Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
> I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.
As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).
They way I see it, there needs to be enough slack in an organization and the timelines for major products for people to not do the bare minimum. When management pushes goal X, and pushes hard, everything else starts to decay, including security. People need enough time to do the things they know they should do, but don’t feel they have the time for. At least this is where I’ve seen a lot of issues arise.
> I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I think there's also a big part of the line that Jennifer Lawrence says in the satiric comedy "Don't look up":
"They are not even smart enough to be as evil as you're giving them credit for."
Just as the person who picks 123456 as a password doesn't see where the problem is, I think there are really quite a lot of people dumb enough all along the decision chain to think that firing the person who reported the problem did actually fix the problem.
When you have bad practice and process it can erode the security discipline of everyone working within the system. Until they commit brazen crap like reusing simple passwords everywhere.
Im not in tech but still in corporate. Our store went through 6 GMs in 5 years. The problem is actually the corporate, not the new guy every 8 months who is being brought on to save the day. I think they're going to replace him again next year without addressing any of the issues on the ground.
Rome wasn’t built in a day, not did it fall in a day. In a capitalist society you can gauge overall direction and success of the society but how well the market and private enterprise is doing, and well not merely in context of maximising shareholder value but as a fundamental part of the social fabric.
> I dont understand why there is not massive reorganisations in systems
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
A major problem we have is that computer programming is not engineering as people like to say. An engineering discipline VALUES redundancy and is always designing for safety. Programming likes to think of itself as math, and deliberately choses less redundancy for the sake of convenience and speed. The classical example is how operating systems are written with languages that allow an index to be out of bounds. We now have systems that are glued together using bubble gum pretending to be safe, when they fail in the most horrible way when one of the links break.
Yeah that is a pretty weird opinion. Who cares about if he gets fired. He should be charged with criminal negligence and face prison time. Everyone is responsible for their own actions and its always possible to quit.
The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)
Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...
Next step in typical security team fashion: Prevent password managers from working, by obscuring the password field, using click-to-type passwords or similar shenanigans, because fuck you, that's why...
Until security forces the password manager session to expire after 1 hour, and forces the master password to be 16 char long with a combination of lower, upper, digit, punctuation, moon phase, astrological sign. And then they force you to change it every 2 months, and you can't reuse it until the next time Halley's comet is in the solar system.
You're missing the systemic problem the parent is talking about.
> It's tussle between two counter-acting forces at play.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.
Productivity and Aesthetics could also be said to be counter acting forces. Or really anything that requires contemplation. I think the problem is in how some people define "productive". Is it productive to have significant security problems which cause more work?
Sorry, if your job title implies even a smidgen of security responsibility, you deserve to be fired for "123456" as your password. The person who was an administrator would fall under this label. Besides, "If productivity is not your goal, then security is not my goal." is what results in draconic security measures, because employees can't be trusted AT ALL. I really don't understand your comment.
The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"
The guys who are really into keyboard layouts would argue vehemently that 123456 is more ergonomic as it's an "inward roll" vs 6 consecutive presses of a key that aligns to the pinky
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
I'd add missing MFA as weakness number three, at minimum.
Problem number 4 is that the "password" was leaked, and the company (Pays ApS) didn't figure that out.
Problem number 5 - the "password" belonged to a _former_ employee. How was that account not disabled?
Problem number 6 - how can a company with two employees get access to this register in the first place? Don't they need to show compliance with some security standard that would be not possible to deliver for such a small company?
If you start thinking more about this, more and more problems pop up.
There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
My first thought was "maybe security compliance training should include mandatory screening of Spaceballs"
Which does remind me of my game theory class in college... the professor would show movie scenes that demonstrated the game model we would be studying that week. It was quite effective, and certainly helped keep me engaged.
Fingers crossed this late sequel parody somehow duplicates the original's charm. It would be embarrassing for Disney if it's better written/received than their own attempt with the source material.
It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
> Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
I think you mean that isn’t how they are meant to be used. If that was consistently the case in practice, however, no one would talk about this leak (at least not the CPR number part of it).
