+0.32 Anyone can push updates to the doge.gov website (www.404media.co S:+0.35 )
1125 points by mahkeiro 379 days ago | 1123 comments on HN | Moderate positive Editorial · v3.7 · 2026-02-28 08:20:01
Summary Government Accountability & Digital Security Advocates
This investigative article documents a critical security vulnerability in DOGE.gov where unauthorized parties can modify government databases. The reporting advocates for government transparency, accountability, and digital security (Articles 19, 21) while documenting failures in system security and privacy protection (Articles 3, 12). The piece demonstrates free expression and investigative journalism holding government responsible for transparency commitments.
Article Heatmap
Preamble: +0.30 — Preamble P Article 1: ND — Freedom, Equality, Brotherhood Article 1: No Data — Freedom, Equality, Brotherhood 1 Article 2: ND — Non-Discrimination Article 2: No Data — Non-Discrimination 2 Article 3: -0.04 — Life, Liberty, Security 3 Article 4: ND — No Slavery Article 4: No Data — No Slavery 4 Article 5: ND — No Torture Article 5: No Data — No Torture 5 Article 6: ND — Legal Personhood Article 6: No Data — Legal Personhood 6 Article 7: ND — Equality Before Law Article 7: No Data — Equality Before Law 7 Article 8: ND — Right to Remedy Article 8: No Data — Right to Remedy 8 Article 9: ND — No Arbitrary Detention Article 9: No Data — No Arbitrary Detention 9 Article 10: ND — Fair Hearing Article 10: No Data — Fair Hearing 10 Article 11: ND — Presumption of Innocence Article 11: No Data — Presumption of Innocence 11 Article 12: +0.50 — Privacy 12 Article 13: ND — Freedom of Movement Article 13: No Data — Freedom of Movement 13 Article 14: ND — Asylum Article 14: No Data — Asylum 14 Article 15: ND — Nationality Article 15: No Data — Nationality 15 Article 16: ND — Marriage & Family Article 16: No Data — Marriage & Family 16 Article 17: ND — Property Article 17: No Data — Property 17 Article 18: ND — Freedom of Thought Article 18: No Data — Freedom of Thought 18 Article 19: +0.66 — Freedom of Expression 19 Article 20: ND — Assembly & Association Article 20: No Data — Assembly & Association 20 Article 21: +0.40 — Political Participation 21 Article 22: ND — Social Security Article 22: No Data — Social Security 22 Article 23: ND — Work & Equal Pay Article 23: No Data — Work & Equal Pay 23 Article 24: ND — Rest & Leisure Article 24: No Data — Rest & Leisure 24 Article 25: ND — Standard of Living Article 25: No Data — Standard of Living 25 Article 26: ND — Education Article 26: No Data — Education 26 Article 27: ND — Cultural Participation Article 27: No Data — Cultural Participation 27 Article 28: +0.16 — Social & International Order 28 Article 29: ND — Duties to Community Article 29: No Data — Duties to Community 29 Article 30: ND — No Destruction of Rights Article 30: No Data — No Destruction of Rights 30
Negative Neutral Positive No Data
Aggregates
Editorial Mean +0.32 Structural Mean +0.35
Weighted Mean +0.35 Unweighted Mean +0.33
Max +0.66 Article 19 Min -0.04 Article 3
Signal 6 No Data 25
Confidence 13% Volatility 0.23 (Medium)
Negative 1 Channels E: 0.6 S: 0.4
SETL +0.02 Editorial-dominant
FW Ratio 65% 13 facts · 7 inferences
Evidence: High: 1 Medium: 5 Low: 0 No Data: 25
Theme Radar
Foundation Security Legal Privacy & Movement Personal Expression Economic & Social Cultural Order & Duties Foundation: 0.30 (1 articles) Security: -0.04 (1 articles) Legal: 0.00 (0 articles) Privacy & Movement: 0.50 (1 articles) Personal: 0.00 (0 articles) Expression: 0.53 (2 articles) Economic & Social: 0.00 (0 articles) Cultural: 0.00 (0 articles) Order & Duties: 0.16 (1 articles)
HN Discussion 20 top-level · 30 replies
4ndrewl 2025-02-14 07:54 UTC link
With friends like these, who needs enemies?
nxobject 2025-02-14 08:11 UTC link
Ironically enough, the WHOIS record points to CISA – the Cybersecurity and Infrastructure Security Agency. Very confidence-building.
zoelow 2025-02-14 08:15 UTC link
petargyurov 2025-02-14 08:24 UTC link
Move fast and break things, government edition.
rainforest 2025-02-14 08:26 UTC link
For a while the /join page was blocked by cloudflare WAF yesterday - I wonder if this is why.
fecal_henge 2025-02-14 08:39 UTC link
Can someone help me with what roro means?
cyberlimerence 2025-02-14 09:07 UTC link
Every other intelligence agency on the planet is about to scoop a ton of American data via cyber and basic HUMINT. It's free for all out there, I guess.
tjpnz 2025-02-14 09:34 UTC link
They're promising to deliver security next quarter.
EvanKnowles 2025-02-14 09:40 UTC link
If I click Join I am immediately redirected to a "Sorry, you have been blocked You are unable to access doge.gov" CloudFlare page. That's odd.
Brendinooo 2025-02-14 13:03 UTC link
Does anyone want to talk about the hack itself? Can anyone give more details than "left their database open"? I came to this site hoping for a real discussion about that and didn't see it here yet...
deadbabe 2025-02-14 17:50 UTC link
Maybe they should fire these kids and replace them with REAL engineers.

