this post was submitted on 14 Feb 2025
20 points (100.0% liked)

Cybersecurity

12 readers
9 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
 

"The doge.gov website that was spun up to track Elon Musk’s cuts to the federal government is insecure and pulls from a database that can be edited by anyone, according to two separate people who found the vulnerability and shared it with 404 Media. One coder added at least two database entries that are visible on the live site and say “this is a joke of a .gov site” and “THESE ‘EXPERTS’ LEFT THEIR DATABASE OPEN -roro.”

Doge.gov was hastily deployed after Elon Musk told reporters Tuesday that his Department of Government Efficiency is “trying to be as transparent as possible. In fact, our actions—we post our actions to the DOGE handle on X, and to the DOGE website.” At the time, DOGE was an essentially blank webpage. It was built out further Wednesday and Thursday, and now shows a mirror of the @DOGE X account posts, as well as various stats about the U.S. government’s federal workforce.

Two different web development experts who asked to remain anonymous because they were probing a federal website told 404 Media that doge.gov is seemingly built on a Cloudflare Pages site that is not currently hosted on government servers. The database it is pulling from can be and has been written to by third parties, and will show up on the live website."

https://www.404media.co/anyone-can-push-updates-to-the-doge-gov-website-2/

#USA #Musk #Trump #DOGE #CyberSecurity #SQL #Databases #Privacy #DataProtection

you are viewing a single comment's thread
view the rest of the comments
[–] psoutham@infosec.exchange 5 points 2 months ago

@remixtures@tldr.nettime.org Like I tell my kids, it's never been a better time to get involved in #cybercrime / #hacking.

#usa #uspol #musk #trump #cybersecurity #dataprotection