Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

31–40 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#32
post #20
post #18

Earlier quoted context omitted.

> But again there is little to no way to figure out for sure whether the Chinese government has this information assume they have it.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Hi, nice to meet you Johan! Can I get you a drink? Oh, you're an electrician? That's nice, I sell light fixtures.

...

Good to see you again Johan! You'll never believe, I was down at XYZ Clinic yesterday, and they'd left your file out!! Careless right? How did you break it to your wife you had herpes? Oh, she didn't know?! Man, sorry I mentioned it, I'll keep that quiet for sure.

...

Man, it's been a hard month Johan. Sales are down! Hey, you told me you worked at the DaneSecure building right? Oh you didn't? Someone else must have told me that. But look, don't worry. I can keep secrets!! Look could you do me a favour? I need to know what kind of light fixtures they use at DaneSecure so I can pitch to them. Could you take a look and let me know? I'd like to know what kind they are, and specifically, how many are installed on Level 7. You know we're friends, because you know I can keep my mouth shut.

...

Johan, we have a problem!!! My boss said that because we're Chinese-owned, you telling me about the light-fittings in a classified area is technically passing on state secrets!!! You have a lawyer right? No?! OK, here's the plan, don't tell anybody, and we'll figure a way to keep us both out of jail!

...

Are you OK Johan? You look kind of pale. You haven't been worrying about this all week have you? Oh you have? OK well don't worry, I've got a solution. My boss has said he thinks he can stop our corporate lawyers reporting it, and we'll both be fine. There's a small catch favour he wants from us though. He needs to know the power consumption of the floor to help us tailor our pitch. Do you think you could plug this thing in to a light fixture for me? I think we're both going to be fine...

...

Johan, I have some bad news for you? Remember I said I sold light fixtures? Well that wasn't the whole truth...

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#33
post #20

Earlier quoted context omitted.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

They use it can track the movements of Chinese residents abroad, to blackmail Danes who are assisting Chinese disidents, run scams at doctors offices or insurers in order to get documentation for spies. I am sure there is more, I am no expert in this sort of thing.

Plus identity theft to help spies assume a false identity when gathering information. And of course: Selling the health records to insurers in order to allow them to set prices for prospective customers. I'm sure insurance companies would pay nicely for this.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#35

Earlier quoted context omitted.

This happens more than you think, although not usually at this scale and this high up in the chain. When a care institution needs to communicate with one of their vendors handling health records about a problem with a specific person's record, most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue without even considering encryption or the necessity of sending all that…

> most IT-workers at those institutions tend to just mail all details they feel are relevant to the issue Not necessarily disbelieving you, but why do you say this? Every place I've worked or contracted at with PII, I've had to sit through training about not doing this, and management provided tools for proper handling. I don't mean to say that because there are policies that no one ever breaks them. I've also encoun…

I work for a SaaS vendor of health care record software. From what I have seen care institutions (as opposed to hospitals) do not have the experience or staff in-house to facilitate proper security procedures. The problem as I see it lies not in the routine operations that have a high degree of visibility in the organisation and tend to have strict policies surrounding them because they are anticipated, but in the exceptions, such as key users or the IT support responsible for the service they use reporting issues to the vendor.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#36
post #8

Earlier quoted context omitted.

That's the problem with blame culture. It needs to be someones (emphasis ONE) fault, and then anyone else can breathe a sigh of relief and move on. It's blatantly irresponsible that SSI even has the infrastructure to burn CDs with this information on it (it needs to live in heavily secured, jealously guarded and scrupulously audited (ideally airgapped) computer system). If they absolutely need this capability, it's b…

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history. Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years. Unless by airgapped you mean to build a separate, free standing, network just for delivering medical re…

First, this is not about doctors exchanging patients' medical histories, it's about two central government offices exchanging everybody's medical histories.

Second, the fact that security is (really!) hard is not a valid argument against doing it.

Third, there's a huge difference between the appropriate levels of security around individual patients' medical histories, a single doctors office worth of patients' data, and then the collective medical histories for every single patient in the nation.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#37
post #7

Google Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?

As others write, the data protection agency doesn't have any real power. As a result very few companies and even other government agencies really care about the opinion of the data protection agency.

It doesn't make sense to fine anyone, or even try to prosecute, because everyone will just claim that they are just doing as instructed, and a fine to government agency is a little weird.

The issue is a very combination of a belief that any problem can be slowed using IT, and at the same time refusing to make any effort to understand IT. In terms of IT the Danish government is completely ignorant, bordering on the incompetent.

I don't think I would be completely of, if I claim that almost no one working in Denmark has ever received any real training in basic IT, and least of all in data protection. It's naively assumed that everyone in society has the skills required use a computer, and threat data with the care that is needed.

The basic issue is that the person in charge of making the CDs didn't see an issue with not encrypting them, or not knowing how to do so. It a culture of incompetence and happy ignorance.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#38
The story from the Chinese Visa Application Office (CVAO) is that an employee opened the letter "by mistake":

>"It said that it was contacted by an employee of the Chinese Visa Application Centre who said she opened the letter addressed to Statistics Denmark “by mistake” but then delivered the package to the statistics agency." (TheLocal, linked above, http://www.thelocal.dk/20160720/five-million-danish-id-numbe...). //

Having worked as a civil servant I find this unlikely if it were properly addressed. In the office I worked at all mail came in via a mail room who checked and registered it and directed it to relevant personnel.

Presumably the CVAO receive a lot of mail, they must have a dedicated system for recording [because we're talking about legal documents and receipt dates therefore are important to record] and directing that mail. So a piece of mail comes in for "Statistics Denmark", now what happens?

What I'd expect is it's sent to a mail-room manager to handle. They can then either redirect the mail unopened or forward it to some other personnel. I really can't see them just opening things "by accident" at all. They have a choice to honestly redirect unopened or to actually open it. Now, the opening may have been an individual's simple curiosity, for sure.

Interested in any other analysis particularly with reference to how mail receipt is handled in other country's civil service locations. I expect things have moved on somewhat, something like 'tag with barcode, photograph and the computer records the article' is probably the current workflow?

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#39
The Danmark Statistik office in Copenhagen is 250m away from the Chinese Visa Application Service Center, just for context.

I don't see why the Chinese employee had to open the package in order to figure out it was not meant for them. When the package was adressed for someone else isn't that quite obvious when you have a first look at the package?

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#40

So, to summarise - burning it to CD is actually fine, but they should have used an in-house courier.

Not Danish so I don't know their laws, but in the US not encrypting the disk would be a violation of HIPAA. In-house courier would work but isn't necessary. FedEx at least, I am sure the others do too, provide services for transporting secure information. Though you have to make use of them, you don't just drop it off with the regular shipping as seems to have been done here.
Post reply on HN