And I know some of those kids probably read Hackernews, so here’s the advice: put away ChatGPT and learn what the fuck you’re doing.

tolmasky 2025-02-14 17:50 UTC link
I guess DOGE lives up to "Vox Populi, Vox Dei" even better than Twitter.
danso 2025-02-14 18:29 UTC link
Worth noting that the U.S. Digital Service (USDS, i.e the org that DOGE has now subsumed) has for a long while been experts at building and deploying static websites for the federal government. And doing it completely in the open. Within minutes you can literally clone and re-deploy all of httsp://usds.gov — 150MB of 2,700 assets and documents, built on Jekyll — locally or on S3. They've even written out the complete deployment instructions:

https://github.com/usds/website

gvx 2025-02-14 18:42 UTC link
Everyone knows investing in cybersecurity is just wasteful spending!
linuxhansl 2025-02-14 19:22 UTC link
Is that really a surprise to anyone. DOGE is theater, a stage show.
insane_dreamer 2025-02-14 21:26 UTC link
Trump/Elon fascism/heroism (depending on your point of view) aside, one thing that concerns me is how quickly is it possible to decide that 1000 employees at a place like the Department of Energy, including 300 at the National Nuclear Security Administration, can be dismissed without any impact on the effectiveness of these agencies.

Even if you do believe that these agencies are bloated with workers who are doing "unnecessary" work, which is possible, it seems very unprudent to make cuts so quickly. And who is qualified to make these decisions? Elon? Some Tesla or SpaceX engineer who wrote some code and put up a website? Come on. WTF do they know about how all these agencies operate and the downstream effects? You think they're taking the time to really think it through?

Now it's possible that prior to taking office, Trump had people with deep understanding of government operations go through everything, and really think things through, and prepare a list of jobs that could be cut without any impact, but if that is the case, it's never been said. Given who Trump has around him to lead these agencies (McMahon for Dept of Ed? An Oil and Gas Lobbyist for BLM? Really?) that doesn't seem likely.

Move fast and break things works fine for a start-up, and might even be fine for more cultural type stuff ("DEI"), but Dept of Energy?

It's like firing two-thirds of your sysadmins because "well, we haven't had any issues with our servers lately, and no breaches, so those people must not be needed".

aqueueaqueue 2025-02-14 22:45 UTC link
I am wondering if it would have been more of an effect to instead of this add some DEI trolling ... April 1st level of foolery so people think it is real and then get Twitter riled up on it.
IAmGraydon 2025-02-15 04:01 UTC link
Does anyone else see what’s really going on here? Naming a “government agency” after a meme coin? Wearing a hat in the Oval Office while talking over the (literally) sitting president? Elon is attempting to telegraph that he has no respect for the institutions of our country. Why do you think Trump did something as petty as renaming the Gulf of Mexico? It’s a litmus test to see who will follow his most inane power plays. Today, it was put into action when they banned the AP from the Oval Office and AF1 for not bending the knee on this issue. This is far darker than Elon just running amok.
croes 2025-02-15 05:04 UTC link
They claimed the savings site would show receipts not later than Valentine's Day

https://www.doge.gov/savings

Now it says "Receipts coming over the weekend!"

Next time it's: The site is receipt-ready

JKCalhoun 2025-02-15 13:38 UTC link
Wondering why DOGE articles where we apparently are leaking classified info over the internet are being flagged.

