← Back to context

Comment by gnull

13 hours ago

In Sweden, to avoid this kind of malicious leaks, we leak the residents' data officially. https://hitta.se lets you look up personal numbers, names, addresses, birthdays and sometimes phone numbers of any resident. The residents are not asked for consent, the data goes there automatically (some of my friends had success with having it removed from hitta, but it comes back once you change residence address).

It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.

What's the big deal, Danes? What do you have to hide?

(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)

These services were just the natural extension of the phonebook. At the exact same time as the phonebooks stopped being circulated, these services popped up online.

And since everyone's name, address and phone number was in the phone book (At least for their city) people didn't find it weird when it popped up online. Sure, to do the same thing for the whole country you'd need dozens of phonebooks for different areas, but it was just the same information.

Which makes me wonder: weren't there phonebooks in US cities and in other countries before? Were they incomplete/opt-in?

The key thing about the Swedish phonebooks were that they were opt-out, so people were basically all in the phone book. So even before the internet, it was just very natural that your name, address and phone number was public. "Getting someone's number" as in moves and TV wasn't a thing. You could just call anyone if you knew their name.

  • Yes, we had phone books. And it was useful. But they didn't generally include personal information such as birthdates, salary, etc. And it was easy to opt out. Additionally there were not a bunch of online services with financial impacts that used phone numbers are primary keys.

    And, importantly, they were physical in a time when it was hard to collect and collate the data in all of them. In 1990, there were about 5,000 distinct "white pages" phone books in the US. And OCR was pretty crappy.

    Also, in all the places that I lived, mobile numbers didn't end up in the phone books, only residential landlines did. I don't know if that was universal.

    • Right. It was harder to spoof my bank (since banking was an in-person affair), and steal all my money back then. Now, this information is available to anyone in the world, and there aren’t good protections. I don’t know the solution, but the world is a different place than it was in the days of white-pages.

  • In the UK, you could always choose to go 'ex-directory'. More and more people did over time I think and the personal part of the phone directory got slimmer and slimmer, basically just leaving the business part.

Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?

Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.

  • I've been told back in the day it was quite normal get a physical, dead-tree book with similar information sent out to you every year, until people decided that was a waste of paper.

    • It used to be illegal here to reverse look up a name matching to a phone number, since it was "owned" by the state telephone company and they didn't want that happening. But you were allowed to reverse look up the address of a number and then look up the person and match it to the number. So that magic happened under the hood. The trick was getting the residential information but since that wasn't a problem in the '90s I'm sure it is even less of an issue now.

      2 replies →

  • When I lived Norway, my gf at the time would look up the license plates of cars that annoyed her and could see how much debt they had on the car to make fun of them. Scandinavians are oddly very open with this type of personal info.

    • In Sweden I have looked up someone's phone number through the info I got from the license plate to notify the owner of a BMW M5 that their 20 years old son was often speeding down the 30km/h street close by my house where kids would cross coming from the metro or a bus stop nearby.

      The owner just thanked me, and said was going to have a chat with the driver. Never saw that car speeding nearby again.

    • When you do this the owner of the car is notified. And there is an audit trail because you do it by sending a text to a premium number.

      The debt information is there so that when the owner sells the car the buyer can check to see if they actually really do own it outright.

    • I don't even see salary or what your debt is as "personal information" (am Swede not in Sweden), personal information is stuff that no one else would need to know. What people earn affects not just people around you and others in the workplace but also society at large, makes a ton of sense for that stuff to be public.

      Especially great that you can see what employees at competitors earn, what your peers at your workplace earn and what your boss earns. Become a hell of lot easier to ensure you're not exploited. Helps that Sweden has a really strong union-culture as well.

      9 replies →

  • I learned this (public info) about Sweden a few years ago and as an American it really pissed me off.

    In the US you can get the exact same info and probably more by simply paying a private corporation/middle man (background check services).

    It seems like a huge trend in many sectors. We have the same setup as other countries, but shittier for consumers because there are lifeless leaches as middle men to make a quick buck.

  • Yes, it is possible to have a protected identity.

    • It seems that you can have a protected address in Denmark as well. Apparently, the protected address is even a field in the current leak.

      2 replies →

    • Ah, so the “open” system is actually a two-tier system where everyone’s information is equally open except for those who are more equal than the rest.

  • > Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?

    Of course, contrary to popular belief, Sweden is not a perfect country without violence and shit people!

    It seems to be somewhat respected overall though, but I'm sure it'll eventually disappear. For the people who are stalked and what not, it's relatively easy to apply and get "protected identity" if you're affected by those things, and then eventually all those 3rd party websites remove the stale data.

    Personally I solved this problem for myself by moving away from the country.

    • > Personally I solved this problem for myself by moving away from the country.

      Quite drastic to move away from a country for just this. Did you only do it for just this? Or was this simply one of the factors why you moved away?

  • There are. You can get a protected identity if you have that issue.

    The current system has been in place around 1770. There's some pushback against it the last few years.

I have been advocating for Denmark to do the same for 15+ years. The fact that your social security number can be used for anything on it's own is a disaster. Mostly it can't anymore, because you have to do electronic signing with MitID, but it's still considered secret. If you own a home in Denmark, address information is already public, but a little hard to lookup.

The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.

  • >Because the demo was done with politicians

    I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.

    • >I feel like this should be the default.

      The autorities do not, and the guy who "leaked" the CPR number of Mette Frederiksen was thrown in jail.

      On an unrelated note, I recently read about voyage of the Mayflower across the Atlantic. It's a captivating piece of history.

  •   The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.
    

    From the source

Talk about creating our own problems lol. We’ve made a total mess of things. No onset normal people hate us technologists.

I was actually surprised when I heard about this for the first time. Also I've heard that even the salaries of people are publically available. That's really cool.

  • This probably improves economic efficiency a lot. Want to build something and remember meeting a relevant expert 3 years ago at a party? Easy to find that person and start doing business...

Yeah, Offentlighetsprincipen is quite Swedish, isn’t it? I like it. Not sure it was made for the 21st century though.

Personal numbers are not available from hitta.se.

  • Not in full as it doesn't have the last 4 partly random digits, though personal numbers aren't that useful even if it was the full one.

    • If you login with an account (which you can create for free), you can also see the personnumber. See someone elses salary without them knowing about it for 39/49SEK, which is around 3-4$

      1 reply →