Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

41–50 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#41
post #21

Earlier quoted context omitted.

But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.

> it’s easy to lose all of them in a fire or flood Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?

I think what the comment meant was that it's harder for an individual to lose their paper documents compared to losing the electronic ones. It just shifts who's responsible for keeping them safe

Re: Source code of Swedish e-government services has been leaked

#42
post #23
post #10

Earlier quoted context omitted.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

The point of a system like this is specifically that it’s accessible and not air gapped. Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible

If you can't implement it securely then perhaps such an undertaking wasn't a good idea? In the vast majority of cases I don't see why PII ever needs to be available over the network for remote queries. For the purpose of verification isn't it sufficient to verify hashes or better yet to attest via smartcard?

Re: Source code of Swedish e-government services has been leaked

#43

I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.

I would guess that skatteverket.se, polisen.se, kronofogden.se are among those affected by the leak.

Re: Source code of Swedish e-government services has been leaked

#44
post #16

Earlier quoted context omitted.

If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.

> it is still easy to make misstakes. That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.

Imagine if the bank took such a cavalier attitude with the contents of my account.

Re: Source code of Swedish e-government services has been leaked

#45
post #23

Earlier quoted context omitted.

The point of a system like this is specifically that it’s accessible and not air gapped. Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible

If you can't implement it securely then perhaps such an undertaking wasn't a good idea? In the vast majority of cases I don't see why PII ever needs to be available over the network for remote queries. For the purpose of verification isn't it sufficient to verify hashes or better yet to attest via smartcard?

You can, they didn't; big difference.

Re: Source code of Swedish e-government services has been leaked

#46
Knowing swedish people's mindset I'm not surprised at all by the breach. What can be mildly surprising is that no major e-gov service has expressed concerns on their websites. Only on skatteverket.se, which is Swedish Tax Service website, there is a vague note on "maintenance work" planned for coming Saturday. Maybe totally unrelated though.

Re: Source code of Swedish e-government services has been leaked

#47
post #46

Knowing swedish people's mindset I'm not surprised at all by the breach. What can be mildly surprising is that no major e-gov service has expressed concerns on their websites. Only on skatteverket.se, which is Swedish Tax Service website, there is a vague note on "maintenance work" planned for coming Saturday. Maybe totally unrelated though.

Interesting, care to elaborate?

Re: Source code of Swedish e-government services has been leaked

#48
post #43

I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.

I would guess that skatteverket.se, polisen.se, kronofogden.se are among those affected by the leak.

Some other comments mention BankID private keys . That would be the biggest disaster as that’s what everyone uses to identify themselves “securely” on all government services.

Re: Source code of Swedish e-government services has been leaked

#49
post #32

The source code is the least of it! From the article: > citizen PII databases and electronic signing documents were also collected but are being sold separately

What does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?

If that is case, then it would have been wrong from the beginning for any government to keep hold of the private keys for the signature on my citizen card.

Because in that case they can sign documents on my behalf without my permission. In a court case, it would be near impossible for me to prove that the government gave my private key to someone else and that it wasn't me signing an incriminating document.

Post reply on HN