This for example: https://news.ycombinator.com/item?id=43051135

(EDIT: Looks like others are wondering too: https://news.ycombinator.com/item?id=43050833)

tennisflyi 2025-02-14 08:42 UTC link
I think they meant "ruh roh" - https://www.youtube.com/watch?v=R3SaxRRfJ4E
average_r_user 2025-02-14 09:28 UTC link
Tinfoil hat mode: "What if" this results from a foreign influence?

But I guess that you don't need to find answers externally when stupidity is a much simpler reason

gavinray 2025-02-14 09:49 UTC link
It's common to sign your handle to exploit/pwn'ed messages.

I'd wager the person who did the edit goes by the name "roro".

dobin 2025-02-14 09:59 UTC link
Its not just this website. Since DOGE, China probably canceled all vacation days for their hackers, as its a free for all. Firing of most so many people including security departments and most likely the (good) femboy furry hackers.

Is the newly created user with name "bigballs" who downloads whole government databases a foreign TA or just DOGE? Who knows. Who cares, certainly not the Government.

The data and access gained currently by China, Russia, NK and SA will continue to be useful until and way after the next war.

bstsb 2025-02-14 10:10 UTC link
same, i'm assuming they've set up a firewall rule on the cloudflare dashboard to block non-internal ips for certain routes
giomasce 2025-02-14 11:08 UTC link
You mean Full Self Security?
bamboozled 2025-02-14 11:19 UTC link
I thought this was a feature to make it easier to leech information ?
cedws 2025-02-14 11:28 UTC link
Elon Musk needs it most of all, he’s the most insecure human in existence.
a012 2025-02-14 13:03 UTC link
My bet is on SQL injection
rsynnott 2025-02-14 13:25 UTC link
> The database it is pulling from can be and has been written to by third parties, and will show up on the live website.

Not enough detail to say for sure; could be SQL injection, could be credentials exposed in the frontend.

internetter 2025-02-14 16:36 UTC link
According to a source of mine, there were unsecured API endpoints for modification
davidw 2025-02-14 17:43 UTC link
Or they could just, like, call Tulsi Gabbard.
monocasa 2025-02-14 17:47 UTC link
Someone unminified the js, and it turned out that a bunch of the rest endpoints it knew about were just unverified crud endpoints for the site.

https://archive.ph/2025.02.14-132833/https://www.404media.co...

guywithahat 2025-02-14 17:51 UTC link
The one good thing about them all being so young is it explains why I never got an interview; at 28 I was too old to ever get a job there
PokemonNoGo 2025-02-14 17:55 UTC link
Scooby dooby Doo...
palmotea 2025-02-14 18:07 UTC link
> Maybe they should fire these kids and replace them with REAL engineers.

Nah, they'll want reasonable pay, reasonable hours, and won't confuse their boss for a living god. They may even have some self-confidence and morals, which would be a total deal breaker.

guywithahat 2025-02-14 18:09 UTC link
I mean the article is paywalled but it sounds like this is isolated to their site-displayed twitter feed; basically the site was hosted by cloudflare and you could insert your own fake tweets into what was recorded on the site (but not on the actual DOGE twitter feed). I don't think any data was actually compromised
caycep 2025-02-14 19:17 UTC link
I see recent changes being made, are the prior timestamps available for archiving?
enraged_camel 2025-02-14 19:23 UTC link
They are doing tremendous damage for something that is supposed to be a stage show. Among everything they've done over the past three weeks, HUD is being gutted as we speak and the company a friend works at lost $100 million in contracts practically overnight.
anigbrowl 2025-02-14 19:43 UTC link
These are ideologues, not earnest professionals.
mikepurvis 2025-02-14 20:06 UTC link
The real damage that has already been done is almost certainly incalculable. As just a very small taste:

https://www.schneier.com/blog/archives/2025/02/doge-as-a-nat...

e2le 2025-02-14 20:10 UTC link
Perhaps I'm misunderstanding the situation, but isn't this similar to Hillary’s E-Mail?[1]

>Over at OPM, reports indicate that individuals associated with DOGE connected an unauthorized server into the network.

