Amid Hunt for Crime in DC, Whistleblower Implicates Ed "Big Balls" Coristine and John Roberts - emptywheel
Briefly

Right-wing governors are deploying National Guard members away from their communities to pursue an individual tied to criminal hackers. A whistleblower complaint from Social Security's Chief Data Officer, Chuck Borges, alleges DOGE personnel created a live copy of the Social Security database. The complaint alleges equipment pin access and write access that could mask users and violate IRS protections, that DOGE restored and expanded access immediately after a temporary restraining order, and that DOGE replicated SSA's Numerical Identification System on an insecure server. A risk assessment warned that importing NUMIDENT into the cloud could catastrophically expose SSA beneficiaries and PII.
As I've noted repeatedly, there should be far more attention to the fact that right wing Governors are forcing members of their National Guard to leave their homes, their families, and their jobs to avenge Ed "Big Balls" Coristine, the privileged white kid with ties to criminal hackers who allegedly got assaulted when out past 3AM one night. Most are sending their own constituents away from their homes to fight crime, allegedly, in a safer place than their own home.
When DOGE personnel were given access to Social Security data in mid-March, they had equipment pin access (meaning actions could not be traced to one user) and write access, potentially violating laws protecting IRS data. After Judge Ellen Lipton Hollander imposed a Temporary Restraining Order on DOGE access on March 20, DOGE almost immediately restored - and expanded - access to Social Security data, potentially exposing those who granted access to CFAA hacking charges.
A risk assessment of recreating a live Social Security database described the catastrophic risk involved. Developers (presumably DOGE) planned to import NUMIDENT into the cloud, and because AWS-ACI is an extension ofthe SSA network, any other SSA production data and PII could also be imported; " unauthorized access to the NUMIDENT would be considered catastrophic impact to SSA beneficiaries and SSA programs" [emphasis Borges']; Since earlier this month, Borges has been trying to understand the impact of that
Read at emptywheel
[
|
]