Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

61–70 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#61
post #21
post #15

I like paper documents for this very reason. It's very hard to steal everyone's documents when they weight about the same as a train.

But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.

Problems with well-known solutions 100 years ago:

"Fireproof file rooms and cabinets in the 1920s were crucial for protecting business and government records during the rapid expansion of the industrial era. The era saw a massive shift from flammable wooden office furniture to robust, steel-based storage designed to resist both fire and water damage."

That's a Google AI summary - but I've been in a fair number of buildings with such rooms. Thick concrete walls, heavy steel fire doors, no other openings, nothing but steel file cabinets in 'em, sealed electric light fixtures that look like they belong in a powder magazine (where one spark could kill everyone) - it's really simple tech.

And "high ground" was a reliable flood protection tech several centuries before that.

Re: Source code of Swedish e-government services has been leaked

#62
Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any additional) addresses of individuals

A Swedish citizen database is... you know. fun. But not exactly hard to get hold of.

[1] https://www.statenspersonadressregister.se/master/start/engl...

Re: Source code of Swedish e-government services has been leaked

#63
post #58
post #55

Earlier quoted context omitted.

That's an interesting guess that I assume is based on absolutely nothing?

Yes, nothing and the facts that these are government services, they use BankID and they updated their websites with "maintenance work" announcements for tomorrow, Saturday. For kronofogden.se there was no maintenance planned just half an hour ago. Knowing swedish tendency to plan things months ahead I would _guess_ that this maintenance work has been rushed due to some circumstances.

It's quite possible that the maintenance is related, but I can nearly 100% assure you this has absolutely nothing to do with BankID. I don't know who suggested that but they are either poorly informed or actively trying to sow FUD.

Re: Source code of Swedish e-government services has been leaked

#64

I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.

It's not going to be a specific service or agency with a domain name, it's going to be services that are either internal and used by employees only, or that are integrated into other systems that you may be interacting with without knowing it.

Re: Source code of Swedish e-government services has been leaked

#65

Swedish news has some quotes from authorities that nothing of value has been leaked, and a quote from the service CGI that it only concerns test servers.[1][2] [1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform... [2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...

As a Swede this is giving me shudders, the statements reeks of paper-pushers and certification-chasers that don't seem to understand fundamental risks of how how threat actors can move around once having established footholds, hopefully there's more competent people down in the trenches.

Re: Source code of Swedish e-government services has been leaked

#66

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

> by simply signing an agreement with SPAR

But that seems like a completely different thing than a nefarious and anonymous person or group having access to the entire database.

Re: Source code of Swedish e-government services has been leaked

#67
post #19
post #14

How much GDPR fine will they pay? Oh wait it's gov so nothing / does no matter even if. Who will take responsibility and get fired and lose all pension etc.? Oh wait no one. Well the citizens need to suck it up.

Few years ago a huge NRA database was left public with admin/1234 or similar by the Bulgarian NRA. They government fined itself some non-trivial amount, then in the source/destination IBAN they put the same value and paid the fine. They managed to find someone to blame and it was not the person who left the database but the person who found it. Turns out that if you leave the PII of a whole country open to the public…

[dead]

Re: Source code of Swedish e-government services has been leaked

#68
post #54
post #33

Earlier quoted context omitted.

> Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the…

I have (the start of a) solution, but it's a boring one: You have to have people who care about this stuff. If you don't care, the rest does not matter. It does not matter if, when and how you outsource if you don't care about the outcome. You can't just pay someone a salary, nor a consulting bill, check the box and say you've done your part. And the other way around: These huge consulting conglomerates would get ver…

I don't think that's a particularly novel idea, the question is how do you get people who care in an organization that has hundreds of thousands of employees (the public sector)?

Re: Source code of Swedish e-government services has been leaked

#69
post #66

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

> by simply signing an agreement with SPAR But that seems like a completely different thing than a nefarious and anonymous person or group having access to the entire database.

Yeah, nefarious or anonymous people have never used the internet so they could never find out that this was all public information.
Post reply on HN