• SuperCub@sh.itjust.works
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    15 hours ago

    Did anyone come up with a demeaning name to call these little fucks yet? I submit “Elon’s cucks”

    Share yours.

  • astrsk@fedia.io
    link
    fedilink
    arrow-up
    50
    ·
    1 day ago

    Absolutely every prong of this attack on the government is for one goal: to declare mass emergencies by way of manufactured errors and chaos in order to seize ultimate power.

  • gressen@lemm.ee
    link
    fedilink
    arrow-up
    71
    ·
    2 days ago

    Elez did in fact have write access, allowing him to push unvetted and untested changes straight to the Treasury’s payments system — a nightmare scenario that could introduce all sorts of cybersecurity vulnerabilities and leave doors open for adversary hacker groups

    I feel for whoever has to deal with the fallout.

    • meyotch@slrpnk.net
      link
      fedilink
      arrow-up
      46
      ·
      1 day ago

      Us. It’s us who will have to deal with this.

      This is like a reverse Mr Robot scenario.

  • 52fighters@lemmy.sdf.org
    link
    fedilink
    arrow-up
    25
    ·
    1 day ago

    The article doesn’t say what he did, only that he had write abilities. Did he use them? How do we know? If yes, what were they specifically?

    • draughtcyclist@lemmy.world
      link
      fedilink
      arrow-up
      22
      ·
      1 day ago

      He could push directly to main/prod, so there weren’t explicitly any code reviews or necessarily oversight. Also, that code would be private. Only an insider with repository access could tell us that.

      That said, I also want to know. I’m guessing we’ll hear about it soon enough.

          • Maalus@lemmy.world
            link
            fedilink
            arrow-up
            1
            arrow-down
            8
            ·
            1 day ago

            Not really? Every single maintainer / owner of a repository can do that. The only thing stopping them is protecting a branch. And even that isn’t a thing in git, it’s just something that providers like github or gitlab did to prevent people accidentally pushing to main like that. So they got maintainer access and that’s the entire story?

  • kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    19
    ·
    1 day ago

    WAS HE CAUGHT WITH HIS HANDS IN THE COOKIE JAR?

    Does it really matter whether he did?

    Der Müskrat has been screaming “LEMME AT THEM COOKIES” for a month straight while hiring unpaid cookie monsters. Whether or how it already happened, it’s pretty clear the cookie jar is gonna get raided by someone.

    • FirstCircle@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      He wouldn’t want to get his young tech bro hands dirty with Fortran. Surely there are cross-compilers that will translate your mission-critical payments Fortran to JS, maybe with an intermediate Rust and/or TS step. Fortran -> TS -> Rust -> JS, or similar, it would be quite a feat to behold. Never mind testing (that would be “wasteful” and “inefficient”), just push to prod and sit back and watch then chaos unfold, then blame it all on Biden and, I dunno, Bill Gates maybe.

    • GreenKnight23@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      he didn’t quit because of those racist tweets.

      he quit because the bitch was embarrassed for trying to hack FORTRAN by dropping a JS lib into a repo like it was some kind of ABC made-for-tv spy movie.

    • callcc@lemmy.world
      link
      fedilink
      arrow-up
      18
      ·
      2 days ago

      Rofl, and now you need a toolchain of biblical extent to compile it all. Webpack, npm, rollup, ts, etc.