Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

21–30 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#23
post #10

Earlier quoted context omitted.

Man, you've got to be a real low-life to sell all of that.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

The point of a system like this is specifically that it’s accessible and not air gapped.

Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible

Re: Source code of Swedish e-government services has been leaked

#24

This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical…

The tender process is what they are optimised for. They are professional project bidders with a bit of outsourced software development bolted on the back.

Re: Source code of Swedish e-government services has been leaked

#26
post #23
post #10

Earlier quoted context omitted.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

The point of a system like this is specifically that it’s accessible and not air gapped. Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible

[deleted]

Re: Source code of Swedish e-government services has been leaked

#27
post #16
post #10

Earlier quoted context omitted.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.

> it is still easy to make misstakes.

That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.

Re: Source code of Swedish e-government services has been leaked

#28
post #13
post #10

Earlier quoted context omitted.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

It's something akin to a service provider in SAML parlance, if we are to believe reporting. How can it be air-gapped? And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.

At the high end you can use data diodes to isolate critical data.

Re: Source code of Swedish e-government services has been leaked

#29
post #21
post #15

I like paper documents for this very reason. It's very hard to steal everyone's documents when they weight about the same as a train.

But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.

> it’s easy to lose all of them in a fire or flood

Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?

Re: Source code of Swedish e-government services has been leaked

#30
post #16

Earlier quoted context omitted.

If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.

> it is still easy to make misstakes. That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.

It was mainly an explanation, that "airgapping" does not magically provides better security, or is required (or possible) to use at all here.
Post reply on HN