I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.
I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.
There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.
suslik 12 hours ago [-]
I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point.
All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.
The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.
shit_game 12 hours ago [-]
>I simply stopped worrying and began to love the bomb
This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?
I should not have to love the bomb because the bomb will kill me.
BobaFloutist 7 hours ago [-]
Yes, that's the direct subtext of that phrase.
lencastre 2 hours ago [-]
well isn’t the point of the movie that if you have a doomsday-(dead man switch)-device you should let everyone know?
I don’t get that comparison with data being available everywhere
EA-3167 3 hours ago [-]
Some of us are more practical than ideological, but we tend not to put as much energy into communicating our views as the ideological types. The result online is an often distorted sense of the universality and importance of ideology. You feel
That your data is part of your personhood? I feel that it’s more like tracks in the woods and scat.
kspacewalk2 6 hours ago [-]
Loss of privacy has no upsides. The bomb, on the other hand, saved many millions of lives over the last 80 years, so it works as a metaphor everyone shares, but the metaphor itself was always much more arguable with nukes. It's possible to actually rationally love the bomb, but what are the upsides for everything about me being exfiltrated at will?
fpoling 4 hours ago [-]
The upside is that you can know everything of almost any person as well. Whether that upside is beneficial for you is a different matter.
bonoboTP 2 hours ago [-]
Oh, but of course there is. He you ever seen arguments from the other side? It is to catch criminals of various sorts (money laundering, trafficking, smuggling goods and people, terrorism etc), to keep children safe etc etc.
Also,it can help you uncover and put behind bars your dangerous political enemies. That the tables may turn and the shoe may be on the other foot soon, that's too abstract of a thought to occur to most of them.
trimethylpurine 4 hours ago [-]
It tracks terrorists' efforts to acquire the bomb.
clickety_clack 5 hours ago [-]
It’s not the current use of the data that’s concerning, it’s its future use. Who’s to say that some facet of your life that is ordinary now will not one day paint you as the target of some future regime? It happened in Europe a few decades ago, and in many other countries around the world.
vladms 3 hours ago [-]
Yeah, like the way US citizens now are not targeted at all by ICE because their data is out there? Future evil government will not care about your data, they can just invent shit. The idea is to instill fear and uncertainty not "finding the correct people".
On the other hand, said data can be today use because various entities use extremely shitty authentication methods, like just insert your birthday and first name and voila you have a credit with our bank (not an actual example, just for illustration purposes).
thomassmith65 10 hours ago [-]
To be zen about one's privacy is easier for some people than others.
There are situations in many a person's life that if revealed to the public would have life-altering consequences.
Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data.
ruszki 12 hours ago [-]
Similarly. My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything. Even on my phone, I restricted whatever possible. Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade. I gave up right there. I suffered to avoid this, and it was pointless. I knew at that point already that probably all my PI is public information anyway, but I wanted to restrict whatever possible, and no, everybody sells my data anyway, and it seems that avoiding fingerprinting is impossible without turning off the internet completely, and ditching smart phones.
neobrain 11 hours ago [-]
> Google somehow got to know that I played Minecraft again after a decade. [...] I knew at that point already that probably all my PI is public information anyway
How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?
ruszki 48 minutes ago [-]
It wasn't a jump. At that time (about a year ago), I already knew that almost all of my traditional PI is leaked (phone numbers, ID numbers, etc), so I tried to prevent to leak my thoughts further. Basically my last non-public PI. And I tried that for years. And I'm quite sure after my trials, that it's impossible without giving up the internet. My traditional PI would leak even if I don't use the internet at all, since for example one time they leaked from my employer at that time. That's a lost cause even with that sacrifice.
close04 10 hours ago [-]
Your data is still out there, just compartmentalized so each outside party only has a bit. It turns out that's a losing strategy when each outside party decides to cooperate with every other and pool/share/sell that data uniquely attached to you.
conmod278 8 hours ago [-]
Even porn ads are linked with your normal browsing
yieldcrv 11 hours ago [-]
because it’s the same process of intermediaries accumulating, inferring and sharing data to each other
intermediaries that will be compromised
neobrain 11 hours ago [-]
> because it’s the same process of intermediaries accumulating, inferring and sharing data to each other
Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on.
Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.
pbhjpbhj 8 hours ago [-]
You saw the LG TV exposé? They do speech transcription on the TV and so have available for upload the logs for audio even when the TV is off.
Microsoft would definitely sell data on which IPs have Minecraft users, as would your DNS provider, cloudflare, or your ISP.
It could also be coincidence, though my experience is YouTube's suggestion algo is very tightly tracked to use data. (What I was fed on a guest account recently was a mix of fascist propaganda and AI nonsense masquerading as reportage.
autoexec 5 hours ago [-]
> Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.
Surveillance capitalism has been so successful because it's so opaque. It would take a whistleblower for you to know when and how the data companies have is used against you, or how they got that data in the first place. Their tactics can be used in ways that are highly targeted and transient, especially for data collection companies like Google.
