Remix.run Logo
▲ `123456' password used in Danish CPR data breach(cphpost.dk)
78 points by baal80spam an hour ago | 51 comments
▲ionwake 4 minutes ago | parent | next [-]

Im sorry I know Im getting old but when I say everyone is responsible they should be from the press who might focus too much on essentially the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.

I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.

You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it, is crazy. Its just moral/leadership decay.

I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.

▲zkmon 21 minutes ago | parent | prev | next [-]

I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

▲ano-ther 12 minutes ago | parent | next [-]

With two people in the company, there is not a lot of room for corporate games though.

> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

▲ulfbert_inc 9 minutes ago | parent | prev | next [-]

You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)

▲kay_o 5 minutes ago | parent | prev | next [-]

Touch one hardware key for every interaction then, not 123456, the hell?

▲tialaramex 9 minutes ago | parent | prev | next [-]

> It's tussle between two counter-acting forces at play.

It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

▲tossandthrow 5 minutes ago | parent [-]

I would love to hear about a world where security and productivity are not counter acting forces.

For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

If you can just create a world for that simple case, then I will rest my case.

▲altmanaltman 6 minutes ago | parent | prev [-]

Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"

▲zweifuss 39 minutes ago | parent | prev | next [-]

I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.

▲sethammons 35 minutes ago | parent [-]

What would that accountability look like?

▲gunalx 32 minutes ago | parent | next [-]

Not existing preferably.

▲tossandthrow 16 minutes ago | parent | next [-]

This is the likely outcome. It was a company employing 2 people.

▲tannertech 27 minutes ago | parent | prev [-]

Strange way to say prison time. Or if you meant capital punishment harsh but fair.

▲lifestyleguru 23 minutes ago | parent | prev [-]

Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.

▲ano-ther 15 minutes ago | parent | prev | next [-]

So it was actually two weaknesses:

* The non-password at a two-person IT company (Pays ApS)

* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).

▲tuwtuwtuwtuw 2 minutes ago | parent [-]

There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.

▲sokols 25 minutes ago | parent | prev | next [-]

I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.

▲zweifuss 20 minutes ago | parent | next [-]

A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.

▲iLoveOncall 22 minutes ago | parent | prev [-]

Or simply make people who choose insecure passwords criminally responsible for the fallout.

▲piker 43 minutes ago | parent | prev | next [-]

That’s the same combination I have on my luggage!

▲justinclift 29 minutes ago | parent | next [-]

The Spaceballs piece about it: https://www.youtube.com/watch?v=a6iW-8xPw3k

▲HPsquared 24 minutes ago | parent | prev | next [-]

Funnily enough, luggage calls back to those TSA locks.

▲Sau1707 33 minutes ago | parent | prev [-]

I bet you are not the only one!

▲mattlondon 19 minutes ago | parent | prev | next [-]

If only they had insisted on an 8 character password!

▲LarsKrimi 11 minutes ago | parent | next [-]

There are some unconfirmed rumors going that the maximum password length for the API was 8 characters...

▲fifilura 17 minutes ago | parent | prev [-]

1Password#

Oops, can I delete my comment, it was a copy paste mistake!

▲lifestyleguru 11 minutes ago | parent [-]

> **********

> Oops, can I delete my comment, it was a copy paste mistake!

What do you mean? You can safely post your passwords on the internet.

▲_kb 5 minutes ago | parent [-]

hunter2

▲ZuoCen_Liu 3 minutes ago | parent | prev | next [-]

Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...

▲donalhunt 44 minutes ago | parent | prev | next [-]

In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.

Equivalent to social security information in the US I guess.

▲gus_massa a minute ago | parent | next [-]

For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.

Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.

▲lordnacho 30 minutes ago | parent | prev [-]

It's unique, but it encodes your birthday and sex.

There's only 500 numbers it could be, assuming someone knows those other things about you.

In any case, there are alternative systems for authorisation.

▲usrnm 21 minutes ago | parent [-]

You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?

▲piva00 19 minutes ago | parent | next [-]

It's Denmark, it won't have 1k babies born the same day.

It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.

▲ls65536 2 minutes ago | parent [-]

That format looks like it would allow for up to 10k per day. Unless one of those X's is a check digit?

▲tannertech 18 minutes ago | parent | prev [-]

That's a problem for future Denmark!

▲INTPenis 44 minutes ago | parent | prev | next [-]

I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!

Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

▲bricss 2 minutes ago | parent | prev | next [-]

If only there was an algorithm for password strength estimation > . <

▲caaqil 8 minutes ago | parent | prev | next [-]

It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.

▲imdsm 44 minutes ago | parent | prev | next [-]

not ideal

▲tannertech 9 minutes ago | parent [-]

yeah it's rather unfortunate isn't it

▲sneak 35 minutes ago | parent | prev | next [-]

The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?

▲LarsKrimi 31 minutes ago | parent [-]

Privatization

It was run by DXC Technology, the Danish branch of a US software house.

When doing a contract on such programs the Danish government must take the cheapest offer by rule

▲GuestFAUniverse 26 minutes ago | parent [-]

What could go wrong? /S

▲croes 24 minutes ago | parent | prev | next [-]

Did they have MFA?

▲tokai 29 minutes ago | parent | prev | next [-]

Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.

▲GuestFAUniverse 21 minutes ago | parent [-]

Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.

Since then I think medical data science is mainly a waste of tax payer's money.

▲lifestyleguru 41 minutes ago | parent | prev | next [-]

For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.

▲m00dy 42 minutes ago | parent | prev | next [-]

lol, it's a joke right ?

▲lordnacho 35 minutes ago | parent [-]

Completely real.

▲aussieguy1234 3 minutes ago | parent | prev [-]

They forgot to write it on a post-it note attached to the monitor /s