Live data from Hacker News

Five million Danish ID numbers sent to Chinese firm by mistake

thelocal.dk

61–70 of 84 posts

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#61
post #55

The story from the Chinese Visa Application Office (CVAO) is that an employee opened the letter "by mistake": >"It said that it was contacted by an employee of the Chinese Visa Application Centre who said she opened the letter addressed to Statistics Denmark “by mistake” but then delivered the package to the statistics agency." (TheLocal, linked above, http://www.thelocal.dk/20160720/five-million-danish-id-numbe... )…

well, the Danish mail service who's one of its main purposes is to read and process the mailing address correctly failed. And they most likely have _many_ more processes and safeguards than any office mailroom.

I am a Dane. I have twice received mail incorrectly sent to my current address. One was sent to somebody with a different name, to an address that was close to but not the same as my previous address, the other was to a person who may have lived here but was not the previous occupant.

This does not include the letters that should have gone to my neighbors but was put in the wrong letter box.

While I naturally assume this is deliberate I won't rule out that this is just complete incompetence.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#62

So, to summarise - burning it to CD is actually fine, but they should have used an in-house courier.

Please don't be uncharitable in HN comments; i.e. please don't choose a weak interpretation of what someone said in order to make it look bad.

We detached this subthread from https://news.ycombinator.com/item?id=12128662 and marked it off-topic.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#63

Earlier quoted context omitted.

Likely the capability exits for when someone moves to another part of the country, and the local doctor wants to check the new patient's medical history. Note also that the data was meant for what i assume is the national statistics office. Likely for investigating changes in danish public health over recent years. Unless by airgapped you mean to build a separate, free standing, network just for delivering medical re…

First, this is not about doctors exchanging patients' medical histories, it's about two central government offices exchanging everybody's medical histories. Second, the fact that security is (really!) hard is not a valid argument against doing it. Third, there's a huge difference between the appropriate levels of security around individual patients' medical histories, a single doctors office worth of patients' data,…

That it is hard isn't an excuse. That the customers don't pay for security is. And by pay I mean not only the paycheck but also funding and giving prestige and power to doing so. Government IT security is often seen as a necessary evil and most troubles stem from that view.

If you buy a cheap knockoff don't complain when it turns out to not be as good.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#64
post #45
post #4

Earlier quoted context omitted.

Correction: SSI sent a letter containing two unencrypted CDs containing CPR-numbers and health records for 5.28 residents in Danish municipals between 2010 and 2012 to the Danish statistics agency (Statistics Denmark). Post Danmark (postal service) accidentally delivered the letter to Chinese Visa Application Centre instead. When the employee responsible for receiving the letter noticed the mistake upon opening, the…

Was postman of Chinese descent?

Virtually all spy agencies recruit foreign nationals to do their dirty work.

Also your question has a 1 in 5 chance of the answer being "Yes".

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#65
post #20

Earlier quoted context omitted.

Let's assume they have it. What kind of interest would you say the Chinese government has in the health records of a few million Danish residents? I don't know, maybe it's really important, but then maybe it's not that critical after all.

Hi, nice to meet you Johan! Can I get you a drink? Oh, you're an electrician? That's nice, I sell light fixtures. ... Good to see you again Johan! You'll never believe, I was down at XYZ Clinic yesterday, and they'd left your file out!! Careless right? How did you break it to your wife you had herpes? Oh, she didn't know?! Man, sorry I mentioned it, I'll keep that quiet for sure. ... Man, it's been a hard month Johan…

I'm confused. Who is this mysterious stranger who doesn't sell light fixtures?

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#66
post #33

Earlier quoted context omitted.

They use it can track the movements of Chinese residents abroad, to blackmail Danes who are assisting Chinese disidents, run scams at doctors offices or insurers in order to get documentation for spies. I am sure there is more, I am no expert in this sort of thing.

Plus identity theft to help spies assume a false identity when gathering information. And of course: Selling the health records to insurers in order to allow them to set prices for prospective customers. I'm sure insurance companies would pay nicely for this.

I'm not Danish, but...

1. Denmark does not have a private health insurance market.

2. Any company even considering about doing this would be in a huge pot of boiling water, if the public, or the police got wind of it.

Any above-board business would not want to touch lost/stolen health data with a ten-foot pole. In addition to the legalities of this, this opens a huge liability hole, in terms of keeping it secure.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#67
post #45

Earlier quoted context omitted.

Was postman of Chinese descent?

Virtually all spy agencies recruit foreign nationals to do their dirty work. Also your question has a 1 in 5 chance of the answer being "Yes".

    > Also your question has a 1 in 5 chance of the answer being "Yes".
Assuming a uniform distribution of postman nationality. If we go by the CS literature, postmen seem always to be Chinese. :)

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#68
post #9

Earlier quoted context omitted.

Now they must assume that information is compromised and take action.

Which is what? Give every Dane a new health record?

I read that to mean _legal_ action.

IANAL, and can't profess to any knowledge whatsoever of Danish law, but opening a package clearly addressed to someone else without permission may be reasonable grounds for litigation.

Though to the question "what good will that do", you're right, it's not like new health records can be issued.

Depending on the details of what was shared and what ties them to an individual though, I suppose it might be possible to issue new IDs.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#69
post #60
post #59

Earlier quoted context omitted.

Are ID numbers confidential in Denmark? They (personnumer) seem fairly widely shared in Sweden and Finland.

They are confidential in Denmark, or rather they were supposed to be.

Considering everyone and their cousin has your CPR number over here, I fail to see how it could be seen as confidential. My landlord has my CPR, my company has my CPR, my network operator has my CPR, and my language school has my CPR.

Not knowing my CPR has never been a problem, but knowing it has never been an advantage. It's a unique ID as a citizen, but that's as far as it goes.

Every time I call my bank, I have to give the amount of cash available on my account for them to "authenticate" me, or tell them when was the last time I logged on to the website.

Re: Five million Danish ID numbers sent to Chinese firm by mistake

#70
Disclaimer: I 100% believe in the idiom "don't attribute to malice what could equally be caused by ignorance".

But I think all those involved should have permanent monitoring on their bank accounts and living status incase a suspiciously large wire were to come from a Chinese entity. This is happening way to often not to become a source of plausible deniability to future criminals. "It was an accident officer I swear!". Sympathies to all those effected by this incident.

Post reply on HN