Even for something as basic as search results what I see when I search may not be what you see, and what I today might not be what I see when I take the same actions tomorrow.
This can make identifying what our phones are doing almost impossible. A possible explanation for the "phones listen to everything we say, otherwise I wouldn't have been shown this ad" phenomenon might be that a phone picked up an audio beacon being broadcast while something played on a TV, which sparked a related conversation in the person carrying the phone. The conversation wasn't recorded, but topic being discussed was successfully logged anyway. There are countless other data points available that could be used in the same way. In cases like that it would clearly not be coincidence that Google showed an ad when it did, but the spying involved was even more involved and invasive than just listening to what was being said.
There's nothing to stop Google from having small clusters of phones listening to everything for certain periods of time under certain circumstances. They wouldn't have to send all that audio data back to their servers to be effective, just monitor for a sample of specific words/phrases (processed on device) and send back a flag when something is overheard. That kind of behavior would be extremely hard for researchers to catch.
The truth is that we're not allowed to know how and when we're being surveilled, but we are being watched all the time, and that data is collected to be sold or used against us at every opportunity. It doesn't do any good to tell the person imprisoned in the panopticon that he's being paranoid and that it's all coincidental. Even when it happens to be, feeling watched is the natural response.
vladms 3 hours ago [-]
I guess I was selected for the cohort "never show a useful ad to hide we're listening" even if I don't try to protect a lot (except an add blocker in a navigator).
Honestly I wish I would get more targeted ads for the stuff I look for, when I look. Instead, for some, it happens that after I buy them, I get repeated ads after couple of weeks or even months (like, invoice is on gmail, photos of the object on my phone, but nooo they want to trick me, so they still send me more ads of the same shit that I will not buy again in years).
Seriously, I think the tracking is as crappy as most software is. Sure, it might identify one/two keywords and throw ads at you, but it does it a dumb volume way that corporations work, not in a smart "we know everything about you way", that a true geek might implement.
autoexec 1 hours ago [-]
It's absolutely true that companies are pretty horrible at actually targeting ads.
Right now the amount of data about you companies have is just massive. Everywhere you are at every moment of the day, who you were with, what you talk about, everything you buy, and every website you visit, what your mood is, what your level of education is, how you react to stress, it's all too much information for companies to extract useful data out of right now. AI is going to help with that. Unfortunately, like everything else AI does, it will do it pretty badly and with lots of errors and hallucinations. The companies using AI won't care though as long it works enough times on enough people that they make money.
To make matters worse, ads are only a small part of what all that data is used for. It's the thing that's most visible to you though, so you can imagine that if your ads show that companies think the wrong things about you that HR departments and other companies you interact with offline probably do too.
astura 10 hours ago [-]
>My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything
Doesn't that just make your browser very unique?
slumberlust 4 hours ago [-]
Yes. Its a fingerprinting paradox that the more you do to obfuscate the better they can pick you out of the crowd.
emj 7 hours ago [-]
It is unique in a new way every page view.
autoexec 4 hours ago [-]
It's way better to do that than hope that you've managed to cover every possible means of fingerprinting. When trying to make your fingerprint as common as possible it only takes a single consistent data point to identify you, and new techniques pop up all the time. TOR browser is a good example of what not to do.
sillyfluke 11 hours ago [-]
>Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade
Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine.
ruszki 1 hours ago [-]
You are talking about a network which is used by 10-100-1000 thousands of people. Yet, they knew when I started to play Minecraft. With this logic, I should see Minecraft videos all the time, but I didn't, for over a decade.
dmurray 10 hours ago [-]
That's worse. My family or housemates can infer what activity I've been up to online by watching their YouTube recommendations?
astura 10 hours ago [-]
If your family or housemates wanted to know what you did online they could just flash DD-WRT onto the router and turn on logging.
hypfer 11 hours ago [-]
These swings can be avoided by not doing stuff so hard but instead more effectively.
For example, matrix sucks ass. It's terrible. Everything about it is a bad experience.
Of course you'd want to eventually stop using it and go back to the previous life.
But that is not the correct take-away.
The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.
Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.
kuon 9 hours ago [-]
We use xmpp in the family and the experience is good enough. I wish WhatsApp would support official federation and it would be perfect.
PatronBernard 8 hours ago [-]
This makes me think: how would someone like Mark Zuckerberg handle this for his own internet presence? Or does he sidestep this issue completely by having assistants for nearly everything? I can imagine he doesn't do much more than look at .ppts and fire off emails. Do data brokers have any information at all on this guy?
goosejuice 8 hours ago [-]
There's concierge services for this kind of data removal. At a certain level of wealth I assume there are teams working on this with lawyers 24/7.
alephnerd 6 hours ago [-]
Not just lawyers. You get a personal physical and cybersecurity team in most cases. Most largeish businesses also have a dedicated physical security team as well.
You as a normal individual simply cannot replicate the kinds of services that an Executive Protection services provide [0][1].
It would be funny, if there was a website anywhere, which accumulates data about all the tech giant C levels and shares it with the public, just like they share data about all of use behind closed doors to manipulate us and sell us shit, or sell our data to the next tier of data hungry businesses.
