Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

101–110 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#102

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

We're so open, we even leak our government source code _ourselves_ https://github.com/navikt

Re: Source code of Swedish e-government services has been leaked

#103
post #48
post #43

Earlier quoted context omitted.

I would guess that skatteverket.se, polisen.se, kronofogden.se are among those affected by the leak.

Some other comments mention BankID private keys . That would be the biggest disaster as that’s what everyone uses to identify themselves “securely” on all government services.

The private keys in BankID are stored in users phones, not centrally.

Re: Source code of Swedish e-government services has been leaked

#104

Earlier quoted context omitted.

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

I heard a rumor that some people use this to check their neighbour's revenue and sometimes make snark comments if one of them has a high revenue but lives in a "average revenue" part of town. They'd say that if you earn a lot, you shouldn't take a cheap housing. Any truth to that?

Yes and no. You get notified if someone else actually asks for your revenue info and so in practice nobody actually does it.

Re: Source code of Swedish e-government services has been leaked

#105

Earlier quoted context omitted.

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

I heard a rumor that some people use this to check their neighbour's revenue and sometimes make snark comments if one of them has a high revenue but lives in a "average revenue" part of town. They'd say that if you earn a lot, you shouldn't take a cheap housing. Any truth to that?

There used to be a lot more of that, but a system was put in place where you have to identify yourself with electronic ID to access the information, and the information is logged so the other party can see it.

Nowadays I think mostly journalists use it to pull up information about politicians and other people that are in the public spotlight. There are of course the yearly "richest people in Norway" lists in various categories.

Re: Source code of Swedish e-government services has been leaked

#106

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

How do they have handle identity thefts, spams, etc.?

There are so many ways to misuse these data. Are the residents not concerned about this?

Re: Source code of Swedish e-government services has been leaked

#107
post #104

Earlier quoted context omitted.

I heard a rumor that some people use this to check their neighbour's revenue and sometimes make snark comments if one of them has a high revenue but lives in a "average revenue" part of town. They'd say that if you earn a lot, you shouldn't take a cheap housing. Any truth to that?

Yes and no. You get notified if someone else actually asks for your revenue info and so in practice nobody actually does it.

Is this not trivial to get a random person to check stuff for you in exchange for making requests for them (on people they are interested in)? Or is that illegal?

Re: Source code of Swedish e-government services has been leaked

#108
post #106

Earlier quoted context omitted.

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

How do they have handle identity thefts, spams, etc.? There are so many ways to misuse these data. Are the residents not concerned about this?

It's just a unique ID of a person, it's not a password. I don't see how you can be confused by this.

Re: Source code of Swedish e-government services has been leaked

#109
post #80

Earlier quoted context omitted.

Problems with well-known solutions 100 years ago: "Fireproof file rooms and cabinets in the 1920s were crucial for protecting business and government records during the rapid expansion of the industrial era. The era saw a massive shift from flammable wooden office furniture to robust, steel-based storage designed to resist both fire and water damage." That's a Google AI summary - but I've been in a fair number of bui…

Then add “earthquake” to the list, or “domestic terrorists or foreign country bombing the building”. Steelman the argument. The point isn’t “just fire and water specifically”, we’re not playing Pokémon. We have several historic examples of records being lost in disasters, and way more recent than 100 years ago. https://en.wikipedia.org/wiki/National_Personnel_Records_Cen... It makes no difference that we could’ve pre…

I stuck to the threats you mentioned. Paper in a file room is more slightly more quake-resistant and bomb-resistant than digital. But slower to move to safety if the threat is large volcanic eruptions.

I am not saying that paper is magically perfect. Nor better in every situation. I am saying that paper is far easier (than digital) to do well for use cases like a national records collection. "Correctly" may include off-site backups - whether or not your threat model includes massive earthquakes, volcanoes, bombs, special forces, EMP weapons, biological agents, civil war, radioactive fallout, or enemy occupation. Or "Management wouldn't pay for a done-right facility".

As I noted in another comment, the largest downside to paper (within such use cases), is that it is far more difficult to get political support for old-fashioned stuff that just works, compared to anything that can be sold as cool/new/high-tech. Especially when the taxpayer-funded revenue streams from selling/installing/supporting the tech create incentives clearly contrary to the taxpaper's long-term interests.

Re: Source code of Swedish e-government services has been leaked

#110
post #88
post #32

Earlier quoted context omitted.

What does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?

To the best of my understanding it means that a system made by CGI for digital signing of documents (as in: you get something like a PDF from a government agency and need to digitally sign it and send it back) has had its source code and/or some data belonging to it leaked. Skatteverket, the Swedish tax authority, has been quoted in media as confirming that they use CGI's system for digital document signing but that…

So if no data was leaked from the tax agency or from the users, then the leaked "digital signing documents" must have belonged to the only remaining party, which is CGI, so perhaps they were just some marketing documents about the benefits of their digital signing service?
Post reply on HN