Hackers Steal 8 Million Citizens' Records From Danish Government Database (techcrunch.com) 18
Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.
The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)
The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)
Public by Design (Score:2)
The only way to stop constant breaches is to disincentive stealing the data in the first place.
Perhaps someone will come up with a new privacy paradigm one day where all our data is public by design but you can't do anything malicious with it even if you have it.
You'd probably have to confirm all state-altering operations either in person or via some sort of an individual-bound, undisputable cryptographic signature but I'm sure it'd be worth the effort.
Small steps. Let's start with prohibiting sending scans
Re: (Score:2)
There are use cases you're not covering. Last month I needed a photo of my sister-in-law's ID card to prove that I'd correctly transcribed her address (bureaucrats don't always understand that other countries do things like addresses differently) when applying for a document to make it easier for her to visit. If she'd had to be there in person we'd have had a circular dependency.
Today I learned (Score:2)
Re: (Score:2)
And I learned they have a social security program with unique numbers the hackers can steal. Is theirs also funded by currently working individuals paying for seniors like in the US?
Re:Today I learned (Score:4, Interesting)
Many countries like Denmark, Sweden, Norway, and Finland, all have personal identification number, based on date of birth. It is fairly similar to the American Social Security Number but that does not require citizenship.
There are also countries that lack some form of personal identification number, such as Australia, New Zealand, and the United Kingdom. In Germany, it is illegal to have a single number that links all systems, which forces them to use different numbers for the same individual.
Re: (Score:2)
Maybe they can add a good 50.000 from Greenland but that's it, the rest are dead.
Presently I'm in Denmark and the Danes have a great trust in their government, now they suddenly realize their borders don't stop this kind of shit.
A few years ago the GF needed a type of sleeping pill which her job was not allowing, the doctor just booked it on the CPR number of her deceased mother...
Re: (Score:3)
That's a sign of a dysfunctional system, not a functional one.
Re: (Score:2)
Re: (Score:3)
I assume that Denmark's system is similar to our kennitala ID system. The big difference between a kennitala and a social security number is that a SSN is both an key and a password, while a kennitala is purely a key. Kennitölur are public. You can't "do anything" just by having someone's kennitala. Combining both a key and password into a single number is insane from a security perspective, IMHO.
Anyway, this headine would have been more fun if the words were rearranged:
Database Records: Citizens' H
Re: Today I learned (Score:2)
That's a win for Denmark (Score:2)
The hacking has increased their population by almost 2 million.
Re: (Score:2)
The rest are literal ghost records
Re: (Score:2)
You mean those records the hackers couldn't steal? Yeah, almost certainly.
Hackers? (Score:2)
Re: (Score:3)
What would separate the AI agents hacking from a person hacking and performing the same set of actions?
It's hacking all the same.
Naming things what they are (Score:3)
From TFS: "Some companies in Denmark have access to the CPR for verifying people's information with the government"
So the people's data was being used as an authentication token.
That is as bad a design as you could possibly come up with.
Aren't they public? (Score:3)