[1]: https://www.schneier.com/blog/archives/2025/02/doge-as-a-nat...

superfrank 2025-02-14 20:17 UTC link
DOGE is a complete farce, but I think there's an important to not just write this off as a stage show and the people buying into it as idiots. There are a lot of people who feel that government isn't working for them and so when they see things like "8 million dollars spent on condoms for Palestinians" they're already primed to get angry about it. Musk/DOGE's actions may all be for spectacle, but he's tapping into some very real emotions that he wouldn't be able to tap into if people felt the government was working for them. DOGE is a symptom of a larger problem. Even if Musk and DOGE are completely discredited, if we don't figure out a way to make it so the average citizen feels like they're getting their money's worth from the government, it's just a matter of time until someone else steps in to exploit that feeling for their own gain.
ivewonyoung 2025-02-14 20:19 UTC link
Are they just running shell scripts off the public web for deploying federal gov sites that are targeted by nation states?

From the docker file:

  curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.3/install.sh
itronitron 2025-02-14 20:26 UTC link
if you think you own everything then there are no external threats
muglug 2025-02-14 20:34 UTC link
[flagged]
softwaredoug 2025-02-14 20:54 UTC link
The numbers they claim to save are like trying to turn your household budget around by cutting out a weekly latte.

If you really want to make big financial changes, you need a lot more income, or cut serious costs - like a car payment or downsize your house. In the case of DOGE, I haven't seen them touch DoD or any of the massive medical programs, etc.

whoomp12342 2025-02-14 20:59 UTC link
ow, put it back
nomel 2025-02-14 21:10 UTC link
Is there any evidence that the contents of the database are accessible? The linked article doesn't make these claims.

Is there any evidence that the database for this microblog of a cloud flare hosted website has anything of importance in it?

Are you also (alone) suggesting there's a tunnel from cloud flare (where this is hosted) to some larger government database?

You may want to RTFA: https://archive.ph/wy1Wt

Editorial Channel
What the content says
+0.70
Article 19 Freedom of Expression
High Advocacy Framing Coverage
Editorial
+0.70
SETL
+0.26

Core expression of investigative journalism and free speech; advocates for public's right to know about government systems and accountability

+0.50
Article 12 Privacy
Medium Advocacy Framing
Editorial
+0.50
SETL
0.00

Strongly advocates for privacy protection and data security by exposing critical vulnerability in government database

+0.40
Article 21 Political Participation
Medium Advocacy Framing
Editorial
+0.40
SETL
0.00

Advocates for government accountability and transparency as foundational to democratic participation

+0.30
Preamble Preamble
Medium Advocacy Framing
Editorial
+0.30
SETL
0.00

The article documents a government website designed to demonstrate transparency but found to be insecure, emphasizing the importance of government accountability in protecting systems and rights

+0.20
Article 28 Social & International Order
Medium Framing
Editorial
+0.20
SETL
+0.14

Documents failure of proper government administration and security infrastructure

-0.20
Article 3 Life, Liberty, Security
Medium Framing Coverage
Editorial
-0.20
SETL
-0.28

Documents failure of government to maintain security of critical systems and protect citizens' safety

ND
Article 1 Freedom, Equality, Brotherhood

Not addressed

ND
Article 2 Non-Discrimination

Not addressed

ND
Article 4 No Slavery

Not addressed

ND
Article 5 No Torture

Not addressed

ND
Article 6 Legal Personhood

Not addressed

ND
Article 7 Equality Before Law

Not addressed

ND
Article 8 Right to Remedy

Not addressed

ND
Article 9 No Arbitrary Detention

Not addressed

ND
Article 10 Fair Hearing

Not addressed

ND
Article 11 Presumption of Innocence

Not addressed

ND
Article 13 Freedom of Movement

Not addressed

ND
Article 14 Asylum

Not addressed

ND
Article 15 Nationality

Not addressed

ND
Article 16 Marriage & Family

Not addressed

ND
Article 17 Property

Not addressed

ND
Article 18 Freedom of Thought

Not addressed

ND
Article 20 Assembly & Association

Not addressed

ND
Article 22 Social Security

Not addressed

ND
Article 23 Work & Equal Pay

Not addressed

ND
Article 24 Rest & Leisure

Not addressed

ND
Article 25 Standard of Living

Not addressed

ND
Article 26 Education

Not addressed

ND
Article 27 Cultural Participation

Not addressed

ND
Article 29 Duties to Community

Not addressed

ND
Article 30 No Destruction of Rights

Not addressed

Structural Channel
What the site does
+0.60
Article 19 Freedom of Expression
High Advocacy Framing Coverage
Structural
+0.60
Context Modifier
ND
SETL
+0.26

404 Media operates as independent platform exercising free expression and enabling government transparency

+0.50
Article 12 Privacy
Medium Advocacy Framing
Structural
+0.50
Context Modifier
ND
SETL
0.00

