Live data from Hacker News

Swedish Government Scrambles to Contain Damage from Data Breach

nytimes.com

21–30 of 140 posts

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#21

Reading the article, I am reminded of the story of the famous Swedish ship, the Vasa [0], which sank in the XVII century because, ultimately, no one wanted to say no to the king: when the engineers saw there was a massive problem ahead ("your boat don't float"), the management didn't dare tell the King, leading to catastrophe[1]. It's a good lesson, I hope we learn it someday. [0] : https://en.wikipedia.org/wiki/Vasa…

For some reason, I think parts of this writeup were debunked, but it's still one of my favorite reads:

http://faculty.up.edu/lulay/failure/vasacasestudy.pdf [pdf]

Thank you for reminding me about the Vasa!

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#23
"It said that the project manager for the outsourcing agreement admitted during questioning that “he had no knowledge whatsoever of how to ensure security.”

You'd think someone would come in an consult on this, however, and setup basic protocols. A PM isn't expected to be a security expert -- that's what security experts are for.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#24
This is different because it concerns a government, but as long as the CEO doesn't go to jail for IT breaches (Sony,...) and grossly negligent IT decisions (British Airways), nothing will change with data security.

The second the law changes, CEOs will make it a personal matter sound decisions are made.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#25
Here's a summary of what foreign powers got access to:

- identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information

Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email asking the contractor to clear them from the database manually.

My country is a joke.

SÄPO knew about this in 2015, and recommended against it, but the Transport Agency still went through with the deal. How they could even be allowed to do that is beyond me.

The director general of the Transport Agency, and the person ultimately responsible for the leak, was fined a mere $8500 (which is half of what she allegedly would earn in a _month_) for leaking highly classified information to foreign powers - an act that would be punished as high treason in any sane country. Either she knew exactly what she was doing, meaning the Russians paid a meagre $8500 for full access to a database containing top secret information, or (more likely) she was just that stupid, meaning possibly hostile powers got this information for free.

But hey, that's Sweden, where incompetent people become director generals of big government agencies, and any screw up they get caught with is excused by saying that you didn't know better.

Here, Swedes believe that Trump is such a catastrophe, and wonder why Americans could vote for him. We should instead look at our own pathetic "feminist" government, and ask ourselves how and why we got here.

But hey, luckily for everyone we don't have nukes. We'd probably accidentally give the launch codes to Saudi Arabia/Palestine, and respond by giving the person responsible for the leak a small fine while the rest of the world burned in the war that erupted after Israel got nuked.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#26
post #22

The article doesn't mention many specifics, but I'd say when it comes to national security, Sweden has bigger (and more apparent) long-term issues than a handful of known IT professionals from Eastern Europe having access to private DBs.

It blows my mind that rich country like sweden outsource super important info to ibm but on the other side accepts 'refugees' heavily.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#27

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

I must say that if the data leak leads to the fall of the gouvernement, it will force everyone else to take it seriously. That would be a big advance to the credit of Sweden. (In most countries the gouvernement wouldn't fall for "so little")

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#28
post #26
post #22

The article doesn't mention many specifics, but I'd say when it comes to national security, Sweden has bigger (and more apparent) long-term issues than a handful of known IT professionals from Eastern Europe having access to private DBs.

It blows my mind that rich country like sweden outsource super important info to ibm but on the other side accepts 'refugees' heavily.

I don't understand the connection between the two. Do you mean the financial considerations?

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#29
The further the data gets from the original designers of the system, the less likely it's being protected properly.

I've seen this time and again not just in outsourcing but also in regime change at companies where employees and management turn over.

Pretty soon you've got a whole host of legal contracts with customers and regulatory promises saying you provide X, Y, Z encryption, data redundancy, offsite backups, support contracts, and so on -- but you're doing none of it.

I wonder to what extent outsourcing ends up being cheaper precisely because they're not following the framework that the in-house crew implemented and hopefully stuck with.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#30

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

I'm not familiar with Sweden's "feminist" government. Can you help foreigners understand? Was it, for example, a matter of existing staff members hiring new ones based on gender rather than on competence? Any reading material on the matter? It sounds like it's a well-known political argument in Sweden, I just don't know the background.
Post reply on HN