Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

11–20 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#11

This is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the i…

> 5.28m residents

Denmark has a population of 5.7m residents, so this is almost all Danes.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#12
post #7

Google Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?

Yes that's true - The Data Protection Agency see no reason to take any further action in this case. Their assessment is that there is a low likelihood of an actual leak (based on a written statement from the Chinese employee who opened the letter). And the SSI has promised to send such information encrypted going forward.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#14
post #7

Google Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?

Datatilsynet (Data Protection Agency) has no actual powers. They can only raise fingers. Parliament has decided not to actually grant them any powers but say mean things. Datatilsynet themselves have on numerous occasions admitted that they are pretty powerless.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#15

This is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the i…

This happens more than you think, although not usually at this scale and this high up in the chain. When a care institution needs to communicate with one of their vendors handling health records about a problem with a specific person's record, most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue without even considering encryption or the necessity of sending all that data over the wire.

The use of physical post here was probably a good thing all things considered! They could just as easy have used WeTransfer or some other cloud solution — when it comes to security best practices people are very good at downplaying the potential risk, even when legislation does acknowledge it and forbids such treatment of sensitive personal information.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#16
post #9
post #3

Earlier quoted context omitted.

And the letter, which was sent as priority mail, had been opened when they went to retrieve it...

Now they must assume that information is compromised and take action.

Which is what? Give every Dane a new health record?

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#17
post #9
post #3

Earlier quoted context omitted.

And the letter, which was sent as priority mail, had been opened when they went to retrieve it...

Now they must assume that information is compromised and take action.

They wrote that they do not belive that there was a compromise of the data.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#18
post #6

Earlier quoted context omitted.

How long does a modern machine need to copy off the contents of a couple of CDs? Were the discs in tamper-evident packages?

No long, I'd imagine. But again there is little to no way to figure out for sure whether the Chinese government has this information. The story really highlights the careless handling of data, because the chances of the Chinese government (or any other third part) getting access to these data is way too high.

> But again there is little to no way to figure out for sure whether the Chinese government has this information

assume they have it.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#19
post #17
post #9

Earlier quoted context omitted.

Now they must assume that information is compromised and take action.

They wrote that they do not belive that there was a compromise of the data.

So? An unencrypted CD was accessible for a time period to a third party. It's good security practice to consider the data to be compromised. Especially a powerful, malicious actor will put in effort to make it appear that this is not the case.

If anything, this requires a severe audit of the security practices of the affected organisations. Moreover, I think citizens of Denmark are entitled to know what information about their personal health records is leaked.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#20
post #18
post #6

Earlier quoted context omitted.

No long, I'd imagine. But again there is little to no way to figure out for sure whether the Chinese government has this information. The story really highlights the careless handling of data, because the chances of the Chinese government (or any other third part) getting access to these data is way too high.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it.

What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Post reply on HN