Citat:
Ursprungligen postat av
2006
Elon Musks DOGE-webbplats har visat sig vara osäker eftersom vem som helst kan redigera den. Istället för att använda statliga servrar hämtar den data från en öppen databas, vilket redan har lett till att skämtmeddelanden lagts in. Sajten påstår sig vara en officiell regeringssida men verkar slarvigt uppbyggd och dåligt hanterad. Trots Musks påståenden om transparens har sidan varit tom sedan lanseringen och uppdaterades nyligen med inlägg från DOGE:s X-konto.
https://doge.gov/

Jag undrar om Elon Musk inser att den här clown-showen kan inverka på hans andra verksamheter.
De som var först med avslöjandet:
Anyone Can Push Updates to the DOGE.gov Website
https://www.404media.co/anyone-can-push-updates-to-the-doge-gov-website-2/
Citat:
The doge.gov website that was spun up to track Elon Musk’s cuts to the federal government is insecure and pulls from a database that can be edited by anyone, according to two separate people who found the vulnerability and shared it with 404 Media. One coder added at least two database entries that are visible on the live site and say “this is a joke of a .gov site” and “THESE ‘EXPERTS’ LEFT THEIR DATABASE OPEN -roro.”
DOGE.gov Debacle: How a Government Website Went to the Dogs and What It Means for Cybersecurity
https://securityboulevard.com/2025/02/doge-gov-debacle-how-a-government-website-went-to-the-dogs-and-what-it-means-for-cybersecurity/
Citat:
Infrastructure Setup
The DOGE website was built using Cloudflare Pages, a platform typically used for hosting static websites, rather than being hosted on secure government servers This choice of infrastructure raises questions about the decision-making process and the priorities set by the DOGE team.
Database Vulnerability
The core of the security issue lies in the website's database configuration. The site was pulling data from an external database that was left open and accessible to third parties. This setup allowed anyone to make edits to the database, which were then reflected on the live doge.gov website.
Lack of Access Controls
The incident reveals a complete absence of proper access controls and authentication mechanisms. There were no apparent restrictions on who could modify the database, leaving it wide open for anyone to manipulate.
Code Quality and Security Practices
One of the anonymous sources described the website as "hastily thrown together," with numerous mistakes and sensitive information exposed in the page source code. This suggests a lack of proper code review, security testing, and adherence to best practices in web development.