handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

37
active users

#nlrb

28 posts8 participants0 posts today

"A government whistleblower told lawmakers that DOGE's access to National Labor Relations Board (NLRB) systems went far beyond what was needed to analyze agency operations and apparently led to a data breach. NLRB employee Daniel Berulis, a DevSecOps architect, also says he received a threat when he was preparing his whistleblower disclosure.

"Mr. Berulis is coming forward today because of his concern that recent activity by members of the Department of Government Efficiency ('DOGE') have resulted in a significant cybersecurity breach that likely has and continues to expose our government to foreign intelligence and our nation's adversaries," said a letter from the group Whistleblower Aid to the Senate Select Committee on Intelligence leaders and the US Office of Special Counsel.

The letter, Berulis' sworn declaration, and an exhibit with screenshots of technical data are available here. "This declaration details DOGE activity within NLRB, the exfiltration of data from NLRB systems, and—concerningly—near real-time access by users in Russia," Whistleblower Aid Chief Legal Counsel Andrew Bakaj wrote. "Notably, within minutes of DOGE personnel creating user accounts in NLRB systems, on multiple occasions someone or something within Russia attempted to login using all of the valid credentials (e.g. Usernames/Passwords). This, combined with verifiable data being systematically exfiltrated to unknown servers within the continental United States—and perhaps abroad—merits investigation."

Bakaj said they notified law enforcement about an "absolutely disturbing" threat Berulis received on April 7."

arstechnica.com/tech-policy/20

Elon Musk wearing a T-shirt with the word "DOGE" printed on the front.
Ars Technica · Government IT whistleblower calls out DOGE, says he was threatened at homeBy Jon Brodkin
#USA#Trump#DOGE
Replied in thread

It's unclear why #DOGE would need #access to #NLRB files that contain personally identifiable #information to complete its *mission* of improving *efficiency*, outside of employment records for potential reductions in force. The agency publishes publicly available annual performance & accountability reports & budget justifications that former NLRB members told #NPR would likely be sufficient in looking for ways to cut costs.

Replied in thread

"The representatives have requested information about agency operations but asked us to remove any personally identifiable information from documents we provide," the email reads. "Consistent with the President's Executive Order & applicable laws, the Agency will comply with #DOGE's requests for access & information."

Replied in thread

The email, sent to staff on behalf of #NLRB chair Marvin E. Kaplan & acting general counsel William Cowen & shared w/ #NPR by 2 NLRB employees…, said 2 #DOGE reps would be detailed to the agency from the #GSA "part-time for several months" & would largely work *remotely* [guess they’ll be using that back door].

Continued thread

🔴 2️⃣ - Rachel Maddows Pt.2 incl. vollständigem Interview mit Whistleblower Daniel Berulis zu den illegalen DOGE-Aktivitäten, zu möglicherweise russischem Zugriff auf sensibelste Daten auch anderer Institutionen, zum Zusammenhang mit Musks Starlink und den Folgen für die gesamte Sicherheitsstruktur der USA:

Continued thread

🔴 👁️ - Rachel Maddow: „DOGE-Mitarbeiter dringen ein, strukturieren ihren Zugang so, dass niemand sehen kann, was sie tun und während sie dort sind, werden JEDE MENGE DATEN dieser sehr sensiblen Behörde in unbekannte Bereiche gebracht. Dann lassen sie alle Türen unverschlossen und die Alarmanlagen ausgeschaltet, und dann beginnt SOFORT jemand mit einer IP-Adresse in RUS, sich mit einem der DOGE-Konten und einem scheinbar funktionierenden Usernamen und PW in das System einzuloggen.“ 1️⃣

A whistle blower revealed #doge intentions to target the National Labor Relations Board.

They obtained information about labor statistics, and the people involved illegally, after stating they'd be transparent with their actions.

This is going to be a direct attack on labor rights, as they are responsible for unionization, and labor rights complaints.

They are very small, and cutting them would serve no benefit financially.

This needs to not happen.

scoopzapp.com/n/10PILGa3?ctype

scoopzapp.com#GovernmentShutdown Whistle Blower Reveals DOGE's Intentions to Target National Labor Relations Board#GovernmentShutdown Whistle Blower Reveals DOGE's Intentions to Target National Labor Relations Board
Replied in thread

While investigating the #data taken from #NLRB, Berulis tried to determine its ultimate destination. But whoever had exfiltrated it had disguised its destination too….

#DOGE staffers had permission to access the system, but removing data is another matter.

Berulis says someone appeared to be doing something called DNS tunneling to prevent the data exfiltration from being detected.

#criminal#law#Trump
Replied in thread

Someone disabled controls to prevent insecure or unauthorized mobile devices from logging on w/o the proper #security settings. There was an interface exposed to the public internet, potentially allowing malicious actors access to #NLRB's systems. Internal alerting & monitoring systems were manually turned off. Multifactor authentication was disabled. And…an unknown user had exported a "user roster," a file w/contact information for outside lawyers who have worked w/the NLRB.

Replied in thread

Even when external parties like lawyers or overseers like the inspector general are granted guest accounts on the system, it's only to view the files relevant to their case or investigation, explained #labor #law experts who worked with or at the #NLRB….

"None of that confidential & deliberative information should ever leave the agency," said Richard Griffin, who was the NLRB general counsel 2013–2017, in an interview w/NPR.

Replied in thread

Regardless, that kind of spike is extremely unusual, …because #data almost never directly leaves from the #NLRB's databases. In his disclosure, Berulis shared a screenshot tracking data entering and exiting the system, & there's only one noticeable spike of data going out. He also confirmed that no one at the NLRB had been saving backup files that week or migrating data for any projects.

#criminal#law#Trump
Replied in thread

From what he could see, the #data leaving, almost all text files, added up to around 10GB…. It's a sizable chunk of the total data in the #NLRB sys, though the agency itself hosts over 10TB in historical data. It's unclear which files were copied & removed or whether they were consolidated & compressed, which could mean even more data was exfiltrated. It's also possible that #DOGE ran queries looking for specific files…& took only what it was looking for….

#criminal#law#Trump
Replied in thread

On its own, that wouldn't be suspicious, though it did allow the engineers to work invisibly & left no trace of its activities once it was removed.

Then, Berulis started tracking sensitive #data leaving the places it's meant to live…. First, he saw a chunk of data exiting the NxGen case management system's "nucleus," inside the #NLRB system, Berulis explained. Then, he saw a large spike in outbound traffic leaving the network itself.

#criminal#law#Trump
Replied in thread

But he counted on #DOGE leaving at least a few traces of its activity behind,…details he included in his ofcl disclosure.

First, at least 1 DOGE account was created & later deleted for use in #NLRB's cloud systems, hosted by Microsoft:
DogeSA_2d5c3e0446f9@nlrb.microsoft.com

Then, DOGE engineers installed what's called a "container," a kind of opaque virtual computer that can run programs…w/o revealing its activities to the rest of the network.
#law #Trump #Musk #DOGE #InfoSec #NationalSecurity

Replied in thread

About a week after arriving, the #DOGE engineers left #NLRB & deleted their accounts….

In the office, Berulis had had limited visibility into what the DOGE team was up to in real time.

That's partly because, he said, NLRB isn't advanced when it comes to detecting insider threats…. "We as an agency have not evolved to account for those," he explained. "We were looking for [bad actors] outside," he said.

#criminal#law#Trump