Live data from Hacker News

Swedish Government Scrambles to Contain Damage from Data Breach

nytimes.com

121–130 of 140 posts

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#121

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

Data breaches, loss of privacy are common, everywhere. The novel aspect here is this news wasn't buried.

Yes, please be outraged.

But please also realize its the norm. We (society) do not have the laws, rules, procedures, or technology to prevent or mitigate it.

Edit: Just quickly read up on this incident. They did try to bury it. But I read one account that stated one the Pirate Bay guys daylighted the breach. Delicious irony. So this scandal is now at stage 4: Assign the blame. Next is stage 5: Rinse, lather, repeat.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#123
post #16

Earlier quoted context omitted.

I don't know how much blame you can put on IBM here. - The Transport Agency decided to outsource operations, and IBM won the contract (April 2015) - The following month, the head of the agency decided to ignore certain laws about privacy, secrecy, etc., as well as the agency's own requirements about information security - The Swedish Security Service, Säpo (basically our FBI), immediately got wind of this and started…

IBM really should be able to see that this is a very questionable contract and not take the contract.

At this point (and historically for many years), it seems like there is no circumstance upon which an IBM salesperson or any of their management (right to the top) would ever say No to receiving more money.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#124
post #34

Earlier quoted context omitted.

Well, she was also fired (finally) and her career is finished. I agree it was monumentally stupid. But "punished as high treason"? Treason requires intent. She most certainly did not intend to be criminally disloyal to the country. Merely being ignorant and incompetent is not treason. This is a major fuckup but let's be real. Our country is a "joke"? I know complaining is a national sport in Sweden, much like in many…

Wait what? She knew that was a possibility and that it is highly illegal and still she went through with it. I would say that is having intent if anything. I love my country but I think she should be punished a lot harder. Arkebusering på slottsgården. But since that will never happen, 12 years in jail is probably enough.

But crucially not intent to commit treason. Gross negligence, sure (this she also admitted to). And I agree that she - and several others - ought to be punished much harder. But being naïve and incompetent (basically "yeah this is a problem but IBM can't provide people with security clearance yet, it takes too much time, and we're too far into the process and if we stop now many things - such as giving out driver's licenses and checking them - won't work for a while")... is, again, not treason.

Just like involuntary manslaughter is not murder, and so on.

Here's the definition by the way, 19 kap. 1 § brottsbalken: https://lagen.nu/1962:700#K19

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#125
post #81
post #34

Earlier quoted context omitted.

Well, she was also fired (finally) and her career is finished. I agree it was monumentally stupid. But "punished as high treason"? Treason requires intent. She most certainly did not intend to be criminally disloyal to the country. Merely being ignorant and incompetent is not treason. This is a major fuckup but let's be real. Our country is a "joke"? I know complaining is a national sport in Sweden, much like in many…

Being ignorant and incompetent and taking a job that your national security depends on that you can't do is treason in my book. I like Sweden, but the "on the whole, things in general" is a dangerous theme. Real problems and injustice exist in the margins and long tails, typically these can be fixed at manageable cost but not if they are ignored.

Not saying problems don't exist. Just trying to be realistic. Shouting about how everything has gone to hell and the country has become a joke can also be a dangerous theme feeding populist movements. Let's focus on what's actually broken.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#126
post #31

Earlier quoted context omitted.

https://acidmuncher.wordpress.com/2017/02/08/feminist-trump-...

