Comment by mrweasel

12 hours ago

I have been advocating for Denmark to do the same for 15+ years. The fact that your social security number can be used for anything on it's own is a disaster. Mostly it can't anymore, because you have to do electronic signing with MitID, but it's still considered secret. If you own a home in Denmark, address information is already public, but a little hard to lookup.

The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.

>Because the demo was done with politicians

I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.

  • >I feel like this should be the default.

    The autorities do not, and the guy who "leaked" the CPR number of Mette Frederiksen was thrown in jail.

    On an unrelated note, I recently read about voyage of the Mayflower across the Atlantic. It's a captivating piece of history.

  The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.

From the source