| ▲ | `123456' password used in Danish CPR data breach(cphpost.dk) | ||||||||||||||||||||||||||||||||||||||||||||||
| 78 points by baal80spam an hour ago | 51 comments | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ionwake 4 minutes ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Im sorry I know Im getting old but when I say everyone is responsible they should be from the press who might focus too much on essentially the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks. I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder. You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it, is crazy. Its just moral/leadership decay. I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | zkmon 21 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal. It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | zweifuss 39 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ano-ther 15 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
So it was actually two weaknesses: * The non-password at a two-person IT company (Pays ApS) * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour). | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | sokols 25 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | piker 43 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
That’s the same combination I have on my luggage! | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | mattlondon 19 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
If only they had insisted on an 8 character password! | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ZuoCen_Liu 3 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ... | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | donalhunt 44 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen. Equivalent to social security information in the US I guess. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | INTPenis 44 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here! Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that? | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bricss 2 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
If only there was an algorithm for password strength estimation > . < | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | caaqil 8 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | imdsm 44 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
not ideal | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | sneak 35 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence? | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | croes 24 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Did they have MFA? | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | tokai 29 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | lifestyleguru 41 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | m00dy 42 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
lol, it's a joke right ? | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | aussieguy1234 3 minutes ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||
They forgot to write it on a post-it note attached to the monitor /s | |||||||||||||||||||||||||||||||||||||||||||||||