TL;DR: Link is to a rambling blog article about a perceived slight (moving money from a 'foreign aid' budget to a 'refugees' one) that will have an unsubstantiated outcome (Sweden will accept only male refugees in the country), apparently based on a well-known falsehood ("most refugees are single adult males" [1]). Blog has articles such as "Sweden should have guns like Texas because ISIS!". Blog author is not Swedis…

The blogger is a Muslim immigrant from Bosnia that immigrated when he was very young.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#127
post #34

Here's a summary of what foreign powers got access to: - identities of undercover operatives - personal identity data of everyone with a driver's licence - people with protected identities - location of all army vehicles - money transport vehicles - classified infrastructure information Even worse: when they realized they'd leaked photos, home addresses and SSNs of protected identities, they sent a clear text email a…

Well, she was also fired (finally) and her career is finished. I agree it was monumentally stupid. But "punished as high treason"? Treason requires intent. She most certainly did not intend to be criminally disloyal to the country. Merely being ignorant and incompetent is not treason. This is a major fuckup but let's be real. Our country is a "joke"? I know complaining is a national sport in Sweden, much like in many…

>on the whole, things are in general pretty good, relative to most other countries in the world.

15 years ago, those relativizations wouldn't have been necessary. Sweden was a poster child of a good society and now it isn't. Many things in your country did deteriorate quickly over the last decade or so, no matter how you try to coat it.

"At least we're still better than others" is a pretty sad statement by itself when you realize that you could be doing a lot better.

My country is currently going down the same road and it's saddening to see that we didn't learn from your mistakes.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#128
post #102

- identities of undercover operatives... This is terrible. When will people learn to NOT use computers at all for some things. Use typewriters and spend a little bit more on administrative workers. You trade in processing efficiency for making these catastrophic breaches rarer.

I think for actual security you need to practice physical security. No matter if the data is stored on paper or electronically, you will still need to air gap it, and have security and clearance protecting that data. To put it into perspective Manning only got the data out because they were lax about securing the CD-burner in the computer he was using.

Absolutely. But computers and centralized data make physical security easier. Old fashioned typewriters, paper files, and manual indexes for searches are safer (for very specific things), because you simply just can't haul all of it out. For a decent set of paperwork you'd spend months or years xeroxing everything. Leaks may happen but may be smaller. Processed and redacted data may still be put on computers for searching. It's a tradeoff with obvious serious disadvantages, but one that can save the operations and even lives of the good guys.

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#129
post #90

Earlier quoted context omitted.

I am on mobile now, can't google efficiently, and the statistics here are lacking either way, but Swedish policy is to accept anyone who claims their are a minor and has no documents to prove otherwise - as a result, young people lose their docs and claim to be less than 18. This was made widely public when a 23-year old who got asylum as a 17-year old killed a social worker at the asylum about a year ago, and invest…

I did not know that (and that was certainly more informative than the other guy's post). Although I understand the duty to assist minor, the lack of checks is disturbing, especially since it's likely to not go well for anyone (having known someone who did work on refugee cases a while ago, having no legal documents can lengthen the procedure significantly, so they'll be stuck in a center for years, and they do check…

> A kid, even at 17, is much less autonomous, will have an educator or foster family, will go to school, etc, they are going to be 'enrolled' much more actively into society.

That's nice in theory, but it doesn't actually bear out in practice. As one example, according to [0], even second or third generations fail to integrate (with disastrous results), and AFAIK that's the rule rather than the exception (though there are quite a few exceptions, more in the UK, less in mainland Europe). It's not enough if even 50% integrate successfully when the number of immigrants is so high.

[0] https://www.washingtonpost.com/graphics/world/brussels-molen...

Re: Swedish Government Scrambles to Contain Damage from Data Breach

#130

- identities of undercover operatives... This is terrible. When will people learn to NOT use computers at all for some things. Use typewriters and spend a little bit more on administrative workers. You trade in processing efficiency for making these catastrophic breaches rarer.

I say this all the time, but I always get mocked for it. "There are hundreds of thousands of Americans with clearance, how are we supposed to administrate that without computers." But what's the alternative? Even if you air gap things very, very aggressively you still get owned. The CIA has said that air gaps have never stopped them. Ok, so what are we going to do? Getting data out from computer systems is too easy.…

Let's assume people stop mocking this idea and ditch computers for the most recent and highly classified data. Over decades of replacing everything with computers and retiring oldtimers, we probably lost a whole set of skills to run physical paperwork, keep it secure and detect breaches.
Post reply on HN