I doubt the CPR number alone will give you access to obtain credit and the like today, but you can absolutely go into a pharmacy and buy someone’s prescription medicine with just their CPR number, and you for sure can get access to a lot of data by calling various entities and providing your CPR number as proof of identity (but at least fewer now than used to be the case in the past).
If the CPR number was truly made public information, those cases would be much more obviously wrong. The fact that CPR numbers are de facto considered pseudo-secret makes things much worse.
Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
Why would you think active directory has anything to do with this? That seems like a super random conclusion.
What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.
I mostly agree with you, but it's worth considering that there are much more fundamental issues with absolutely abysmal passwords like "123456" . If my password is "ra1nbowC0okies776", and it shows up in another place, it's a pretty strong signal that I reused it, because it's unlikely to have been picked independently by someone else. If my password is "password", even if I never reuse it, that's still far worse than me reusing the password above.
They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
and make the people who didn't put any sort of limits on how many records can be downloaded before there has to be a check on what is going on or any of the other stupid security holes that were found, make them criminally responsible as well. At some point you can be sure you'll be imprisoning someone for making a typing mistake (accidentally commented out some code) or a logic mistake (I should have said IS NOT, but instead I said IS) or just being tired.
There are typically quite a few steps between initial access and domain domination, which I assume is what they ended up with, considering they have administrator account passwords. Well, unless you are using 123456 as the password for an admin account.
The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
I always find the use of acronyms a lack of education and manner. A way for the uneducated to try to sound sophisticated.
When I get an internal mail with multitude of acronyms I know that the people that wrote it does not care if anyone is going to read/understand it or not. It goes directly into the trash.
Something is fishy about this story though. The credentials used was allegedly leaked and purchased on the black market. But the it doesn’t matter how weak or strong the password is.
The information about the leaked password is from the guy claiming to be the hacker who anonymously talked to the media.
Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`.
If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`.
If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
Sorry, I might be too young to remember those times.
Can you tell me more, please? I'm genuinely curious.
Because from the sound of that, it feels that it would patch the `123456` problem, but opens up a new vulnerability - the password is known / being sent through / printed, so it can be leaked from that source.
That would work from the technical point of view, I do agree.
On the other hand, how would we make "lazy" people use those? And ensure that won't reuse the same password on some vibe coded forum that will store them in the plain text and get hacked in a few weeks =)
That's why I mentioned that mindset shift as the prerequisite.
CPR is code for "registersamkøring". Register matching. The small wellfare nation needing to be able to see the populace as a sum of abilities and leanings and willingness to be swayed and pushed to support present and future economic needs of the whole.
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.
Equivalent to social security information in the US I guess.
For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
I'm not super familiar with SSN in US of A, but I think the Danish one is not has secret. Don't get me wrong, the leak is not good, but there is a limit to what you can do with it.
Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.
Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
Denmark comes from a long line of institutional trust: We say we do this, so we do it, so everyone else will naturally expect that.
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
honestly you'd think by 2026 they would at least force a special char so the password becomes 123456!. im not even suprised anymore tbh, just disapointed.
Literally nothing will prevent this but software building codes and enforcement. That's why we have building codes. We let builders do whatever they wanted for decades and it ended in disaster, so we stopped letting safety be optional.
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
There's a very "child-like" (not in a good way) form of responsibility that everyone seems to lean into as they climb up - very intent-based.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
> I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
5 replies →
In a country like Denmark it's very common for a higher up to resign over something like this.
Yes I completely agree. In the local news there was focus on which company it was and that the password was 123456.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
The older the system, the higher the chance it never got a proper security audit, and/or it was built with a lot of implied trust, like most old Internet standards are.
As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).
3 replies →
The security audit recommended changing the password to 234567, but management rejected it because it would require retraining staff
They way I see it, there needs to be enough slack in an organization and the timelines for major products for people to not do the bare minimum. When management pushes goal X, and pushes hard, everything else starts to decay, including security. People need enough time to do the things they know they should do, but don’t feel they have the time for. At least this is where I’ve seen a lot of issues arise.
