this post was submitted on 01 Feb 2025
599 points (98.2% liked)

News

24288 readers
4110 users here now

Welcome to the News community!

Rules:

1. Be civil


Attack the argument, not the person. No racism/sexism/bigotry. Good faith argumentation only. This includes accusing another user of being a bot or paid actor. Trolling is uncivil and is grounds for removal and/or a community ban. Do not respond to rule-breaking content; report it and move on.


2. All posts should contain a source (url) that is as reliable and unbiased as possible and must only contain one link.


Obvious right or left wing sources will be removed at the mods discretion. We have an actively updated blocklist, which you can see here: https://lemmy.world/post/2246130 if you feel like any website is missing, contact the mods. Supporting links can be added in comments or posted seperately but not to the post body.


3. No bots, spam or self-promotion.


Only approved bots, which follow the guidelines for bots set by the instance, are allowed.


4. Post titles should be the same as the article used as source.


Posts which titles don’t match the source won’t be removed, but the autoMod will notify you, and if your title misrepresents the original article, the post will be deleted. If the site changed their headline, the bot might still contact you, just ignore it, we won’t delete your post.


5. Only recent news is allowed.


Posts must be news from the most recent 30 days.


6. All posts must be news articles.


No opinion pieces, Listicles, editorials or celebrity gossip is allowed. All posts will be judged on a case-by-case basis.


7. No duplicate posts.


If a source you used was already posted by someone else, the autoMod will leave a message. Please remove your post if the autoMod is correct. If the post that matches your post is very old, we refer you to rule 5.


8. Misinformation is prohibited.


Misinformation / propaganda is strictly prohibited. Any comment or post containing or linking to misinformation will be removed. If you feel that your post has been removed in error, credible sources must be provided.


9. No link shorteners.


The auto mod will contact you if a link shortener is detected, please delete your post if they are right.


10. Don't copy entire article in your post body


For copyright reasons, you are not allowed to copy an entire article into your post body. This is an instance wide rule, that is strictly enforced in this community.

founded 2 years ago
MODERATORS
 

Summary

A vulnerability in the new OPM email server allowed anyone to send mass messages to federal employees, exposing poor cybersecurity.

Over 13,000 NOAA staff received spam and vulgar messages, including crude jokes about Trump and bizarre newsletters, causing widespread outrage.

The breach resulted from an overhaul led by Elon Musk that installed underqualified personnel and an insecure in-house system, sparking a class-action lawsuit for cybersecurity failures.

The unsecured system also inadvertently revealed ties to Project 2025 and a plan to gather government employee data as Trump’s loyalists reshape federal operations.

you are viewing a single comment's thread
view the rest of the comments
[–] MrEff@lemmy.world 54 points 1 day ago (2 children)

It's worse than you think. Last week we got an email that looked like strait up fishing spam demanding that we were to email back "yes" confirming that we got the email. So many people even reported it as spam that we had supervisors have to directly tell us that it was legit. Then they sent out a second email with a warning that is was in fact legit and to respond to that email with "yes" if we got that one.

On the back end at OPM: Musk forced his way in and demanded to redo the email servers. The IT told him it wasn't possible for what he was asking. So he brought in his own goons to install a non government server with unknown software and unknown security configurations and they plugged it into the OPM network to spoof it as an official OPM server, then sent out those emails.

And sure enough, the idiot didn't didn't configure the security correctly or let official government IT people touch it, it ended up backdooring into the entire government HR system, and it had every active government email that responded "yes" to his stupid email that we were required to. And now we know it was compromised. There is no telling what foreign governments now have all of that info as well as what other backdoors they have installed.

[–] prole@lemmy.blahaj.zone 1 points 5 hours ago

Jesus fucking Christ, someone needs to stop these evil motherfuckers

[–] towerful@programming.dev 37 points 1 day ago (2 children)

Holy shit.
That's some shit that contravenes every security briefing, every security best practice.
Then they go and spoof a legit government installation with their own bullshit?!
Fucking Hilary and her email servers. But like times 10. Legitimately compromising the US government communications.
Why is this lawsuits, why isn't this treason?!

[–] JasonDJ@lemmy.zip 34 points 23 hours ago

This is way worse than Hillary's email servers.

Hillary occasionally conducted government business on an email servers owned by her, but also on her (not .gov) domain.

I never knew the details. But I wouldn't doubt that for simplicity sake they probably had multiple accounts configured on the same phone. At that point, it's incredibly easy to accidentally respond or start a chain from the wrong address. Who among us hasn't done that, we actually grew up with this stuff.

What Musk did was set up his own separate infrastructure to send and receive emails, on a .gov domain, and use that server, as a private contractor to the president, to circumvent tons of critical processes and security practices, in order to push his clients agenda.

The point of that agenda is to nip checks-and-balances in the balls so the president can unilaterally enact "his" (or the highest bidders...Heritage, Musk, Thiel, Federalists, Illuminati, Skull and Bones, whatever, at this point it's all the same) agenda.

It. Is. Actual. Treason.

By an illegal immigrant, no less.

[–] dhork@lemmy.world 19 points 1 day ago

why isn't this treason?!

Because Musk bought the election for Trump, and now Musk do whatever he wants.