Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

131–140 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#131

Earlier quoted context omitted.

Just a few years ago this was about to change in Sweden. But they didn't change it, because "women should be able to look up the men that they date".

Oh yes. I'm Swedish and I do have to admit I have looked up quite a lot of people on these kinds of sites. It's become so normalised to do this even though I also feel like it would be better as a whole if they just did not exist in the first place. Last update I heard about something being done about it was this: https://www.regeringen.se/pressmeddelanden/2024/11/utredning... Not sure what the current status is.

[flagged]

Re: Source code of Swedish e-government services has been leaked

#132
post #106

Earlier quoted context omitted.

How do they have handle identity thefts, spams, etc.? There are so many ways to misuse these data. Are the residents not concerned about this?

> How do they handle identity thefts By just accepting it as a normal fact of life that you will have some random stuff ordered in your name sooner or later with an invoice you'll have to dispute. Happened to a relative of mine, police do not care unless they order things above a certain value, without a police report you cannot get free ID protection, and then you'll have to sit for a long time in phone queues tryin…

I am Swedish and never had this happen to me. Never had random things show up or ordered for me at all. What would the point be, you have to pay or get an invoice? For Klarna they use BankID so only I can order an invoice for myself in reputable shops.

I am in my 30s btw so I was alive before BankID and it was a worse time. Remember my parents paid bills with paper.

Re: Source code of Swedish e-government services has been leaked

#133
post #121

Earlier quoted context omitted.

What is the harm in this case? Shit people are shit even without information. They would be snark about something else then.

I think it was covered during a discussion about immigrants that are easily rejected - because they're immigrants. The points was that it added another layer of issues for immigrants because they didn't understand the neighbourhood they "should be living in" with their revenue.

Why is this not the “shit people do shit things” category? This happens even without being immigrants. Large part of my family lives in a way poorer neighborhood than what we can afford, because we don’t care to move. People who have problem with this had other problems even before we got richer. There is exactly zero difference. The exact same people are snark as before, just for something else now. They were and would be snark even without this.

This seems to me a very bad attempt to hide xenophobia.

Re: Source code of Swedish e-government services has been leaked

#134

Earlier quoted context omitted.

> How do they handle identity thefts By just accepting it as a normal fact of life that you will have some random stuff ordered in your name sooner or later with an invoice you'll have to dispute. Happened to a relative of mine, police do not care unless they order things above a certain value, without a police report you cannot get free ID protection, and then you'll have to sit for a long time in phone queues tryin…

That sounds rather unacceptable.

It basically never happens. I don't know where the GP got their story from.

Re: Source code of Swedish e-government services has been leaked

#135
post #106

Earlier quoted context omitted.

How do they have handle identity thefts, spams, etc.? There are so many ways to misuse these data. Are the residents not concerned about this?

The root cause of identity theft in USA and some other places is the lack of "proper" national identity and the associated use of various personal "secrets" (not that secret) for identity verification because there are no good easy other ways. Businesses in Scandinavia and many other countries would not treat someone knowing your personal information as any evidence of identity (because it's not); having all that inf…

The US has no single national photo + chip ID card that is available to everybody, for free, including illegal and semi-illegal immigrants and homeless people with no access to their birth certificate and such.

It's completely crazy to me that you can be "out of status" with the USCIS and still get a social security card and a bank account, for example.

Re: Source code of Swedish e-government services has been leaked

#136
post #81
post #75

Earlier quoted context omitted.

You can get all of that one-by-one? Or can you get the whole database at once?

I cannot trivially get the whole database, no. But I kind of fail to see what a malicious actor would do with a large database of public information that they couldn’t otherwise do. The system is designed such that you can’t really do a lot of malicious stuff with just public data, and the stuff you can do (scam calls, etc) is probably not meaningfully more effective if you have the whole database than if you do manu…

In the US, property tax records are public by design. However, historically the records were physical and hard to search through. Now that these records are digitized and published online, it is trivial to find out where someone resides by searching through these records. So while public by design, at scale data aggregation changes the threat model.

Re: Source code of Swedish e-government services has been leaked

#138
Worked on a similar platform. The real risk isn't the code - it's the config files. Government deployments have hardcoded staging credentials, VPN endpoints, and encryption keys that don't get rotated when code leaks. Source is whatever. Those env files are the skeleton key.

Re: Source code of Swedish e-government services has been leaked

#139
post #106

Earlier quoted context omitted.

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

How do they have handle identity thefts, spams, etc.? There are so many ways to misuse these data. Are the residents not concerned about this?

"Identity theft" is newspeak right up there with "intellectual property". It serves the sole purpose of diminishing real theft. If someone says "we gave all your money to this other guy, but it's not our fault because he had stolen your identity" doesn't make it so. There are cases of mistaken identity, and with criminal intentions, but there is also an enormous majority of not checking identity because someone was lazy.

Re: Source code of Swedish e-government services has been leaked

#140
post #33

Earlier quoted context omitted.

> Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the…

Split giant projects into small ones, award it to better smaller companies, require interoperability via API that is clearly documented and ask for around the clock security monitoring and patching. The last things being the same thing you do at any decent private company. IBM or Accenture or whoever don't need to be the only ones winning tenders.

The total number of people working on the project might remain similar no matter if it's one company or many smaller companies. Writing clear documentation and API, well thought from the start is harder the larger the project.

Maybe there would be a benefit from having less layers of management, but multiple small companies or one big could have the same structure.

Post reply on HN