Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

51–60 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#51

Earlier quoted context omitted.

Yes that's true - The Data Protection Agency see no reason to take any further action in this case. Their assessment is that there is a low likelihood of an actual leak (based on a written statement from the Chinese employee who opened the letter). And the SSI has promised to send such information encrypted going forward.

If I were a senior official at the Chinese foreign service, and I heard that one of my employees got such a CD and just gave it back to the Danes without notifying higher-ups, then I would want that employee's head. On the other hand, if I were a senior official in the Danish foreign service, then I would find my life a lot easier if no one was kicking up a fuss about the Chinese.

And you'd likely get it, along with the heads of his/her immediate family.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#52
post #7

Google Translate gives me, "Data Protection Agency takes no further action". Is that true? No-one is fined or prosecuted for this? Or even sacked?

As others write, the data protection agency doesn't have any real power. As a result very few companies and even other government agencies really care about the opinion of the data protection agency. It doesn't make sense to fine anyone, or even try to prosecute, because everyone will just claim that they are just doing as instructed, and a fine to government agency is a little weird. The issue is a very combination…

> the data protection agency doesn't have any real power.

Which is a shame, because the Charter of Fundamental Rights of the European Union is suppose to guarantee that data protection issues are protected by an independent body.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#53
I wonder if this would have been a story if a country other than China was involved. Of course, the information was carelessly handled but then again worse things have happened.. like sending a missile to the wrong address. The bias in the article is interesting, with the author of the article putting the words 'by mistake' in quotes to signal that the mere act of opening the package is suspicious. Over the years I have blindly opened plenty of mailed packages only to realize that it was actually addressed to someone else.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#54
post #53

I wonder if this would have been a story if a country other than China was involved. Of course, the information was carelessly handled but then again worse things have happened.. like sending a missile to the wrong address. The bias in the article is interesting, with the author of the article putting the words 'by mistake' in quotes to signal that the mere act of opening the package is suspicious. Over the years I h…

Yeah, it is not that big of a deal. Wrong address.. Happens all the time..

As a Danish person, I am really interested in the process of packaging these CD's. Who burned them? Who was in the room? Who collected that data? Was it an intern? Maybe a secretary? That is some really personal information. Maybe I can register as a researcher and get access? I dont know, but I want to find out. Maybe there is a really sophisticated social engineering attack hiding in this story....

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#55

The story from the Chinese Visa Application Office (CVAO) is that an employee opened the letter "by mistake": >"It said that it was contacted by an employee of the Chinese Visa Application Centre who said she opened the letter addressed to Statistics Denmark “by mistake” but then delivered the package to the statistics agency." (TheLocal, linked above, http://www.thelocal.dk/20160720/five-million-danish-id-numbe... )…

well, the Danish mail service who's one of its main purposes is to read and process the mailing address correctly failed. And they most likely have _many_ more processes and safeguards than any office mailroom.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#56
post #50

The Danish personal identification numbers are useless for identifying someone since we pretty much give them out to anyone who asks for it, and they can be calculated using some methods, which have been done to some politicians just to show the flaws in the system behind them.

Seems more like this make CPR numbers useless for identity verification, but even easier to identify someone with.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#57
Worse, at least according to Google Maps, it is only a 17 minute drive or 28 minute bus ride between Statistics Denmark and the Serum Institute.

At such a small distance, if such large amounts of confidential information must be delivered, I feel that it ought to be hand-delivered.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#58
These things keep happening in Denmark but the thing is, very few people actually care here. Avoiding mistakes of this caliber isn't rocket science but it does take a little effort and awareness and as long as nobody cares there is no motivation to make that effort.

In that sense this is just giving people what they're asking for. They're not asking for security so they're not getting it.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#59
post #43

This is ridiculous. It's not just Danish personal identification numbers, but ID numbers and health records for everyone who have lived in Denmark from 2010 through 2012. Quick recap since it's in Danish: A danish health authority, SSI, accidentally mailed two CDs containing unencrypted CPR-numbers and health records for 5.28m residents to the Chinese Visa Application Office. The Chinese delivered the letter to the i…

Just to give some perspective: These are the confidential ID numbers and health records, including for example psychiatric information, of more than 90 percent of the Danish population. It's not legal, but many organisations still trust you are, who you say you are, if you provide name and the ID number. You can still call some banks in Denmark and get information on the account balance if you state name, account num…

Are ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#60
post #59
post #43

Earlier quoted context omitted.

Just to give some perspective: These are the confidential ID numbers and health records, including for example psychiatric information, of more than 90 percent of the Danish population. It's not legal, but many organisations still trust you are, who you say you are, if you provide name and the ID number. You can still call some banks in Denmark and get information on the account balance if you state name, account num…

Are ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.

They are confidential in Denmark, or rather they were supposed to be.
Post reply on HN