logoalt Hacker News

twalkz04/23/202516 repliesview on HN

> According to a whistleblower complaint filed last week by Daniel J. Berulis, a 38-year-old security architect at the NLRB, officials from DOGE met with NLRB leaders on March 3 and demanded the creation of several all-powerful “tenant admin” accounts that were to be exempted from network logging activity that would otherwise keep a detailed record of all actions taken by those accounts.

Feels like a pretty good Occam’s razor case… but is there any legitimate reason why one would request this?


Replies

rtkwe04/23/2025

Even worse when you know more of the whistleblower's story which is that ~15 minutes after one of DOGE's accounts were made there was an attempted login with the correct password from Russia. Not many explanations for that that look good for DOGE...

show 2 replies
pan6904/23/2025

> all-powerful “tenant admin” accounts that were to be exempted from network logging activity

Is this normal to build this sort of functionality into a software system? Especially software systems that heavily rely on auditability?

show 6 replies
vkou04/23/2025

There isn't one.

Anything musk's dogs claim to find cannot be taken at face value because of this. Because there is no audit, and no evidence that they can offer that they didn't doctor their findings.

The next time they claim that a 170-year old person is receiving SS checks, they have no way to prove that they didn't subtract a century from that person's birthdate in some table.

show 1 reply
Cthulhu_04/23/2025

Sure, to hide your tracks because you know what you intend to do isn't right.

plandis04/23/2025

I can’t think of any. Even if you wanted to give someone broad permissions to access and modify data, you wouldn't turn off the audit logs.

patrickmay04/23/2025

There is no justification for ever creating an account like that. The only purpose is nefarious.

largbae04/23/2025

I am sure they demanded maximum access, but the logging activity phrasing sounds a little bit like spin...

I think if I wanted to describe an account with access to perform "sudo -s" as negatively as possible, I would say "an all-powerful admin account that is exempt from logging activity that would otherwise keep a detailed record of all actions taken by those accounts."

api04/23/2025

To allow dodgy offshore actors to snarf huge amounts of data on US citizens to prepare a huge propaganda assault for the next election?

tootie04/24/2025

Interview with whistleblower detailing the attack and the threats directed against him:

https://www.pbs.org/newshour/show/nlrb-whistleblower-claims-...

show 1 reply
Suppafly04/23/2025

I'm only really familiar with the 'tenant admin' concept from microsoft administration, it's commonly used otherwise?

spencerflem04/23/2025

Obviously no

jimt123404/24/2025

The Deep State! The government is filled with spies determined to "leak" the great work DOGE is doing is the press - so, of course, it needs "God mode" access. Totally legit.

That's the best I could do. LOL

1oooqooq04/23/2025

very clear admission of guilt.

wmf04/23/2025

[flagged]

show 11 replies
mfer04/23/2025

Setting aside legitimate (thats a matter of judgement)...

Some previous attempts for DOGE to get data has resulted in data being deleted before they can look and requests for judges to block access to data.

DOGE may be trying to be covert in order to stop these two activities from happening before they can get and review the data.

show 1 reply