Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

11–20 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#13
post #10

Earlier quoted context omitted.

Man, you've got to be a real low-life to sell all of that.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

It's something akin to a service provider in SAML parlance, if we are to believe reporting. How can it be air-gapped?

And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.

Re: Source code of Swedish e-government services has been leaked

#16
post #10

Earlier quoted context omitted.

Man, you've got to be a real low-life to sell all of that.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.

Re: Source code of Swedish e-government services has been leaked

#18
This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security".

Several government organisations / regional authorities and companies were down. Last I heard several medical journals for whole municipalities were just destroyed.

Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity, are suspicious of things like zero-trust, follow outdated engineering practices. Sigh.

Re: Source code of Swedish e-government services has been leaked

#19
post #14

How much GDPR fine will they pay? Oh wait it's gov so nothing / does no matter even if. Who will take responsibility and get fired and lose all pension etc.? Oh wait no one. Well the citizens need to suck it up.

Few years ago a huge NRA database was left public with admin/1234 or similar by the Bulgarian NRA. They government fined itself some non-trivial amount, then in the source/destination IBAN they put the same value and paid the fine. They managed to find someone to blame and it was not the person who left the database but the person who found it. Turns out that if you leave the PII of a whole country open to the public it is not your fault and you get to keep your cozy job. It is already unlawful to access that, so if someone access it - it is his fault - he broke the law.

Edit, i checked the facts: The Bulgarian government said that the it should pay too much to itself, and appealed the fine for few years until it somehow expired. And the guy (20 year at that time) they accused was later acquitted after they tried to ruin his life.

Post reply on HN