404 Media demonstrates commitment to privacy and responsible investigation of system vulnerabilities

+0.40
Article 21 Political Participation
Medium Advocacy Framing
Structural
+0.40
Context Modifier
ND
SETL
0.00

404 Media supports democratic participation through transparent investigative reporting

+0.30
Preamble Preamble
Medium Advocacy Framing
Structural
+0.30
Context Modifier
ND
SETL
0.00

404 Media operates as an independent journalism platform dedicated to government accountability and transparency

+0.20
Article 3 Life, Liberty, Security
Medium Framing Coverage
Structural
+0.20
Context Modifier
ND
SETL
-0.28

404 Media reports security vulnerabilities responsibly and independently

+0.10
Article 28 Social & International Order
Medium Framing
Structural
+0.10
Context Modifier
ND
SETL
+0.14

404 Media reports on government system administration failures

ND
Article 1 Freedom, Equality, Brotherhood

Not addressed

ND
Article 2 Non-Discrimination

Not addressed

ND
Article 4 No Slavery

Not addressed

ND
Article 5 No Torture

Not addressed

ND
Article 6 Legal Personhood

Not addressed

ND
Article 7 Equality Before Law

Not addressed

ND
Article 8 Right to Remedy

Not addressed

ND
Article 9 No Arbitrary Detention

Not addressed

ND
Article 10 Fair Hearing

Not addressed

ND
Article 11 Presumption of Innocence

Not addressed

ND
Article 13 Freedom of Movement

Not addressed

ND
Article 14 Asylum

Not addressed

ND
Article 15 Nationality

Not addressed

ND
Article 16 Marriage & Family

Not addressed

ND
Article 17 Property

Not addressed

ND
Article 18 Freedom of Thought

Not addressed

ND
Article 20 Assembly & Association

Not addressed

ND
Article 22 Social Security

Not addressed

ND
Article 23 Work & Equal Pay

Not addressed

ND
Article 24 Rest & Leisure

Not addressed

ND
Article 25 Standard of Living

Not addressed

ND
Article 26 Education

Not addressed

ND
Article 27 Cultural Participation

Not addressed

ND
Article 29 Duties to Community

Not addressed

ND
Article 30 No Destruction of Rights

Not addressed

Supplementary Signals
How this content communicates, beyond directional lean. Learn more
Epistemic Quality
How well-sourced and evidence-based is this content?
0.66 medium claims
Sources
0.6
Evidence
0.7
Uncertainty
0.7
Purpose
0.8
Propaganda Flags
No manipulative rhetoric detected
0 techniques detected
Emotional Tone
Emotional character: positive/negative, intensity, authority
urgent
Valence
-0.6
Arousal
0.7
Dominance
0.6
Transparency
Does the content identify its author and disclose interests?
0.70
✓ Author
More signals: context, framing & audience
Solution Orientation
Does this content offer solutions or only describe problems?
0.15 problem only
Reader Agency
0.3
Stakeholder Voice
Whose perspectives are represented in this content?
0.50 3 perspectives
Speaks: individualsinstitution
About: governmentcorporation
Temporal Framing
Is this content looking backward, at the present, or forward?
present immediate
Geographic Scope
What geographic area does this content cover?
national
United States
Complexity
How accessible is this content to a general audience?
moderate medium jargon general
Audit Trail 11 entries
2026-02-28 09:32 rater_validation_warn Light validation warnings for model llama-4-scout-wai: 1W 1R - -
2026-02-28 09:32 model_divergence Cross-model spread 0.33 exceeds threshold (4 models) - -
2026-02-28 09:32 eval_success Light evaluated: Moderate positive (0.56) - -
2026-02-28 09:32 eval Evaluated by llama-4-scout-wai: +0.56 (Moderate positive)
2026-02-28 09:24 model_divergence Cross-model spread 0.33 exceeds threshold (3 models) - -
2026-02-28 09:24 eval_success Light evaluated: Moderate positive (0.40) - -
2026-02-28 09:24 eval Evaluated by llama-3.3-70b-wai: +0.40 (Moderate positive)
2026-02-28 09:24 rater_validation_warn Light validation warnings for model llama-3.3-70b-wai: 0W 1R - -
2026-02-28 08:20 model_divergence Cross-model spread 0.33 exceeds threshold (2 models) - -
2026-02-28 08:20 eval Evaluated by claude-haiku-4-5-20251001: +0.35 (Moderate positive)
2026-02-28 01:13 eval Evaluated by claude-haiku-4-5: +0.68 (Strong positive)