Live data from Hacker News

The 'untouchable hacker god' behind Finland's biggest crime

theguardian.com

91–100 of 183 posts

Re: The 'untouchable hacker god' behind Finland's biggest crime

#92

This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.

You could use a fake name/address? That would make it hard to trace back the records to you should they leak.

I think most people are not seeking therapy and even fewer are seeking therapy under hostile conditions.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#93

Earlier quoted context omitted.

Indeed, the CEO was held criminally liable, but the charges were dropped in a higher court just recently. From the article: "In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025. (He declined my requests to interview him.)" More specifically, he was charged of a data protection crime (i.e., note that in Finland these GDP…

Funny whenever people complain about the GDPR here they're thinking they would be slapped with a €20Mi fine and that EU team 6 is going to parachute in their office and arrest everyone So they're saying this is not the case?

The law is written such that they could do all that to a small family business that forgot to delete their Apache logs, which isn't good and leaves room for abuse even if they pinkie swear it's only meant for big violations.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#94

Earlier quoted context omitted.

>Exactly, was it a burglary when your front door is open Legally speaking, yes in every place I've ever lived if all those things are the case it's still a burglary, although the cops may call the victim an idiot.

In the UK, there is no crime "burglary". "Breaking and entering" it's a criminal offence, and walking through an unlocked front door back door doesn't count. If you are on someone's land but didn't have to break in then that's trespass, which is just a civil offense. Theft is a crime in any case (indeed even if you're not on their land e.g. snatching a phone off the street).

OK, I probably should specify closer, but while the other commenter has noted there is "burglary" in the UK, I was using burglary in the vernacular, meaning you entered someone's house without their knowledge and stole some shit. I was perhaps unclear with this and in fact in some places what entering someone's house that is not locked and stealing some shit may be a different crime than when it is locked both variations are still generally described, in common usage, as a burglary and are both illegal according to every legal code of every place I've lived, which I've lived in a lot of Western Civ type places.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#96
post #61

Earlier quoted context omitted.

Technically, yes it is still burglary. It's an odd position to take, that a crime was not committed or the offense isn't as bad if the difficulties of committing the crime have been removed or reduced.

It's a common attitude with people from low-trust societies. "I'm not a scammer - I'm clever. If you don't want us to scam your system why do you make it so easy?"

The Internet is the ultimate low-trust society. Your virtual doorstep is right next to ~8 billion other peoples' doorsteps. And attributing attacks and enforcing consequences is extremely difficult and rather unusual.

When people from high-trust societies move to a low-trust society, they either adapt to their new environment and take an appropriately defensive posture or they will get robbed, scammed, etc.

Those naïfs from high-trust societies may not be morally at fault, but they must be blamed, because they aren't just putting themselves at risk. They must make at least reasonable efforts to secure the data in their custody.

It's been like this for decades. It's time to let go of our attachment to heaping all the culpability on attackers. Entities holding user data in custody must take the blame when they don't adequately secure that data, because that incentivizes an improved security posture.

And an improved security posture is the only credible path to a future with fewer and smaller data breaches.

See also: https://news.ycombinator.com/item?id=25574200

Re: The 'untouchable hacker god' behind Finland's biggest crime

#97

Earlier quoted context omitted.

Funny whenever people complain about the GDPR here they're thinking they would be slapped with a €20Mi fine and that EU team 6 is going to parachute in their office and arrest everyone So they're saying this is not the case?

The law is written such that they could do all that to a small family business that forgot to delete their Apache logs, which isn't good and leaves room for abuse even if they pinkie swear it's only meant for big violations.

Only after informing you, giving you the opportunity to fix things and many many other steps. The harshness is directly related to the size of the company and the companies willingness to fix any issues. They want companies to comply.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#98
post #69

Earlier quoted context omitted.

Yes, I would expect compensation to increase proportionally with accountability. What makes no sense is compensation that increases irrespective of accountability. Being the CEO of a company that handles risky, sensitive things should be risky for the CEO, personally. And their compensation can reflect that.

In other words, they need to hire people whose job it is to “please”. Provide Legal Exculpation and Sign Everything https://how-i-met-your-mother.fandom.com/wiki/Provide_Legal_...

That could be outlawed as well as it probably wouldn’t be too difficult to show that person wasn’t actually making any of the decisions. Not that I expect any of this will ever happen.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#99
post #21

Earlier quoted context omitted.

Hard-coded, publicly available credentials are criminal to circumvent in germany. See https://www.heise.de/en/news/Modern-Solution-Court-of-Appeal... which is now settled, since the appeal was rejected. https://www.heise.de/en/news/Federal-Constitutional-Court-re... > At the end of the trial, however, this had little impact on the verdict. The presiding judge stated for the record that the mere fact that the [publicl…

Thank you for providing an example that is exactly showing how messed up this is: > Der Vorsitzende Richter gab zu Protokoll, dass alleine die Tatsache, dass die Software ein Passwort für die Verbindung gesetzt habe, bedeute, dass ein Blick in die Rohdaten des Programms und eine anschließende Datenbankverbindung zu Modern Solution den Straftatbestand des Hackerparagrafen erfülle > The Judge gave to protocol that just…

Germany is the most contradicdory country I know of, and such a huge warning flag to anywhere else. For decades, half of children's education has been spent on hammering in "Never Again". Surely there are two huge lessons to learn there: 1. Do not judge the value of people based on their biological characteristics they were born with 2. "I was just following orders" is not an excuse, and one needs to instead do what is right regardless of protocol.

There is no European country which does a worse job at both of these. Germany is easily the number one country in the world for "protocol is everything". It doesn't matter how detrimental and damaging the rules are, the rules are the rules, and they must be followed. This case is the millionth example. The rules are interpretable as it being illegal to access data with a publically available password using this password, so we're going to apply them, despite it being patently absurd. For the first point, German's reponse to Gaza (the slowest in all of the West) said everything.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#100
post #10

"the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it" There _should_ be a bunch of people in jail for that. Including, but not limited to the CEO. It should also include all the people on the org chart between whoever set that database up and the CEO.

Still reading the story but just hit that line and came here to snarkily post, “another MongoDB success story”. I should probably talk to my therapist about this desire to be seen as funny.
Post reply on HN