Probably wouldn't last long though, as they would be furious, that us lowly human beings are able to glean anything about them. The double standard of this is not obvious to them.
gentlerain 12 hours ago [-]
The next frontier is to maintain 'limited privacy'.
That's denying most culprits the opportunity to use the collected data against you.
Like always on VPN, turning off personalization, ad guards and using open source products where possible.
autoexec 2 hours ago [-]
> The next frontier is to maintain 'limited privacy'.
The real next frontier is to maintain one or more carefully curated personas with various companies to optimize how they treat you. Wear shabby clothes and fake beards when grocery shopping so that the cameras think you're poor. Security will be all over you, but the digital price tags will give you lower prices as long as you don't have your cell phone on you and they can't get a good face ID because then they won't be able to pull up your actual income level.
Create and maintain specially crafted social media accounts filled with fake hobbies and AI generated photos but never express an actual opinion on anything at all so that future employers can see you have a "presence" but they won't see anything that might disqualify you a job, like your political views.
Buy multiple high/low end devices and rent a closet or PO box in both rich and poor neighborhoods so that you can selectively hand out a mailing address that will make you appear either poor or well off.
Pay someone to take your cell phone out them on friday night so that you can appear more socially active otherwise you'll be flagged as anti-social which can impact employment, raise your health insurance rates, etc.
arethuza 11 hours ago [-]
It's a bit like physical security of your house - could someone break into my house, not easily but it's a house not a bank vault. Keeping our gate closed and having a large dog (who is actually very friendly) about the place probably keeps the vast majority of possible thieves away.
TeMPOraL 11 hours ago [-]
That's still a bit on the obsessive side. The reasonable position is the same as it always has been in the real world too:
- Don't volunteer your intimate details left and right;
- Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)
- Otherwise don't sweat it, because you can't actually control what others know about you, you never could
deltoidmaximus 5 hours ago [-]
The trouble with this is the baseline is getting to high. You've got age verification coming, google rolling out phone verification for websites, etc. Once that is rolled out, accepted and "easy" it will be used for everything important "for security" and then everything not important because hey, you were doing anyway?
The reasonable position will be slow marched into hell same as the rest of them, just a few steps behind.
az09mugen 10 hours ago [-]
I feel like this is the best compromise. Thanks for wording it.
_the_inflator 10 hours ago [-]
I agree.
And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.
I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.
Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.
Security is their business while security for the state is a cost factor.
Being at the mercy of some ignorant politician is not the best way to talk about data security.
Berlin, Denmark - those are the known one. And there are many more to come.
And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.
X got fined for a missing blue mark. Berlin? Denmark? Others?
A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.
So it is relatively easy to get data on them as well just by filtering out the other data.
In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.
And remember: being the one who is not using google when being around other guys who do - magic.
So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.
Pick your fate.
KPGv2 8 hours ago [-]
> I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.
How many state data breaches vs corporate data breaches? There are hundreds of state entities with my data (probably thousands), and yet private companies with my data have been hacked more times.
Grimeton 5 hours ago [-]
> and yet private companies with my data have been hacked more times.
...and yet private companies with my data have been hacked more times, so far.
Also they might have not been targeted....
thewizzardofnl 11 hours ago [-]
I think both are possible. To have a goal and to accept reality. I would not draw the conclusion that all privacy measures are meaningless. It is hard, but I think it is still worth working towards a goal of better privacy for citizens.
mdp2021 10 hours ago [-]
> wasted effort
That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not.
Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist.
adverbly 8 hours ago [-]
Two problems with that:
1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though.
2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen.
One thought here that I don't personally agree with, but might be important regardless:
Imagine a society without secrets or privacy at all for example.
I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world.
Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important?
robwwilliams 6 hours ago [-]
LoL. We are all dancing naked on the table and hoping our clothes and wallet or purse and some of our pride will be where we left them.
TeMPOraL 11 hours ago [-]
Evidence is pretty clear after decades of this: big data breaches are inconsequential for an average person.
They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.
At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.
anilakar 11 hours ago [-]
> big data breaches are inconsequential for an average person
A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't.
A single suicide due to a massive data breach is, unfortunately, completely inconsequential. Especially if we consider what social media does to teenagers without needing any data breaches.
diydsp 11 hours ago [-]
[dead]
swozey 8 hours ago [-]
All of the popular surveillance apps correlate your email address and phone numbers mostly, but if you used 1@gmail.com to sign up for 2@gmail.com google knows and marks it as your altnerate account, it could give them all your 30 rando gmails, you're then linked by phone activations through those emails to everything else, whatsapp, telegram, credit card purchase, etc. the biggest link in the chain is always the phone number though. They also have a big "Alternate Emails" button. Everything fans out from those.
