Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    125comments
  2. Pirating the Pirates (mubi.com)
    231comments
  3. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    22comments
  4. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    66comments
  5. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    20comments
  6. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    169comments
  7. Tank Body Problem (jimsitu.com)
    5comments
  8. Scientists solve 1840s space weather mystery (arstechnica.com)
    38comments
  9. Sonnet 5.5 (anthropic.com)
    418comments
  10. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    3comments
  11. World Labs Is Joining AMD (worldlabs.ai)
    77comments
  12. Hijacking the PS5's RTMP stream (yashgarg.dev)
    67comments
  13. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    9comments
  14. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    185comments
  15. How to win a beer with high-dimensional statistics (jamiesimon.io)
    2comments
  16. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    153comments
  17. It's Time to Investigate the AI Labs (calnewport.com)
    123comments
  18. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    —discuss
  19. The Art Forger Who Became a National Hero (priceonomics.com)
    —discuss
  20. Blend and Haul: Fertilizer Blending Simulator (wedgworth.com)
    1comments
  21. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    140comments
  22. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    25comments
  23. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    82comments
  24. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    151comments
  25. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    56comments
  26. Behold the pawpaw (cbc.ca)
    17comments
  27. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    28comments
  28. First Steps of the PLC Organization – Independent Public Ledger of Credentials (plcred.org)
    19comments
  29. Coding is not solved (alexewerlof.com)
    438comments
  30. When did Google get so weird? (sancho.bearblog.dev)
    1038comments

DOGE Exposes Once-Secret Government Networks, Making Cyber-Espionage Easier Than

99 pointsby 1y agocyberintel.substack.com
25 comments
1y agoHN ↗

Now that we're talking about doge, could anyone from us tell me if doge.gov/join has a cloud flare chaptcha when interacting with the form from the USA? I can only visit it via VPN and I have a chaptcha before the submit button. No, I don't wanna join doge, it's for... Educational purposes

1y agoHN ↗

I don’t see one immediately, it doesn’t appear only after you click the submit button, does it?

1y agoHN ↗

With a VPN I see it after a few seconds/when I interact with the text fields of the form. You only see it when submit is clicked?

1y agoHN ↗

I don't get any captchas at all (haven't tried submitting), and I have a custom patched build of Chromium presenting an old user agent and several privacy features and extensions that usually get me captcha'd by cloudflare all the time.

1y agoHN ↗

COOL, I wasn't definitely working on a bot that spams requests with junk fake data, but if I were could I send you a trial version to see if you get chaptcha'ed? If yes lemme know if I can contact you on telegram or via mail or whatever

1y agoHN ↗

No, I think I'd prefer not to get involved in that.

1y agoHN ↗

You're treading dangerously close to violating the CFAA... and you're here admitting it on a public forum. And you're trying to get others involved in your scheme.

1y agoHN ↗

I just wanted to try whether the chaptcha was for US people as well, all in all I just wanted to see how easy (or not easy) it would have been to do so.

Honestly, I was more curious than other things. Unfortunately, I do not believe that people could actually make a dent on doge even if things like what I were talking about were adopted by the large public

Aside from raising public awareness on the topic, I would have done nothing else. But, well, it's not feasible so I just abandoned it whole

As weird as it might seem, I never sent any data to doge, it was all done locally

1y agoHN ↗

"Alarmingly, a Department of Energy server allowed anonymous login with write access, raising the risk of hackers uploading malicious code or installing backdoors for persistent network access."

I sincerely hope that's a honeypot

1y agoHN ↗

I read this article and it is alarming, but what's the DOGE connection to once-private systems showing up on the public internet? That doesn't seem to be explained outside of the correlation with the Treasury system access.

Also, the authors of this SubStack appear to be anonymous?

1y agoHN ↗

It appears to be conflating things that may or may not be real with other things that are being misreported in the news and making up sensational stories out of them.

Unclassified government networks are mostly connected to the internet. The government is mostly bad at cyber security. These are well known facts. Whether or not "DOGE" has any actual connection to this is not really in evidence at this point, this is a highly partisan person's attempt to influence other people to their point of view.

1y agoHN ↗

I'm not sure this is partisan, looking back the (very light) post history of this substack and the nonexistent explanation of who the authors are, it looks like just a pure FUD machine.

1y agoHN ↗

I think it isn't only DOGE. Giving the chaos, the government employees are probably exfiltrating data, personal and governmental, to preserve as evidence to "CYA" or for possible future use say in their lawsuit for unlawful termination or whatever comes, like various investigations where by the time of the investigation the evidence my get removed from the government systems, etc...

1y agoHN ↗

The first sentence of the article:

this alarming trend seems to coincide with DOGE’s unrestricted access to federal networks.

the first 2 paragraphs: Beginning on January 8, 2025, a surge of U.S. government infrastructure began appearing on what’s known as “the search engine of Internet-connected devices,” Shodan.io.

Federal agencies typically secure their systems behind multiple layers of protection, ensuring that critical services – such as mail servers, directory services, VPNs, internal IP addresses, and remote access gateways – remain isolated from public access.

Now is this conclusive proof that DOGE did it? Hardly. However, can you think of anything else that changed since 8 Jan that would override decades of policy in the matter of hours?

1y agoHN ↗

However, can you think of anything else that changed since 8 Jan that would override decades of policy in the matter of hours?

Surely this is the wrong question- if the change happened on 8 Jan, we'd need to look at events before 8 Jan to find what precipitated the change, no?

1y agoHN ↗

Wasn't the inauguration after January 8? Ruling any post inauguration related shenanigans

1y agoHN ↗

Beginning on January 8, 2025, a surge of U.S. government infrastructure began appearing on what’s known as “the search engine of Internet-connected devices,” Shodan.io.

Seeing as how Trump was inaugurated on Jan 20th, it's hard to come to the conclusion that this is something that DOGE is responsible for.

1y agoHN ↗

Trump announced DOGE on Nov 12th, 2024 [0] and the transition doesn't all just happen on Jan 20th. The Presidential Transition Act has provisions that allow some members of transition staff to get access to federal IT systems, and with both Congress turning over on Jan 3rd, 2025 and Biden already completely checked out, it wouldn't be even a bit surprising to me if Congressional staffers or DOGE staffers started opening things up as soon as they could.

I don't have any evidence that it's the case, but if the claim about a surge of govt infrastructure appearing on shodan is accurate, I don't have any other hypotheses to explain it.

[0] https://www.nbcnews.com/tech/tech-news/trump-says-elon-musk-...

1y agoHN ↗

Beginning on January 8, 2025, a surge of U.S. government infrastructure began appearing on what’s known as “the search engine of Internet-connected devices,” Shodan.io.

DOGE didn't exist on January 8th.

1y agoHN ↗

The world is laughing at us, when they're not busy booing us. Hopefully we've all learned a valuable lesson here.

1y agoHN ↗

How do we know this is a real researcher and not a disgruntled (former) US government employee? It feels extremely politically-motivated, anyway.

1y agoHN ↗

This post should NOT be flagged. Plenty of substantial research in this article and it is disturbing. There is a concerted effort to silence anything that sounds like criticism.

1y agoHN ↗

January 8?

Are you familiar with calendars or how time works?

1y agoHN ↗

Yes, I can read a calendar and a clock. Thank you for the concern. I believe you are trying to say that the evidence is null because it happened earlier than the new admin got into power. Administrative handover happens within 30 days previous. So they began early January. Another way to look at this is, why didn’t they show up earlier? Like in 2023 or 24? Why only in 25, right after doge? It’s a little coincidental.