The incompetence will continue as long as people can profit from it inconsequentially.
Our system now heavily reenforces lack of accountability to executives for what happens under their watch.
Investors don't lose money when these breaches happen.
This is why it won't change until those change.
Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
> Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.
... said every "security" pedlar ever.
> I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I think there's also a big part of the line that Jennifer Lawrence says in the satiric comedy "Don't look up":
"They are not even smart enough to be as evil as you're giving them credit for."
Just as the person who picks 123456 as a password doesn't see where the problem is, I think there are really quite a lot of people dumb enough all along the decision chain to think that firing the person who reported the problem did actually fix the problem.
They are really that dumb.
When you have bad practice and process it can erode the security discipline of everyone working within the system. Until they commit brazen crap like reusing simple passwords everywhere.
Im not in tech but still in corporate. Our store went through 6 GMs in 5 years. The problem is actually the corporate, not the new guy every 8 months who is being brought on to save the day. I think they're going to replace him again next year without addressing any of the issues on the ground.
Let's also include the system itself, that allowed the account to have a password that short and apparently didn't require 2FA.
"I dont understand why there is not massive reorganisations in systems when things go wrong"
Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.
Rome wasn’t built in a day, not did it fall in a day. In a capitalist society you can gauge overall direction and success of the society but how well the market and private enterprise is doing, and well not merely in context of maximising shareholder value but as a fundamental part of the social fabric.
I've tried reading your second sentence several times but I'm unable to parse it. What exactly are you trying to say?
1 reply →
> I dont understand why there is not massive reorganisations in systems
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
A major problem we have is that computer programming is not engineering as people like to say. An engineering discipline VALUES redundancy and is always designing for safety. Programming likes to think of itself as math, and deliberately choses less redundancy for the sake of convenience and speed. The classical example is how operating systems are written with languages that allow an index to be out of bounds. We now have systems that are glued together using bubble gum pretending to be safe, when they fail in the most horrible way when one of the links break.
[dead]
Yeah that is a pretty weird opinion. Who cares about if he gets fired. He should be charged with criminal negligence and face prison time. Everyone is responsible for their own actions and its always possible to quit.
The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)
Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...
Ha, I don't need to type 123456, it's stored in my navigator's password manager for convenience. Checkmate.
1 reply →
Next step in typical security team fashion: Prevent password managers from working, by obscuring the password field, using click-to-type passwords or similar shenanigans, because fuck you, that's why...
2 replies →
Until security forces the password manager session to expire after 1 hour, and forces the master password to be 16 char long with a combination of lower, upper, digit, punctuation, moon phase, astrological sign. And then they force you to change it every 2 months, and you can't reuse it until the next time Halley's comet is in the solar system.
You're missing the systemic problem the parent is talking about.
2 replies →
With two people in the company, there is not a lot of room for corporate games though.
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
> It's tussle between two counter-acting forces at play.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
I would love to hear about a world where security and productivity are not counter acting forces.
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
12 replies →
It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.
It is actually very hard to force password manager usage. You can encourage it, educate, but forcing it? How do you do that.
4 replies →
How do you force password manager usage?
4 replies →
Productivity and Aesthetics could also be said to be counter acting forces. Or really anything that requires contemplation. I think the problem is in how some people define "productive". Is it productive to have significant security problems which cause more work?
Touch one hardware key for every interaction then, not 123456, the hell?
Sorry, if your job title implies even a smidgen of security responsibility, you deserve to be fired for "123456" as your password. The person who was an administrator would fall under this label. Besides, "If productivity is not your goal, then security is not my goal." is what results in draconic security measures, because employees can't be trusted AT ALL. I really don't understand your comment.
Just because a task is hard it should never absolve anything. Guy could just have quit if he didn't want the responsibility.
The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"
The guys who are really into keyboard layouts would argue vehemently that 123456 is more ergonomic as it's an "inward roll" vs 6 consecutive presses of a key that aligns to the pinky
1 reply →
I'm not sure, I think it's a little more ergonomical to hit six different keys compared to hitting a single key precisely six times.