I don't know how deep palantir can build profiles on someone, like digging into comment histories and extrapolating you are x y or z sort of stuff. I'm sure they've learned a lot about people via public irc logs and discord servers. But the only screenshots I've seen have been way more simple than that, basically a facebook UI that gives them buttons for all the apps with the phone # that has been identified as you the user, so it would be your list of social media apps accounts and they just click in and read messages. These screenshots have popped up in court cases recently.
We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Carry a dumb 2fa. I've always been on the "dont ask for my phone number to use your service" bandwagon but absolutely now.
And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore.
sillyfluke 11 hours ago [-]
>I just don't want to stop living - flying abroad, going to doctor
Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.
The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.
I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.
ionwake 12 hours ago [-]
I gave up when i realised Firefox had google analytics and noone even knew or cared. That was about 10 years ago now.
Kbelicius 12 hours ago [-]
Because it did not. Extensions page used them but nothing else.
ionwake 12 hours ago [-]
I love the bit where a programmer always proudly chimes in with this statement as if it means anything.
You dont get it bro, its not a good vibe.
And if I had bean in management I would have fired anyone involved with that decision.
Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.
Im just a guy who recognises patterns and im not even smart.
Kbelicius 11 hours ago [-]
> I love the bit where a programmer always proudly chimes in with this statement as if it means anything.
So you knew that fierfox never came with google analytics but you decided to claim it anyway...
sillyfluke 7 hours ago [-]
Not the parent, but I'm not sure I understand your reasoning.
You download firefox. In firefox, you go to settings->Extensions to download extensions and get exposed to google analytics, is that correct? If that's true, how is it not insidious that in order to download the thing that blocks google analytics, you have to get exposed to google analytics?
TeMPOraL 11 hours ago [-]
> Why is it so often HN that I point something obvious out
Because many "obvious" things are just plausibly sounding bullshit. For example:
> Rockstar having clearly failed management and a complete loss of control
That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.
If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.
bluebarbet 11 hours ago [-]
>the company starts falling apart.
This site will start falling apart if we don't keep things civil.
astura 10 hours ago [-]
>if I had bean in management I would have fired anyone involved with that decision.
Oh, I love the bit where a programmer always proudly chimes in with this statement as if it means anything.
wyre 11 hours ago [-]
What? So 10 years ago you though 1+1=Firefox is using Google Analytics, something you can't prove, but is "obvious" and "recognizing patterns"
I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious"
archon 9 hours ago [-]
> I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked
And then add on that fact that my doctor recently started using some kind of AI voice transcription app that listened to our entire conversation. Except that it hallucinated details I absolutely did not say, which are now in that doctor's records and I'm sure will be taken at face value in the future.
It's maddening.
98codes 6 hours ago [-]
It is definitely worth asking for a copy of those notes, verbatim, as-is from the automatic transcription, to check for errors while the session is fresh in your mind.
If your doctor is worth seeing at all, they will be glad for the corrections.
coryrc 5 hours ago [-]
I have another solution. I look normal online when filling out information. I use Facebook, whatever.
But whenever possible, I lie. Different name, birthdate, every question about "favorite pet"? A lie. "They" have tons of data on me, but more and more is wrong. Let it leak.
I use my password manager to maintain unique answers to all of the useless verification questions about pets, movies, teachers, etc. Only way to scale it.
docjay 3 hours ago [-]
I just use the noun in the question. The name of my pet is pet, my favorite movie is movie, and I attended High School. Add your own standard prefix if you want it impossible to guess. Nobody will know you attended “BLARG High School.”
strideashort 12 hours ago [-]
I recently needed a lawyer on something that involved lots of highly sensitive PI.
Sending my file over to lawyers in a semi-safe way has proved impossible.
And in any case, i received an answer with lots of PI over a plain email…
Absolutely maddening
vaylian 1 hours ago [-]
Was Signal an option you have considered? It's designed to be secure even if the user is non-technical.
master-lincoln 12 hours ago [-]
Why? I would assume encrypting and sending the key via a different channel would be sufficient. Or are lawyers still not technically apt to do so?
CrimsonRain 12 hours ago [-]
Then lawyer replies in plain email discussing those very things...
data-ottawa 11 hours ago [-]
The lawyers I’ve used have always asked and used encrypted email. I don’t know if that’s regional, but it was taken very seriously here.
SoftTalker 8 hours ago [-]
Probably greatly depends how old the lawyer is and how big the law firm is.
If it's one older guy, good luck. You're probably better off doing everything by FAX honestly.
strideashort 6 hours ago [-]
“We can’t open this”
It was .7z with strong pwd. The normal zip is supposedly too weak according to llms
Telaneo 11 hours ago [-]
If normal people aren't, I wouldn't expect lawyers to be either. If there's no happy path to encrypted communication, then it will not happen.
chronogram 9 hours ago [-]
It's part of their job. If they can't do that right they certainly can't do the rest of their job right. Just like it's OK to get queazy if your doctor is functionally illiterate or your lifeguard can't swim. Also things that match average people in some areas.
talon8635 1 hours ago [-]
I was at that point in 2015, at which point my social was already leaked in a major breach, and after which it was leaked two more times in other breaches.
msdz 11 hours ago [-]
> There should be some consequences for companies […] retaining drivers licence photos after test driving a car, they just don't need the data anymore.
