| ▲ | ano-ther an hour ago |
| So it was actually two weaknesses: * The non-password at a two-person IT company (Pays ApS) * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour). |
|
| ▲ | tuwtuwtuwtuw an hour ago | parent [-] |
| There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms. |
| |
| ▲ | nylonstrung 26 minutes ago | parent | next [-] | | Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously | |
| ▲ | olau an hour ago | parent | prev [-] | | Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way. I don't think any IT infrastructure is doing it, it's all by a national single-sign on system. | | |
| ▲ | tuwtuwtuwtuw 32 minutes ago | parent [-] | | I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers. |
|
|