Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

31–40 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#31
post #14

How much GDPR fine will they pay? Oh wait it's gov so nothing / does no matter even if. Who will take responsibility and get fired and lose all pension etc.? Oh wait no one. Well the citizens need to suck it up.

As the attack actor now has the data, they're liable for ongoing GDPR failures, on top of the theft. Then anyone they sell the data to becomes liable (on top of handling stolen goods). Could be a money-earner for the EU if they pursue it properly.

Re: Source code of Swedish e-government services has been leaked

#32

The source code is the least of it! From the article: > citizen PII databases and electronic signing documents were also collected but are being sold separately

What does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?

Re: Source code of Swedish e-government services has been leaked

#33

This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical…

> Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity

So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the tender) or a region (Europe) if there is no obvious alternative.

Re: Source code of Swedish e-government services has been leaked

#34
post #21

Earlier quoted context omitted.

But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.

> it’s easy to lose all of them in a fire or flood Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?

The good news is you can keep offline, offsite digital copies, which is much more convenient than offsite paper copies.

Re: Source code of Swedish e-government services has been leaked

#35

Earlier quoted context omitted.

I saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.

In Aftonbladet comments from CGI they seem to think that no production related data has been leaked: https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...

As if it ever happened that a breached company admitted immediately that they've just been fucked.

Re: Source code of Swedish e-government services has been leaked

#36
post #24

This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical…

The tender process is what they are optimised for. They are professional project bidders with a bit of outsourced software development bolted on the back.

A lot of outsourced development.

The tender process + clueless buyers + tender process law(s) cause this. Whole process needs a revamp for this to not be a problem.

Re: Source code of Swedish e-government services has been leaked

#37

Earlier quoted context omitted.

I saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.

In Aftonbladet comments from CGI they seem to think that no production related data has been leaked: https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...

[deleted]

Re: Source code of Swedish e-government services has been leaked

#38

Earlier quoted context omitted.

I saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.

In Aftonbladet comments from CGI they seem to think that no production related data has been leaked: https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...

But a copy of production data in the test environment isn't production data... It's test data! :)

Re: Source code of Swedish e-government services has been leaked

#40
Swedish news has some quotes from authorities that nothing of value has been leaked, and a quote from the service CGI that it only concerns test servers.[1][2]

[1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...

[2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...

Post reply on HN