I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much
worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.
nswizzle31 9 hours ago [-]
What punishment does the country of Denmark get here, if you had to guess?
senordevnyc 9 hours ago [-]
Pretty ironic to be extolling the virtues of the EU's privacy approach on this story in particular...
faidit 7 hours ago [-]
We need HIPAA for businesses. We tried letting them regulate themselves and it didn't work. Businesses need to be forced to compete on the quality of their products/services and not rewarded for reselling customer data to spammers and criminals
amelius 13 hours ago [-]
I mean why does every hotel need to make a copy of my passport?
ElDji 12 hours ago [-]
It is a basic police requirements on most countries. Hotels must collect visitor id's and keep it for several weeks.
toyg 12 hours ago [-]
Yeah, it's old-school people control. This said, these days it could be done electronically, without the hotel storing physical information: at check-in, you put your passport in goverment-issued, (hopefully) tamper-proof machines, the hotel confirms length of stay, police server gets the info and that's it; early checkouts, the hotel must notify via some web portal. It would be relatively easy to implement.
But nobody really cares enough to spend money modernising this sort of system.
rithdmc 12 hours ago [-]
I'm sure they're done electronically in some places: Your passport details are appended to the shared Google Spreadsheet...
I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
toyg 12 hours ago [-]
I know, and that's really the thing: nobody cares, not the government and certainly not the hotels.
rithdmc 12 hours ago [-]
I don't think my at-the-time employer cared much, either :)
12 hours ago [-]
GJim 12 hours ago [-]
> This said, these days it could be done electronically
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
toyg 12 hours ago [-]
The whole point is that the hotel would not even get a copy, the machine would just send hashes around and the hotel would only get an anonymous transaction ID to store. It would probably be even more secure than what you have today at the airport.
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
preg_match 4 hours ago [-]
I’m sure this can be done, but somehow I doubt it.
When I toured apartments they would often take a photocopy of my ID. Okay, overkill. But realistically I have no idea where that photocopy is stored.
Probably in a OneDrive somewhere to this day.
GJim 11 hours ago [-]
Good lord!
Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet!
tlb 11 hours ago [-]
When paper data is breached, the crooks don't steal the paper and put in their own locked file cabinet. They take pictures of the documents and sell the data on the dark web. So the end result is the same.
mainecoder 10 hours ago [-]
the will need to take a picture everytime they are lazy but stealing all the people who ever stayed at that hotel is a simple copy past taking less than 10 minutes
sib 4 hours ago [-]
Yeah, honestly I'd prefer the remote, simple hotel makes a physical photocopy which at least has a chance of being thrown out after a couple of weeks vs the government of "random country" gets a digital copy which will never, ever, ever be deleted.
astura 10 hours ago [-]
Ironically, that would enable tracking much more than the normal case, which is a hotel stores the scans on a hard drive on the closet that nobody every looks at unless they get a subpoena.
toyg 9 hours ago [-]
That's not what happens in Italy, at least - the documents are scanned and uploaded to a police portal in less than 24h. I expect that's roughly the same elsewhere. (I honestly did not know until today, I just knew the police would come every night to collect copies - good to see some modernization...)
carlosjobim 12 hours ago [-]
All these giant data leaks are coming from the government's "tamper proof" systems!
toyg 12 hours ago [-]
I know, and it's really the trade-off whenever this sort of system is centralized: you can better secure the leafs, but the central repository becomes an even juicier target.
This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.
severino 8 hours ago [-]
The requirement is that they provide some of the information contained in the visitor's id to a police web application. At least, that's how it works here in Spain. But it doesn't mean the hotel needs to take a picture of your id, nor scan it. They just need to transcribe the required information. Yet some would not let you check-in if you refuse to let them scan your id or take pictures of it, that you never know how and for how long will be kept. Of course, you usually don't want to argue after you arrive at some place to make the check-in when the alternative is to sleep on the street.
ninalanyon 9 hours ago [-]
Not in my, admittedly limited, experience. I've stayed in hotels in at least a dozen countries and under half of them wanted my passport. In the UK it's usually enough to just say my name to the receptionist, they confirm how long I'm staying, ask me to sign a form and tell them my car registration number and then they hand me the key. Quite often there isn't even a form to sign, just a terminal to enter my car registration number to avoid parking fees.
I was asked for my passport in a Premier Inn this summer because they thought I was a foreigner but when I pointed out that I was a UK citizen they dropped the requirement.
In Europe it was mostly Italy and Poland that wanted to see my passport.
edelbitter 9 hours ago [-]
I politely refused the data collection a couple times just to confirm my understanding, expecting to trigger some discussion in case I was wrong. But hotel staff was perfectly aware of the applicable local rules and just skipped ahead to explaining the most convenient route to my room. Apparently the general assumption among visitors is that they would not ask if they were not required to collect it.
