Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)
> It's tussle between two counter-acting forces at play.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"
The guys who are really into keyboard layouts would argue vehemently that 123456 is more ergonomic as it's an "inward roll" vs 6 consecutive presses of a key that aligns to the pinky
They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers.
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
and make the people who didn't put any sort of limits on how many records can be downloaded before there has to be a check on what is going on or any of the other stupid security holes that were found, make them criminally responsible as well. At some point you can be sure you'll be imprisoning someone for making a typing mistake (accidentally commented out some code) or a logic mistake (I should have said IS NOT, but instead I said IS) or just being tired.
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.
Equivalent to social security information in the US I guess.
For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
There have been collisions in Sweden, but that was due to lots of immigrants coming from the middle east that did not know when they where born. So many of them picked first of January. They “solved” it by overflowing to the next days.
They said sex is encoded in it, so it’s probably a sex digit.
edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.
It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
Oops, can I delete my comment, it was a copy paste mistake!
> Oops, can I delete my comment, it was a copy paste mistake!
What do you mean? You can safely post your passwords on the internet.
Equivalent to social security information in the US I guess.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.
edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.
It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
Thieves give it back now!
It was run by DXC Technology, the Danish branch of a US software house.
When doing a contract on such programs the Danish government must take the cheapest offer by rule
Since then I think medical data science is mainly a waste of tax payer's money.