`123456' password used in Danish CPR data breach(cphpost.dk) |
`123456' password used in Danish CPR data breach(cphpost.dk) |
Thieves give it back now!
Since then I think medical data science is mainly a waste of tax payer's money.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
Oops, can I delete my comment, it was a copy paste mistake!
> Oops, can I delete my comment, it was a copy paste mistake!
What do you mean? You can safely post your passwords on the internet.
Equivalent to social security information in the US I guess.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.
Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
It was run by DXC Technology, the Danish branch of a US software house.
When doing a contract on such programs the Danish government must take the cheapest offer by rule
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.
Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.
Real world, as you say, not so simple. Everything has to deal with certain degree of forecastable nonsense, e.g. a bridge has to cope not only with traffic and winds, but the possibility that someone will be drunk in charge of a ship and crash into it.
> AI is built on human knowledge so guess what it will keep doing.
Yes, and also brings its own additional mess on top of that. All machine learning takes a huge number of examples to get good, so an LLM isn't just "read all the online courses in how to run a business", but also likely has 50 business versions of the recent demonstration of common sense failure with "I live 100m from a car wash, should I walk or drive?"
> How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
Many such disciplines. Perhaps all except maths and computer science? Or even including maths and computer science, given stats is part of maths and even compsci has to deal with fault tolerance.