones that have popped up? They all have feeds. You can follow any Mastodon account (which means you can follow any Threads account) via RSS. Same for Bluesky. That also goes for older platforms, like Tumblr and Medium. There's RSS for Hacker News, and there's a sub-feed for the comments on every story. You can get RSS feeds for the Fedex, UPS and USPS parcels you're awaiting, too.

Your local politician's website probably has an RSS feed. Ditto your state and national reps. There's an RSS feed for each federal agency (the FCC has a great blog!).

Your RSS reader lets you put all these feeds into folders if you want. You can even create automatic folders, based on keywords, or even things like "infrequently updated sites" (I follow a bunch of people via RSS who only update a couple times per year – cough, Danny O'Brien, cough – and never miss a post).

Your RSS reader doesn't (necessarily) have an algorithm. By default, you'll get everything as it appears, in reverse-chronological order.

Does that remind you of anything? Right: this is how social media used to work, before it was enshittified. You can single-handedly disenshittify your experience of virtually the entire web, just by switching to RSS, traveling back in time to the days when Facebook and Twitter were more interested in showing you the things you asked to see, rather than the ads and boosted content someone else would pay to cram into your eyeballs.

Now, you sign up to so many feeds that you're feeling overwhelmed and you want an algorithm to prioritize posts – or recommend content. Lots of RSS readers have some kind of algorithm and recommendation system (I use News, which offers both, though I don't use them – I like the glorious higgeldy-piggeldy of the undifferentiated firehose feed).

But you control the algorithm, you control the recommendations. And if a new RSS reader pops up with an algorithm you're dying to try, you can export all the feeds you follow with a single click, which will generate an OPML file. Then, with one click, you can import that OPML file into any other RSS reader in existence and all your feeds will be seamlessly migrated there. You can delete your old account, or you can even use different readers for different purposes.

You can access RSS in a browser or in an app on your phone (most RSS readers have an app), and they'll sync up, so a story you mark to read later on your phone will be waiting for you the next time you load up your reader in a browser tab, and you won't see the same stories twice (unless you want to, in which case you can mark them as unread).

RSS basically works like social media should work. Using RSS is a chance to visit a utopian future in which the platforms have no power, and all power is vested in publishers, who get to decide what to publish, and in readers, who have total control over what they read and how, without leaking any personal information through the simple act of reading.

And here's the best part: every time you use RSS, you bring that world closer into being! The collective action problem that the publishers and friends and politicians and businesses you care about is caused by the fact that everyone they want to reach is on a platform, so if they leave the platform, they'll lose that community. But the more people who use RSS to follow them, the less they'll depend on the platform.

Unlike those largely useless, performative boycotts of widely used platforms, switching to RSS doesn't require that you give anything up. Not only does switching to RSS let you continue to follow all the newsletters, webpages and social media accounts you're following now, it makes doing so better: more private, more accessible, and less enshittified.

Switching to RSS lets you experience just the good parts of the enshitternet, but that experience is delivered in manner that the new, good internet we're all dying for.

My own newsletter is delivered in fulltext via RSS. If you're reading this as a Mastodon or Twitter thread, on Tumblr or on Medium, or via email, you can get it by RSS instead:

https://pluralistic.net/feed/

Don't worry about which RSS reader you start with. It literally doesn't matter. Remember, you can switch readers with two clicks and take all the feeds you've subscribed to with you! If you want a recommendation, I have nothing but praise for Newsblur, which I've been paying $2/month for since 2011 (!):

https://newsblur.com/

Subscribing to feeds is super-easy, too: the links for RSS feeds are invisibly embedded in web-pages. Just paste the URL of a web-page into your RSS reader's "add feed" box and it'll automagically figure out where the feed lives and add it to your subscriptions.

It's still true that the new, good internet will require a movement to overcome the collective action problems and the legal barriers to disenshittifying things. Almost nothing you do as an individual is going to make a difference.

But using RSS will! Using RSS to follow the stuff that matters to you will have an immediate, profoundly beneficial impact on your own digital life – and it will appreciably, irreversibly nudge the whole internet towards a better state.


Hey look at this (permalink)


* You Can't Make Friends With The Rockstars https://www.wheresyoured.at/rockstars/



A Wayback Machine banner.

