The 'untouchable hacker god' behind Finland's biggest crime
91–100 of 183 posts
Re: The 'untouchable hacker god' behind Finland's biggest crime
#92This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.
You could use a fake name/address? That would make it hard to trace back the records to you should they leak.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#93Earlier quoted context omitted.
Indeed, the CEO was held criminally liable, but the charges were dropped in a higher court just recently. From the article: "In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025. (He declined my requests to interview him.)" More specifically, he was charged of a data protection crime (i.e., note that in Finland these GDP…
Funny whenever people complain about the GDPR here they're thinking they would be slapped with a €20Mi fine and that EU team 6 is going to parachute in their office and arrest everyone So they're saying this is not the case?
Re: The 'untouchable hacker god' behind Finland's biggest crime
#94Earlier quoted context omitted.
>Exactly, was it a burglary when your front door is open Legally speaking, yes in every place I've ever lived if all those things are the case it's still a burglary, although the cops may call the victim an idiot.
In the UK, there is no crime "burglary". "Breaking and entering" it's a criminal offence, and walking through an unlocked front door back door doesn't count. If you are on someone's land but didn't have to break in then that's trespass, which is just a civil offense. Theft is a crime in any case (indeed even if you're not on their land e.g. snatching a phone off the street).
Re: The 'untouchable hacker god' behind Finland's biggest crime
#95Wasn't he the guy that used tar for the leaked folder of data, but the tar included his user folder which contained his legal name?
Re: The 'untouchable hacker god' behind Finland's biggest crime
#96Earlier quoted context omitted.
Technically, yes it is still burglary. It's an odd position to take, that a crime was not committed or the offense isn't as bad if the difficulties of committing the crime have been removed or reduced.
It's a common attitude with people from low-trust societies. "I'm not a scammer - I'm clever. If you don't want us to scam your system why do you make it so easy?"
When people from high-trust societies move to a low-trust society, they either adapt to their new environment and take an appropriately defensive posture or they will get robbed, scammed, etc.
Those naïfs from high-trust societies may not be morally at fault, but they must be blamed, because they aren't just putting themselves at risk. They must make at least reasonable efforts to secure the data in their custody.
It's been like this for decades. It's time to let go of our attachment to heaping all the culpability on attackers. Entities holding user data in custody must take the blame when they don't adequately secure that data, because that incentivizes an improved security posture.
And an improved security posture is the only credible path to a future with fewer and smaller data breaches.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#97Earlier quoted context omitted.
Funny whenever people complain about the GDPR here they're thinking they would be slapped with a €20Mi fine and that EU team 6 is going to parachute in their office and arrest everyone So they're saying this is not the case?
The law is written such that they could do all that to a small family business that forgot to delete their Apache logs, which isn't good and leaves room for abuse even if they pinkie swear it's only meant for big violations.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#98Earlier quoted context omitted.
Yes, I would expect compensation to increase proportionally with accountability. What makes no sense is compensation that increases irrespective of accountability. Being the CEO of a company that handles risky, sensitive things should be risky for the CEO, personally. And their compensation can reflect that.
In other words, they need to hire people whose job it is to “please”. Provide Legal Exculpation and Sign Everything https://how-i-met-your-mother.fandom.com/wiki/Provide_Legal_...
Re: The 'untouchable hacker god' behind Finland's biggest crime
#99Earlier quoted context omitted.
Hard-coded, publicly available credentials are criminal to circumvent in germany. See https://www.heise.de/en/news/Modern-Solution-Court-of-Appeal... which is now settled, since the appeal was rejected. https://www.heise.de/en/news/Federal-Constitutional-Court-re... > At the end of the trial, however, this had little impact on the verdict. The presiding judge stated for the record that the mere fact that the [publicl…
Thank you for providing an example that is exactly showing how messed up this is: > Der Vorsitzende Richter gab zu Protokoll, dass alleine die Tatsache, dass die Software ein Passwort für die Verbindung gesetzt habe, bedeute, dass ein Blick in die Rohdaten des Programms und eine anschließende Datenbankverbindung zu Modern Solution den Straftatbestand des Hackerparagrafen erfülle > The Judge gave to protocol that just…
There is no European country which does a worse job at both of these. Germany is easily the number one country in the world for "protocol is everything". It doesn't matter how detrimental and damaging the rules are, the rules are the rules, and they must be followed. This case is the millionth example. The rules are interpretable as it being illegal to access data with a publically available password using this password, so we're going to apply them, despite it being patently absurd. For the first point, German's reponse to Gaza (the slowest in all of the West) said everything.
Re: The 'untouchable hacker god' behind Finland's biggest crime
#100"the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it" There _should_ be a bunch of people in jail for that. Including, but not limited to the CEO. It should also include all the people on the org chart between whoever set that database up and the CEO.