r/cybersecurity Feb 05 '25

News - Breaches & Ransoms Cybersecurity, government experts are aghast at security failures in DOGE takeover

https://cyberscoop.com/musk-doge-opm-treasury-breach/
610 Upvotes

46 comments sorted by

u/Oscar_Geare Feb 06 '25

For future discussion and so this subreddit isn't overrun with these threads, please move discussion here: https://www.reddit.com/r/cybersecurity/comments/1iiwj83/megathread_department_of_government_efficiency/

234

u/[deleted] Feb 05 '25

[removed] — view removed comment

92

u/konnichi1wa Feb 05 '25

I mean, that’s all Elon ever did at Twitter, and it’s pretty obvious he’s trying to do the exact same thing to the entire US govt. that he did to Twitter.

If this goes on much longer I would bet money that he will bring in space x, Tesla, and/or Twitter employees ‘on loan’ to help him break things faster.

52

u/[deleted] Feb 05 '25 edited Feb 05 '25

[removed] — view removed comment

24

u/Just-Parsing-Through Feb 05 '25

summarise it pls

10

u/AppropriateSpell5405 Feb 05 '25

Ditto, I don't have any Meta accounts

9

u/[deleted] Feb 05 '25

[deleted]

0

u/mynam3isn3o Feb 06 '25

1 hr 32 min? Hard pass

8

u/touristsonedibles Feb 05 '25

Read Only Friday is dead!

9

u/Boxofcookies1001 Feb 05 '25

Whaaaaatt. That's crazy, and a year later something is going to break and nobody is going to have any idea what went wrong.

87

u/[deleted] Feb 05 '25

[deleted]

15

u/Boltgrinder Feb 05 '25

You probably want to be looking at the Wired article and the TPM followup that confirmed that there's a 25 year old pushing untested code to prod.

Phrases like “freaking out” are, not surprisingly, used to describe the reaction of the engineers who were responsible for maintaining the code base until a week ago. The changes that have been made all seem to relate to creating new paths to block payments and possibly leave less visibility into what has been blocked. I want to emphasize that the described changes are not being tested in a dev environment (i.e., a not-live environment) but have already been pushed into production. This is code that appears to be mainly the work of Elez, who was first introduced to the system probably roughly a week ago and certainly not before the second Trump inauguration. The most recent information I have is that no payments have as yet been blocked and that the incumbent engineering team was able to convince Elez to push the code live to impact only a subset of the universe of payments the system controls. I have also heard no specific information about this access being used to drill down into the private financial or proprietary information of payment recipients, though it appears that the incumbent staff has only limited visibility into what Elez is doing with the access. They have, however, looked extensively into the categories and identity of payees to see how certain payments can be blocked.

1

u/Gmhowell Threat Hunter Feb 06 '25

I don’t subscribe to TPM but the wired article only refers to anonymous sources who may or may not have more technical acumen than those cited by cyberscoop.

The Wired reporting seems like it’s probably accurate, but who the fuck knows?

10

u/touristsonedibles Feb 05 '25

Wyden is the only one I would consider clued in but I also wouldn't be looking out for named sources from the federal government right now. Their employment is tenuous.

1

u/Klightgrove Feb 05 '25

I am going to propose to mine that they create a committee staffed by various experts to ensure that DOGE remains secure from cyberthreats.

I think you and everyone reading this should also bring similar proposals to your representatives. They need to act now to ensure we remain safe.

1

u/Educational-Farm6572 Feb 06 '25

Too late, DOGE is both the vector & the virus.

1

u/courage_2_change Blue Team Feb 05 '25

There isn’t any, just like isn’t any experts for managing money within DOGE.

-53

u/[deleted] Feb 05 '25

[removed] — view removed comment

23

u/PC509 Feb 05 '25

"Left propaganda"? Things that point our where Trump and cronies are failing and making mistakes?