So it was actually two weaknesses:
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
I'd add missing MFA as weakness number three, at minimum. Problem number 4 is that the "password" was leaked, and the company (Pays ApS) didn't figure that out. Problem number 5 - the "password" belonged to a _former_ employee. How was that account not disabled? Problem number 6 - how can a company with two employees get access to this register in the first place? Don't they need to show compliance with some security standard that would be not possible to deliver for such a small company?
If you start thinking more about this, more and more problems pop up.
There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
Authentication in Denmark also uses cryptographic signatures etc.
The CPR alone is used for casual identification.
Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously
Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
1 reply →
[flagged]
That’s the same combination I have on my luggage!
The Spaceballs piece about it: https://www.youtube.com/watch?v=a6iW-8xPw3k
My first thought was "maybe security compliance training should include mandatory screening of Spaceballs"
Which does remind me of my game theory class in college... the professor would show movie scenes that demonstrated the game model we would be studying that week. It was quite effective, and certainly helped keep me engaged.
Way off topic, they're getting the band back together next year, https://www.imdb.com/title/tt32659463/.
Fingers crossed this late sequel parody somehow duplicates the original's charm. It would be embarrassing for Disney if it's better written/received than their own attempt with the source material.
I don’t normally upvote jokes on hn, but it’s saturday and I was about to say the same thing.
Props to you, good sir. You beat me by one hour.
I think a number of us immediately searched 'luggage'
Funnily enough, luggage calls back to those TSA locks.
the same price of a large pizza where I used to work as a delivery guy! Those pizzas were way expensive.
I bet you are not the only one!
It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
> Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
I think you mean that isn’t how they are meant to be used. If that was consistently the case in practice, however, no one would talk about this leak (at least not the CPR number part of it).
I doubt the CPR number alone will give you access to obtain credit and the like today, but you can absolutely go into a pharmacy and buy someone’s prescription medicine with just their CPR number, and you for sure can get access to a lot of data by calling various entities and providing your CPR number as proof of identity (but at least fewer now than used to be the case in the past).
If the CPR number was truly made public information, those cases would be much more obviously wrong. The fact that CPR numbers are de facto considered pseudo-secret makes things much worse.
1 reply →
Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
Why would you think active directory has anything to do with this? That seems like a super random conclusion.
What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.
I mostly agree with you, but it's worth considering that there are much more fundamental issues with absolutely abysmal passwords like "123456" . If my password is "ra1nbowC0okies776", and it shows up in another place, it's a pretty strong signal that I reused it, because it's unlikely to have been picked independently by someone else. If my password is "password", even if I never reuse it, that's still far worse than me reusing the password above.
2 replies →
They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
As a Dane I agree, but try constructing 13-19 in English. We just did it from 13-99.
However Im sad that now our national password is out :(
seks og halvtreds six plus two and a half times twenty
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
Or simply make people who choose insecure passwords criminally responsible for the fallout.
and make the people who didn't put any sort of limits on how many records can be downloaded before there has to be a check on what is going on or any of the other stupid security holes that were found, make them criminally responsible as well. At some point you can be sure you'll be imprisoning someone for making a typing mistake (accidentally commented out some code) or a logic mistake (I should have said IS NOT, but instead I said IS) or just being tired.
> According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company.
So the password could have been 32 alphanumerics with special characters and there still would have been a breach.
The password was not the problem here.
There are typically quite a few steps between initial access and domain domination, which I assume is what they ended up with, considering they have administrator account passwords. Well, unless you are using 123456 as the password for an admin account.
Yes and no.
The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
What would that accountability look like?
Not existing preferably.
2 replies →
Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
Personal pet peeve undefined acronyms, "CPR": Central Person Register. For those who didn't know, like me, and had to look it up.
I always find the use of acronyms a lack of education and manner. A way for the uneducated to try to sound sophisticated.
When I get an internal mail with multitude of acronyms I know that the people that wrote it does not care if anyone is going to read/understand it or not. It goes directly into the trash.
Something is fishy about this story though. The credentials used was allegedly leaked and purchased on the black market. But the it doesn’t matter how weak or strong the password is.
