Earlier quoted context omitted.
That's an interesting guess that I assume is based on absolutely nothing?
Yes, nothing and the facts that these are government services, they use BankID and they updated their websites with "maintenance work" announcements for tomorrow, Saturday. For kronofogden.se there was no maintenance planned just half an hour ago. Knowing swedish tendency to plan things months ahead I would _guess_ that this maintenance work has been rushed due to some circumstances.
Source code of Swedish e-government services has been leaked
141–150 of 263 posts
Re: Source code of Swedish e-government services has been leaked
#142Knowing swedish people's mindset I'm not surprised at all by the breach. What can be mildly surprising is that no major e-gov service has expressed concerns on their websites. Only on skatteverket.se, which is Swedish Tax Service website, there is a vague note on "maintenance work" planned for coming Saturday. Maybe totally unrelated though.
Of course, they might be wrong!
Re: Source code of Swedish e-government services has been leaked
#143Earlier quoted context omitted.
I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…
We're so open, we even leak our government source code _ourselves_ https://github.com/navikt
Re: Source code of Swedish e-government services has been leaked
#144This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical…
> Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the…
It's the same reason major govt. IT orgs keep pushing for closed source (recently the Swedish Tax Authority was in the media for _pushing for Office 365_ as necessary for operations), out-sourced designs, big firm purchases over FOSS or real standards.
You need people that care (and they exist, even in the gigantic state orgs.) in positions to make good decisions. Right now, everything is up in the hands of nebulously defined managerial staff with none-to-doubtful technical competence.
Another recent case: the Swedish digital exams platform flopped at a rough cost of a billion SEK. Can't sustain 150K concurrent users, despite paying a "large company". Like, come on.
Re: Source code of Swedish e-government services has been leaked
#145Re: Source code of Swedish e-government services has been leaked
#146Re: Source code of Swedish e-government services has been leaked
#147also: hi tavro! it's been a few years, how have you been :D
Re: Source code of Swedish e-government services has been leaked
#148Earlier quoted context omitted.
How do they have handle identity thefts, spams, etc.? There are so many ways to misuse these data. Are the residents not concerned about this?
"Identity theft" is newspeak right up there with "intellectual property". It serves the sole purpose of diminishing real theft. If someone says "we gave all your money to this other guy, but it's not our fault because he had stolen your identity" doesn't make it so. There are cases of mistaken identity, and with criminal intentions, but there is also an enormous majority of not checking identity because someone was l…
Re: Source code of Swedish e-government services has been leaked
#149Swedish news has some quotes from authorities that nothing of value has been leaked, and a quote from the service CGI that it only concerns test servers.[1][2] [1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform... [2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...
Let me just say, the likelihood that CGI would have any _actual_ real personal data is close to 0%, at least on servers outside of Skatteverket. I had access to absolutely nothing even working inside. I have never worked in a more closed-down system, maybe excepting the swedish military "complex". No, actually that was less locked down in a way, at least once you were "inside" the system.
Re: Source code of Swedish e-government services has been leaked
#150Earlier quoted context omitted.
Oh yes. I'm Swedish and I do have to admit I have looked up quite a lot of people on these kinds of sites. It's become so normalised to do this even though I also feel like it would be better as a whole if they just did not exist in the first place. Last update I heard about something being done about it was this: https://www.regeringen.se/pressmeddelanden/2024/11/utredning... Not sure what the current status is.
[flagged]
This is very close to the "Yet you participate in society, how curious" mean, especially since they're implying they would vote in favor of a law that changes it so that the data is no longer public in the same manner.
But then your comment history reveals enough about your intent.