I like paper documents for this very reason. It's very hard to steal everyone's documents when they weight about the same as a train.
Source code of Swedish e-government services has been leaked
21–30 of 263 posts
Re: Source code of Swedish e-government services has been leaked
#22The source code is the least of it! From the article: > citizen PII databases and electronic signing documents were also collected but are being sold separately
Re: Source code of Swedish e-government services has been leaked
#23Earlier quoted context omitted.
Man, you've got to be a real low-life to sell all of that.
You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible
Re: Source code of Swedish e-government services has been leaked
#24This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical…
Re: Source code of Swedish e-government services has been leaked
#25Re: Source code of Swedish e-government services has been leaked
#26Earlier quoted context omitted.
You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
The point of a system like this is specifically that it’s accessible and not air gapped. Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible
Re: Source code of Swedish e-government services has been leaked
#27Earlier quoted context omitted.
You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.
That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.
Re: Source code of Swedish e-government services has been leaked
#28Earlier quoted context omitted.
You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
It's something akin to a service provider in SAML parlance, if we are to believe reporting. How can it be air-gapped? And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.
Re: Source code of Swedish e-government services has been leaked
#29I like paper documents for this very reason. It's very hard to steal everyone's documents when they weight about the same as a train.
But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.
Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?
Re: Source code of Swedish e-government services has been leaked
#30Earlier quoted context omitted.
If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.
> it is still easy to make misstakes. That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.