The information about the leaked password is from the guy claiming to be the hacker who anonymously talked to the media.
That's the kind of password an idiot would have on his luggage.
Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`. If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`. If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
There was a time when you would get a truly random password sent, every X months.
Sorry, I might be too young to remember those times. Can you tell me more, please? I'm genuinely curious.
Because from the sound of that, it feels that it would patch the `123456` problem, but opens up a new vulnerability - the password is known / being sent through / printed, so it can be leaked from that source.
1 reply →
How about making the passords longer but easier to memorize? (no digit / letter / special character requirement)
https://xkcd.com/936
That would work from the technical point of view, I do agree.
On the other hand, how would we make "lazy" people use those? And ensure that won't reuse the same password on some vibe coded forum that will store them in the plain text and get hacked in a few weeks =)
That's why I mentioned that mindset shift as the prerequisite.
Yes, S in Government stands for Security, C - for Competence (or caring about your data), and D - for system Design
If only they had insisted on a secure 8 character password!
There are some unconfirmed rumors going that the maximum password length for the API was 8 characters...
1Password#
Oops, can I delete my comment, it was a copy paste mistake!
> **********
> Oops, can I delete my comment, it was a copy paste mistake!
What do you mean? You can safely post your passwords on the internet.
2 replies →
hunter2#
It flows nicely on the numeric pad
At this stage all SSN, NI numbers, CPR etc should just be made public. Its assuming its some kind of secret is the problem. Its an ID not a password.
CPR is code for "registersamkøring". Register matching. The small wellfare nation needing to be able to see the populace as a sum of abilities and leanings and willingness to be swayed and pushed to support present and future economic needs of the whole.
.... what?
We really missed a trick by not normalising the term passphrase.
Beyond the weaknesses already mentioned, why did the system allow such weak passwords in the first place?
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.
Equivalent to social security information in the US I guess.
For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
It's unique, but it encodes your birthday and sex.
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
8 replies →
I'm not super familiar with SSN in US of A, but I think the Danish one is not has secret. Don't get me wrong, the leak is not good, but there is a limit to what you can do with it.
Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.
Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
Is this cultural?
When things like this happen in Asian countries, you always see a lot of people here comment about how “the culture” contributed to it.
So I’m wondering if there are any experts here who can explain if this is cultural too?
Well, if you change to many settings, it will break. So don’t change anything. So it doesn’t break.
That's the stupidest combination I ever heard in my life! The kind of thing an idiot would have on his luggage!
I guess I should change my password.
Not using 2FA on the admin account is the real crime.
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
If only they had used "12345678"!
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
Denmark comes from a long line of institutional trust: We say we do this, so we do it, so everyone else will naturally expect that.
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
The first major violation of obvious security practices was having a registry like that in the first place.
The second was giving out access to "companies and associations" that might have "legitimate needs".
THEN we get to morons using passwords like that.
not ideal
yeah it's rather unfortunate isn't it
Did they have MFA?
Nope.
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
Privatization
It was run by DXC Technology, the Danish branch of a US software house.
When doing a contract on such programs the Danish government must take the cheapest offer by rule
What could go wrong? /S
Always add a !
honestly you'd think by 2026 they would at least force a special char so the password becomes 123456!. im not even suprised anymore tbh, just disapointed.
Literally nothing will prevent this but software building codes and enforcement. That's why we have building codes. We let builders do whatever they wanted for decades and it ended in disaster, so we stopped letting safety be optional.
That's my password!!!
Thieves give it back now!
My password is 123qwe so it's safe for now.
Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.
Since then I think medical data science is mainly a waste of tax payer's money.
hey that's my password too!
Another fact - was only discovered because the invoice for using the lookup was big
If only there was an algorithm for password strength estimation > . <
Spaceballs CPR
Oh my fucking god
lol, it's a joke right ?
Completely real.
[dead]
[flagged]
[flagged]
[dead]
[flagged]
[dead]
[dead]
[flagged]
They forgot to write it on a post-it note attached to the monitor /s