This day in history (permalink)

#20yrsago Sony bullies Retropod off the net https://web.archive.org/web/20041018040446/http://www.retropod.com/

#15yrsago This Side of Jordan – Violent jazz age novel by Charles M Schulz’s son Monte https://memex.craphound.com/2009/10/16/this-side-of-jordan-violent-jazz-age-novel-by-charles-m-schulzs-son-monte/

#10yrsago FBI chief demands an end to cellphone security https://www.nytimes.com/2014/10/17/us/politics/fbi-director-in-policy-speech-calls-dark-devices-hindrance-to-crime-solving.html

#10yrsago Please, Disney: put back John’s grandad’s Haunted Mansion tombstone https://thedisneyblog.com/2014/10/16/petition-to-return-a-lost-tombstone-to-the-haunted-mansion/

#10yrsago How Microsoft hacked trademark law to let it secretly seize whole businesses https://www.wired.com/2014/10/microsoft-pinkerton/

#10yrsago If you think you’ve anonymized a data set, you’re probably wrong https://web.archive.org/web/20141014172827/http://research.neustar.biz/2014/09/15/riding-with-the-stars-passenger-privacy-in-the-nyc-taxicab-dataset/

#10yrsago The lost cyber-crayolas of the mid-1990s https://memex.craphound.com/2014/10/16/the-lost-cyber-crayolas-of-the-mid-1990s/

#5yrsago “The People’s Money”: A crisp, simple, thorough explanation of how government spending is paid for https://neweconomicperspectives.org/2019/10/the-peoples-money-part-1.html

#5yrsago What it’s like to have Apple rip off your successful Mac app https://memex.craphound.com/2019/10/16/what-its-like-to-have-apple-rip-off-your-successful-mac-app/

#5yrsago Blizzard suspends college gamers from competitive play after they display “Free Hong Kong” poster https://www.vice.com/en/article/three-college-hearthstone-protesters-banned-for-six-months/

#5yrsago Terrified of bad press after its China capitulation, Blizzard cancels NYC Overwatch event https://www.bloomberg.com/news/articles/2019-10-15/blizzard-cancels-overwatch-event-as-it-tries-to-contain-backlash

#5yrsago A San Diego Republican operator ran a massive, multimillion-dollar Facebook scam that targeted boomers https://www.buzzfeednews.com/article/craigsilverman/facebook-subscription-trap-free-trial-scam-ads-inc

#5yrsago Britain’s unbelievably stupid, dangerous porn “age verification” scheme is totally dead https://arstechnica.com/tech-policy/2019/10/uk-government-abandons-planned-porn-age-verification-scheme/

#5yrsago Not only is Google’s auto-delete good for privacy, it’s also good news for competition https://memex.craphound.com/2019/10/16/not-only-is-googles-auto-delete-good-for-privacy-its-also-good-news-for-competition/

#5yrsago Edward Snowden on the global war on encryption: “This is our new battleground” https://www.theguardian.com/commentisfree/2019/oct/15/encryption-lose-privacy-us-uk-australia-facebook

#5yrsago In Kansas’s poor, sick places, hospitals and debt collectors send the ailing to debtor’s prison https://features.propublica.org/medical-debt/when-medical-debt-collectors-decide-who-gets-arrested-coffeyville-kansas

#5yrsago Want a ride in a Lyft? Just sign away your right to sue if they kill, maim, rape or cheat you https://memex.craphound.com/2019/10/16/want-a-ride-in-a-lyft-just-sign-away-your-right-to-sue-if-they-kill-maim-rape-or-cheat-you/

#5yrsago #RedForEd rebooted: Chicago’s teachers are back on strike https://www.thenation.com/article/archive/union-strike-chicago-teachers/

#1yrago One of America's most corporate-crime-friendly bankruptcy judges forced to recuse himself https://pluralistic.net/2023/10/16/texas-two-step/#david-jones


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, holding a mic.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • Picks and Shovels: a sequel to "Red Team Blues," about the heroic era of the PC, Tor Books, February 2025

  • Unauthorized Bread: a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, 2025



Colophon (permalink)

Today's top sources:

Currently writing:

  • Enshittification: a nonfiction book about platform decay for Farrar, Straus, Giroux. Today's progress: 818 words (64779 words total).

  • A Little Brother short story about DIY insulin PLANNING

  • Picks and Shovels, a Martin Hench noir thriller about the heroic era of the PC. FORTHCOMING TOR BOOKS FEB 2025

Latest podcast: Spill, part one (a Little Brother story) https://craphound.com/littlebrother/2024/10/06/spill-part-one-a-little-brother-story/


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Medium (no ads, paywalled):

https://doctorow.medium.com/

Twitter (mass-scale, unrestricted, third-party surveillance and advertising):

https://twitter.com/doctorow

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

Read the whole story
tjkirch
127 days ago
reply
Seattle, WA
popular
127 days ago
reply
Share this story
Delete
4 public comments
Hanezz
82 days ago
reply
I agree, people should be using an RSS reader to follow up on new stories the moment they're published. NewsBlur makes this very EASY!
cjheinz
128 days ago
reply
RSS FTW!
I've been using NewsBlur since Google killed Reader.
Lexington, KY; Naples, FL
countswackula
127 days ago
Same!
digdoug
128 days ago
reply
You really should be using Newsblur, people.
Louisville, KY
J04NNY8
101 days ago
Yes I found it ironic reading this here.
Ferret
128 days ago
reply
The irony of sharing Cory's 'use should be using an RSS reader' post in my RSS reader is not lost on me
Next Page of Stories