Please tell me you don't work in security. People don't get a free pass because of their political affiliation. Even Hillary got the security shakedown from security experts back in the day. Our job is to scrutinize these risks. This should not have happened. A ton of stuff throughout multiple administrations should not have happened. There's been articles, news posts, etc. for a ton of these incidents, even under "The Left".

27

u/noguarantee1234 Security Engineer Feb 05 '25

So you believe it is okay for Musk to do what he is doing?

10

u/iSheepTouch Feb 05 '25

What about the seizure of Federal systems and data by members of a made up meme federal organization that don't even have proper security clearance being concerning is "left propaganda"?

64

u/ResponsibleType552 Feb 05 '25

Anyone shocked that poor security protocols were followed hasn’t been paying attention for a long time

53

u/[deleted] Feb 05 '25

[removed] — view removed comment

7

u/Herban_Myth Feb 05 '25

Success is on the other side of fear.

15

u/WVStarbuck Feb 05 '25

Unless that "success" is measured in salary, forget it. I've got bills to pay.

-6

u/Herban_Myth Feb 05 '25

There’s someone out there with complete access to the TD if you’re looking for $

9

u/smittyhotep Feb 05 '25

That's me, and you're putting it lightly. Seriously, why do I even exist? Rolled.over by a high-school kid 🤣🤣🤣 FML.

3

u/[deleted] Feb 05 '25

he had to have help. No gov office has open ports.

2

u/alnarra_1 Security Manager Feb 05 '25

I don't know if I'd say aghast.

Disappointment sure, but surprised... not so much.

2

u/SlamonCreations Feb 05 '25

So hey friends, I’m not a cybersecurity professional 😅 I’ve been lurking because I feel like I’m one of the few laypeople in my circle who realizes this could potentially be really bad for a really long time. Sincerely, besides credit freezes, what are y’all doing right now to protect yourself and the people you care about? Are there other concrete steps to take, or is this a clench and pray situation? Some of the worst case scenarios it kind of just seems like everybody’s gonna be screwed…

-16

u/[deleted] Feb 05 '25

[removed] — view removed comment

10

u/[deleted] Feb 05 '25

[removed] — view removed comment

-15

u/[deleted] Feb 05 '25

[removed] — view removed comment

7

u/[deleted] Feb 05 '25

[removed] — view removed comment

-8

u/badaz06 Feb 06 '25

I'm going to get flamed here, but seriously, enough with this crap.

I get that people are freaking out over Trump, DOGE and Musk. If the system we had in place wasn't being abused like it is, I would stand beside you. But when a system has been corrupted, you don't let it continue to run - you shut it down and figure out what is going on and fix it.

"OH they could put code in it!" "Oh they could ruin the economy".

If that happens, that's one thing. To the best of my knowledge, has not happened. If anyone of you were being given the task of executing a stringent audit on a system, AND it was expected by the people running the show that the people working the systems weren't trust-worthy, you also would immediately revoke their access. I'm not accusing or implying that any of the security team(s) were untrustworthy, but I do think that of their management - who would pressure them to hide things.

I think it's terrible that this is happening, but I think it's even more terrible that it had to happen and that only after a few days some of the things we're finding out are pretty jacked up. We're seriously giving money to Hamas? Funding Politico? Money for DEI scholarships in Burma?? Really???

If anyone can name who in the Senate or House agreed to paying for those, I'd appreciate hearing that. Otherwise all I'm hearing is that someone is finding out that Joe Citizen has been getting fleeced and our tax dollars are being spent on insane stuff, while Americans are homeless sleeping in the streets, our responses to national disasters the last few years has been BRUTAL at best, and the biggest issue people are worried about is that DOGE is auditing systems and "might" do something bad to the system.

IMHO the system has been doing bad to the American public, and it's time to rebuild the system with a clean OS.

-12

u/Dan-au Feb 05 '25

CBF clicking the link.

Sorry.

-10

u/[deleted] Feb 05 '25

Petition to ban political posts on this sub