Live data from Hacker News

Source code of Swedish e-government services has been leaked

darkwebinformer.com

81–90 of 263 posts

Re: Source code of Swedish e-government services has been leaked

#81
post #75
post #74

Earlier quoted context omitted.

No, public information for anyone. You realize that if it's public information, then it's public, and anyone can re-publish it online? There are websites for that. I can get the complete identification number, home address, phone number, etc for any Swedish citizen (that does not have a protected identity) in less than a minute.

You can get all of that one-by-one? Or can you get the whole database at once?

I cannot trivially get the whole database, no. But I kind of fail to see what a malicious actor would do with a large database of public information that they couldn’t otherwise do. The system is designed such that you can’t really do a lot of malicious stuff with just public data, and the stuff you can do (scam calls, etc) is probably not meaningfully more effective if you have the whole database than if you do manual lookups or web scraping. I’m open to being proved wrong about that however.

Basically: obviously it's not desirable to have that full database in the hands of a malicious actor but I'm not sure it's such a big deal either. Again, it's public data by design.

Re: Source code of Swedish e-government services has been leaked

#82

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

I heard a rumor that some people use this to check their neighbour's revenue and sometimes make snark comments if one of them has a high revenue but lives in a "average revenue" part of town.

They'd say that if you earn a lot, you shouldn't take a cheap housing.

Any truth to that?

Re: Source code of Swedish e-government services has been leaked

#83
post #57

Earlier quoted context omitted.

I saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.

some report it's basically the code and certs responsible for BankID SSO No. CGI has nothing to do with BankID. IMO the most credible reports suggest that the source code and data involved are related to these four services: https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Mina engagemang offers a user-friendly and flexible solution that allows your customers to manage their cases directly through a p…

> CGI has nothing to do with BankID

That's incorrect. Skatteverket used CGI for BankID-login, I don't know if they still do. I have personal experience working on a BankID-login using CGI for another company and it is still active.

Edit: I just confirmed Skatteverket still uses CGI for BankID-auth. "funktionstjanster" is CGI.

Re: Source code of Swedish e-government services has been leaked

#84
post #32

Earlier quoted context omitted.

What does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?

If that is case, then it would have been wrong from the beginning for any government to keep hold of the private keys for the signature on my citizen card. Because in that case they can sign documents on my behalf without my permission. In a court case, it would be near impossible for me to prove that the government gave my private key to someone else and that it wasn't me signing an incriminating document.

I apparently didn't phrase that very well. If what is the case? I was trying to ask which case was the case, not trying to claim that something specific was the case.

I'm familiar with electronic signatures, and I know what documents are, but I have never heard the phrase "electronic signing documents" and don't know what that is supposed to mean. What kind of documents? Documents about signing, documents that were signed, documents in the sense that files containing keys could be considered documents, or what?

Re: Source code of Swedish e-government services has been leaked

#85
post #16
post #10

Earlier quoted context omitted.

You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.

If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.

"misstakes", love it, almost peotic

Re: Source code of Swedish e-government services has been leaked

#86

Earlier quoted context omitted.

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

I heard a rumor that some people use this to check their neighbour's revenue and sometimes make snark comments if one of them has a high revenue but lives in a "average revenue" part of town. They'd say that if you earn a lot, you shouldn't take a cheap housing. Any truth to that?

Yep, that tracks.

There's also the underlying current of Jantelagen (Law of Jante) https://en.wikipedia.org/wiki/Law_of_Jante

Re: Source code of Swedish e-government services has been leaked

#87
post #84

Earlier quoted context omitted.

If that is case, then it would have been wrong from the beginning for any government to keep hold of the private keys for the signature on my citizen card. Because in that case they can sign documents on my behalf without my permission. In a court case, it would be near impossible for me to prove that the government gave my private key to someone else and that it wasn't me signing an incriminating document.

I apparently didn't phrase that very well. If what is the case? I was trying to ask which case was the case, not trying to claim that something specific was the case. I'm familiar with electronic signatures, and I know what documents are, but I have never heard the phrase "electronic signing documents" and don't know what that is supposed to mean. What kind of documents? Documents about signing, documents that were s…

In Portugal we were early adopters for digital signatures on citizen cards.

You use the card reader, insert your gov-issued identification and can sign PDF papers which have legal validity since the private key from the citizen card was used.

Now imagine someone signing random legal documents with your ID for things like debts, opening companies or subscritions to whatever.

Re: Source code of Swedish e-government services has been leaked

#88
post #32

The source code is the least of it! From the article: > citizen PII databases and electronic signing documents were also collected but are being sold separately

What does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?

To the best of my understanding it means that a system made by CGI for digital signing of documents (as in: you get something like a PDF from a government agency and need to digitally sign it and send it back) has had its source code and/or some data belonging to it leaked.

Skatteverket, the Swedish tax authority, has been quoted in media as confirming that they use CGI's system for digital document signing but that none of their data nor that of any citizens has been leaked.

https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...

"One of the government agencies that uses CGI’s services is the Swedish Tax Agency, which was notified of the incident by the company. However, according to the Swedish Tax Agency, its users have nothing to worry about.

“Neither our data nor our users’ data has been leaked. It is a service we use for e-signatures that has been affected, but there is no data from us or our users there,” says Peder Sjölander, IT Director at the Swedish Tax Agency."

Re: Source code of Swedish e-government services has been leaked

#89

Ok, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any addition…

I think this is good to highlight for non-Scandinavians. Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings. Personal identification numbers do not tend to be considered private in the same…

And then there are widespread amounts of identity theft and mapping out of minorities, but you may sleep well as everyone knowing where you do so is an important step in making sure corruption is no more, don't think too much about it.

Re: Source code of Swedish e-government services has been leaked

#90
post #57

Earlier quoted context omitted.

some report it's basically the code and certs responsible for BankID SSO No. CGI has nothing to do with BankID. IMO the most credible reports suggest that the source code and data involved are related to these four services: https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Mina engagemang offers a user-friendly and flexible solution that allows your customers to manage their cases directly through a p…

> CGI has nothing to do with BankID That's incorrect. Skatteverket used CGI for BankID-login, I don't know if they still do. I have personal experience working on a BankID-login using CGI for another company and it is still active. Edit: I just confirmed Skatteverket still uses CGI for BankID-auth. "funktionstjanster" is CGI.

OK, let me rephrase that: CGI, while they may "have something to do" with BankID in the sense that they have developed systems that integrate with it, does not itself develop BankID and does not hold any private keys for BankID.
Post reply on HN