Scaled 12 hours ago [-]
I just tell them they can look at it but not copy it and that's satisfied them, for now. Sometimes had to get a manager in, but never had them deny me fully. I'm sure sooner or later I'll run into a stubborn one and have to scramble for a day-of replacement hotel, and that just adds to my list of reasons to avoid travel.
mk_stjames 3 hours ago [-]
Travel to Spain and they will not give you a room key until they can take your passport and make a scan of it, often times on an old flatbed print/scanner combo, that they print out a copy on paper to staple to their copy of the invoice and put god knows where. It's been like that for about 6-8 years. No more showing up and paying cash for a hotel room.
You can try to say no, but I don't think you can anymore. I go through this a dozen times a year on my travels there.
This is Spain.
Razengan 12 hours ago [-]
And why are politicians immune to all of this shit??
Why can’t WE spy on them 24/7?
lynx97 12 hours ago [-]
If democracy really worked, and your desire to spy on politicians is shared by enough people, supposedly, you should be able to create your own party which has that explicit goal. Maybe find a few other goals, or you will end up like the pirates :-)
I am writing this because I don't think democracy works as advertised.
sparkling 12 hours ago [-]
Because you are a slave, Neo.
NooneAtAll3 2 hours ago [-]
> or retaining drivers licence photos after test driving a car,
mind that there was a breach recently where all the data was being leaked *the moment it was collected*
so simply controlling retention is not enough. The very fact of data being taken is already a vulnerable part
tokioyoyo 12 hours ago [-]
I said it before as well, but it’s because nothing “publicly really bad” happened despite the leaks and stolen information over the past decades. After Equifax breach, everyone got tired, because company survived, and whatever identity theft happens from time to time gets swept under the rug. It didn’t impact most people’s lives, despite leaking half of the US’s SSNs and etc. Then fatigue kicked in, and with subsequent leaks everything just mellowed down, so nobody cares.
I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.
TacticalCoder 11 hours ago [-]
In France the french IRS leaked infos about the wealth of its citizens and evil thieves cross-checked it with leaks of people who ordered hardware wallet for cryptocurrencies and families are getting kidnapped and tortured. In a recent case three family members have been beaten over two days so that... 40 000 EUR could be stolen.
That's the world we live in.
"Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).
As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.
Shame on the french government.
Two sides of the same coin.
Frieren 10 hours ago [-]
> As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.
The cryptocurrency ecosystem is used to not only avoid taxation but to enable criminal activity. How many people are being held hostage and the ransom will be payed thanks to cryptocurrencies?
I do not like the cryptocurrency ecosystem either. And I totally agree that it should be abolished. It is just a way to finance crime and terrorism.
crabbone 3 hours ago [-]
Last month I had to lodge a complaint with Lycamobile because they arbitrary cancelled my plan, essentially, pocketing some 50 Euro. Trying to follow their very elaborate support extensions maze, I ended up in some Indian customer support center that proved to be completely useless when it comes to solving issues caused by the service provider itself.
However, next week, I started getting calls from other Lycamobile numbers, where it sounded like the same Indian guy, but now he presented himself as a police officer who wanted to arrest my bank account :)
The moral of the story: if you have a phone number, it's been already sold to some shady call center in South-East Asia and it's just a matter of time before they will try to scam you or use your phone for some nefarious purpose. I don't think Lycamobile is unique in how bad their system is and how much they want to extract every last penny from you buy outsourcing every service to foreign companies with zero responsibility and questionable work ethics.
mdp2021 12 hours ago [-]
> where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked
Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).
astura 10 hours ago [-]
>previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods
Excuse me?
If you weren't paying with cash whoever paid for the prescription (govt, insurance) has a record of it. The pharmacy that filled the prescription has a record of it as well as the doctor who wrote it.
mdp2021 9 hours ago [-]
> cash
How can you presume we do not pay with cash?! How can you remotely suppose one sane mind would not use cash for all sensitive private transactions - books, medicines, preferential (profiling) products etc.?
We use cash in general because nobody in Dignity would accept their own daily matters to be recorded and given to multiple untrusted parties¹, not to mention potentially retrievable by even more untrusted parties - of course the matter is much more evident for all transactions over confidential items!
(¹EU here: 12 public-hybrid-private DBs as per the PSD2 legislation.)
bookofjoe 9 hours ago [-]
I haven't used physical cash in over two years. (I'm in the U.S.) I'm don't think I'm an outlier.
mdp2021 8 hours ago [-]
We know you are not an outlier, it is a grave issue that you are not an outlier.
Are the elements in your set aware of what they are doing?
bookofjoe 8 hours ago [-]
I/we know and we don't care.
mdp2021 7 hours ago [-]
> we don't care
And why did you post that replying to mine, what is the message? We knew that you in the cashless are many.
Is it a cry for help - as you know what you are doing but cannot care? Ok: reread the "Book of Joe", which obviously you have heard of, and take your side. Both of them, really: one for morals, one at least for the mentions of the beast requiring its mark for transactions.
NooneAtAll3 2 hours ago [-]
then why are you commenting here if you don't care?
chrisjj 10 hours ago [-]
> I'm baffled how it's not secure.
Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer.
Tangurena2 9 hours ago [-]
Too much is stored in computers. In the EU, you own the data about yourself. In the US, whoever owns the computer owns all the data on that computer - you own nothing and you will love it. We need to make PII radioactive and fine everyone who had that data stored on their computer when it leaked.
yeahforsureman 2 hours ago [-]
No, in the EU, you don't "own" the data about yourself in any meaningful sense. For example, under the GDPR, consent is just one of several potentially available legal bases for processing personal data — in fact, it's the one basis you usually want to avoid as a business if at all possible — which also means that for most uses of your data, you do not have any unqualified right to demand a controller cease processing or remove your personal data.
c-fe 10 hours ago [-]
> they just don't need the data anymore.
Thats the wording of GDPR.. that you should delete data after you dont need it anymore for the original purpose..
Unfortunately, it seems noone is enforcing it enough.
KPGv2 8 hours ago [-]
> my passport may be used to aqquire a loan by cybercriminals
In the US, you can freeze your credit, making this impossible (even for yourself).
Hamuko 12 hours ago [-]
I’m never going to a therapist after one company leaked all of the patient data / therapy notes for 33k patients.
lux44 12 hours ago [-]
It looks like you punish yourself unnecessarily, for things that are out of your control.
Hamuko 10 hours ago [-]
Whether or not that data exists to be leaked is entirely within my control though.
wyre 11 hours ago [-]
Thanks, I got a good laugh out of this comment, but therapy is just a tool to mostly learn how to deal with things that are outside of your control.
childintime 11 hours ago [-]
A therapist reads like the-rapist, in his case, and in many others. It's bandaid on a failing system, a failing society, and instead of fixing the system the victim has to pay the-rapist. Misaligned incentives all over again. To correct this therapy should be free, because the need for it shouldn't exist. Let the tech billionaires pay for it: if they cause the damage, they have to pay the bill. That'll teach them how to prioritize user satisfaction.
> things that are out of your control
That's because of corruption. A system that doesn't want to change because some tits can't be let go of. A well working system would render control back to you.
gausswho 8 hours ago [-]
2028 headline: Meta The-Rapy daily users exceed Facebook
ratg13 12 hours ago [-]
This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate.
In this case, the EU does have consequences for data breaches where proper protocols are not followed.
Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.
In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.
In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.
In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.
Zealotux 11 hours ago [-]
[dead]
heresie-dabord 11 hours ago [-]
> I don't think [...] these companies [...] can be trusted with my data
Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.
hk__2 11 hours ago [-]
There’s nothing lucrative in abusing privacy, and yes the government is busy but it has nothing to do with a "corporate agenda", any government or any country with more than a few millions of people is busy, agenda or not.
gnull 12 hours ago [-]
In Sweden, to avoid this kind of malicious leaks, we leak the residents' data officially. https://hitta.se lets you look up personal numbers, names, addresses, birthdays and sometimes phone numbers of any resident. The residents are not asked for consent, the data goes there automatically (some of my friends had success with having it removed from hitta, but it comes back once you change residence address).
It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.
What's the big deal, Danes? What do you have to hide?
(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)
alkonaut 9 hours ago [-]
These services were just the natural extension of the phonebook. At the exact same time as the phonebooks stopped being circulated, these services popped up online.
And since everyone's name, address and phone number was in the phone book (At least for their city) people didn't find it weird when it popped up online. Sure, to do the same thing for the whole country you'd need dozens of phonebooks for different areas, but it was just the same information.
Which makes me wonder: weren't there phonebooks in US cities and in other countries before? Were they incomplete/opt-in?
The key thing about the Swedish phonebooks were that they were opt-out, so people were basically all in the phone book. So even before the internet, it was just very natural that your name, address and phone number was public. "Getting someone's number" as in moves and TV wasn't a thing. You could just call anyone if you knew their name.
sib 4 hours ago [-]
Yes, we had phone books. And it was useful. But they didn't generally include personal information such as birthdates, salary, etc. And it was easy to opt out. Additionally there were not a bunch of online services with financial impacts that used phone numbers are primary keys.
And, importantly, they were physical in a time when it was hard to collect and collate the data in all of them. In 1990, there were about 5,000 distinct "white pages" phone books in the US. And OCR was pretty crappy.
Also, in all the places that I lived, mobile numbers didn't end up in the phone books, only residential landlines did. I don't know if that was universal.
christophilus 57 minutes ago [-]
Right. It was harder to spoof my bank (since banking was an in-person affair), and steal all my money back then. Now, this information is available to anyone in the world, and there aren’t good protections. I don’t know the solution, but the world is a different place than it was in the days of white-pages.
jvvw 7 hours ago [-]
In the UK, you could always choose to go 'ex-directory'. More and more people did over time I think and the personal part of the phone directory got slimmer and slimmer, basically just leaving the business part.
aranelsurion 12 hours ago [-]
Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?
Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.
