Live data from Hacker News

Swedish Government Scrambles to Contain Damage from Data Breach

nytimes.com

101–110 of 140 posts

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#101
post #6

Earlier quoted context omitted.

Well, one person was already fired for buying this kind of IBM, but that was just the director general of the authority that leaked the data. The thing most swedes have an issue with is that the government tried to silence the leak for like two years (people really dislike being actively lied to). If they had owned it, I don't think it would have been such a big deal.

It is an old truism that it is the cover-up that gets you. I.e. when we look at scandals, the thing that people generally get in trouble for was part of the cover up rather than the original scandal. Given that this is common knowledge, why do cover-ups keep happening? Theory (A): the failed cover-ups we hear about are only a tiny fraction of the successful ones, so on average it is rational to try and cover things u…

People cover up things because at the time when the cover up starts the damage/cost of exposing the problem and taking the blame far outweighs the cost of doing a cover up. As time progresses (the simple view is) one of two things can happen, either the incident blows over and so the cover up was worth it, or the person needs to keep maintaining and increasing the cover up, thus increasing the damage/cost of the cover up.

In this way we end up with cover ups that cause more damage and are more costly than the original incidents, even though at the onset just owning up to the error would be less costly in the long term.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#102

- identities of undercover operatives... This is terrible. When will people learn to NOT use computers at all for some things. Use typewriters and spend a little bit more on administrative workers. You trade in processing efficiency for making these catastrophic breaches rarer.

I think for actual security you need to practice physical security. No matter if the data is stored on paper or electronically, you will still need to air gap it, and have security and clearance protecting that data.

To put it into perspective Manning only got the data out because they were lax about securing the CD-burner in the computer he was using.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#103
post #79

Earlier quoted context omitted.

It's darwinian; if you don't deliver the savings you are out. One solution would be rigorous research that demonstrated that insourced onshore operations were more effective and cheaper in the long run. But no such research exists, is that because it's hard to do or is it because the result is that offshoring and outsourcing is cheaper and as good?

no its because vested interests want to prove that outsourcing is all rainbows and unicorns.

Ronald Coarse won a Nobel Prize for his work on transaction costs, and how those (usually hidden) costs should be considered when companies externalize business functions.

Coase’s writings and teachings lead directly to the idea of accounting for all costs in any business or outsourcing endeavor, or “Total Cost of Ownership.”

That's just an example of "vested interests" proving that outsourcing is not all rainbows and unicorns.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#104

- identities of undercover operatives... This is terrible. When will people learn to NOT use computers at all for some things. Use typewriters and spend a little bit more on administrative workers. You trade in processing efficiency for making these catastrophic breaches rarer.

I say this all the time, but I always get mocked for it. "There are hundreds of thousands of Americans with clearance, how are we supposed to administrate that without computers."

But what's the alternative? Even if you air gap things very, very aggressively you still get owned. The CIA has said that air gaps have never stopped them. Ok, so what are we going to do? Getting data out from computer systems is too easy. Things should be pen and paper and maybe specialized typewriters (there are ways of bugging typewriters or using sound recordings of the typing to reconstruct sentences).

At the very least we should keep our foreign agents out of our databases.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#105

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

"location of all army vehicles"

The defense minister has openly said that the "försvarsmakten"'s cars aren't listed in the STA's registers.

I can't find a link to prove this but i think it was said in one of the press conference's

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#106
post #34

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

Well, she was also fired (finally) and her career is finished. I agree it was monumentally stupid. But "punished as high treason"? Treason requires intent. She most certainly did not intend to be criminally disloyal to the country. Merely being ignorant and incompetent is not treason. This is a major fuckup but let's be real. Our country is a "joke"? I know complaining is a national sport in Sweden, much like in many…

You have housing mortgages that do not need to be repaid and you have no car sales tax. Two incredibly good reasons to love Sweden. <3

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#108

Earlier quoted context omitted.

The screw-up was initiated by Alliansen (not the current government), by outsourcing this to IBM. I'm not saying current government are free of blame here, but please stop trying to fit this into a "feminist" argument.

How can this be Alliansens fault? It was the current government-assigned general director of the Transport Agency that knowingly broke the law. She was even informed by SÄPO (Swedish equivalent of MI5 or CIA) that what she's trying to do is illegal, but still went through with it. The problem here is not outsourcing, because it is completely legal to do so as long as the company outsourced to goes through with proper…

> SÄPO (Swedish equivalent of MI5 or CIA)

Nitpicking: Säpo is not the Swedish equivalent of the CIA. e.g., the single largest expense of Säpo is protection of dignitaries, which is a role held by the USSS, not the CIA.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#110

Earlier quoted context omitted.

"unaccompanied minors" the ones that claim to be 17y.o. when they can get away with it?

I'm sure an overwhelming number of unaccompanied minor refugees are in fact adults claiming to be 17. /s

"but a study using dental tests in Norway revealed that 9 out of 10 underage refugee children were actually older than 18."

https://sverigesradio.se/sida/artikel.aspx?programid=2054&ar...

Post reply on HN