Alpha3031 12 hours ago [-]
I've been told back in the day it was quite normal get a physical, dead-tree book with similar information sent out to you every year, until people decided that was a waste of paper.
consp 11 hours ago [-]
It used to be illegal here to reverse look up a name matching to a phone number, since it was "owned" by the state telephone company and they didn't want that happening. But you were allowed to reverse look up the address of a number and then look up the person and match it to the number. So that magic happened under the hood. The trick was getting the residential information but since that wasn't a problem in the '90s I'm sure it is even less of an issue now.
SoftTalker 7 hours ago [-]
When I was a kid there were reverse phone books that were indexed by number. Not common, and I think they were pretty expensive, but the IIRC the local public library had them.
stefanfisk 3 hours ago [-]
When I was a kid in Sweden that was just part of the local phone book.
MisterMunchkin 4 hours ago [-]
But that was optional, you weren’t forced to reveal your location to the person who raped you
s3p 4 hours ago [-]
Who was talking about rape?
lifeisloving 11 hours ago [-]
When I lived Norway, my gf at the time would look up the license plates of cars that annoyed her and could see how much debt they had on the car to make fun of them. Scandinavians are oddly very open with this type of personal info.
piva00 10 hours ago [-]
In Sweden I have looked up someone's phone number through the info I got from the license plate to notify the owner of a BMW M5 that their 20 years old son was often speeding down the 30km/h street close by my house where kids would cross coming from the metro or a bus stop nearby.
The owner just thanked me, and said was going to have a chat with the driver. Never saw that car speeding nearby again.
ninalanyon 9 hours ago [-]
When you do this the owner of the car is notified. And there is an audit trail because you do it by sending a text to a premium number.
The debt information is there so that when the owner sells the car the buyer can check to see if they actually really do own it outright.
embedding-shape 10 hours ago [-]
I don't even see salary or what your debt is as "personal information" (am Swede not in Sweden), personal information is stuff that no one else would need to know. What people earn affects not just people around you and others in the workplace but also society at large, makes a ton of sense for that stuff to be public.
Especially great that you can see what employees at competitors earn, what your peers at your workplace earn and what your boss earns. Become a hell of lot easier to ensure you're not exploited. Helps that Sweden has a really strong union-culture as well.
melvinroest 9 hours ago [-]
> I don't even see salary or what your debt is as "personal information" (am Swede not in Sweden), personal information is stuff that no one else would need to know. What people earn affects not just people around you and others in the workplace but also society at large, makes a ton of sense for that stuff to be public.
In a high trust culture I get this. But what about if you're in a low trust culture with quite some "not so orderly behavior" (if you will).
ninalanyon 9 hours ago [-]
Perhaps one of the steps to a high trust culture is actually trusting people.
MentalM 5 hours ago [-]
> In a high trust culture I get this.
Wait, aren't Sweden like literally the world leader by rapes count?
stefanfisk 3 hours ago [-]
Our definition of rape is VERY broad by international standards, so comparisons are complicated.
etiennebausson 5 hours ago [-]
Declared or actual?
There is a huge difference in most countries.
Sweden may well be one of the few countries where being raped isn't shameful/your fault for dressing too lightly/punishable by death.
rwyinuse 2 hours ago [-]
Yep, and this applies to several other types of crimes too. Countries with the very lowest rate of reported rape, domestic violence and so on tend to be horrible for women, because the reason for low rate is that they are too afraid to report the crimes.
AuthAuth 3 hours ago [-]
your brain is cooked if you think sweden is leading the world in rape count
lifeisloving 37 minutes ago [-]
He's also trying to infer something about migrants here, he's just not willing to say it outright.
Sounds like someone who needs to lay off the X/twitter feed.
embedding-shape 8 hours ago [-]
I think it's the opposite, the mismatch of information availability between employer and employee makes that a low trust culture, which is addressed by making that information public instead. If it was a high trust culture, employees would trust their employer pay them fairly, but they don't, hence this information deserves to be public.
darknavi 7 hours ago [-]
I learned this (public info) about Sweden a few years ago and as an American it really pissed me off.
In the US you can get the exact same info and probably more by simply paying a private corporation/middle man (background check services).
It seems like a huge trend in many sectors. We have the same setup as other countries, but shittier for consumers because there are lifeless leaches as middle men to make a quick buck.
f646993e074382f 12 hours ago [-]
Yes, it is possible to have a protected identity.
fwn 11 hours ago [-]
It seems that you can have a protected address in Denmark as well. Apparently, the protected address is even a field in the current leak.
spragl 10 hours ago [-]
According to their announcement, the names and addresses of people with protected address, were not leaked.
mrweasel 11 hours ago [-]
I worked on systems that has this, it would be funny if it wasn't putting people at risk. You can see the address, and then as you say there is a field that indicated that this is a protected address, so don't leak it,... unlike the others with you're then completely fine to leak?
p-e-w 9 hours ago [-]
Ah, so the “open” system is actually a two-tier system where everyone’s information is equally open except for those who are more equal than the rest.
embedding-shape 11 hours ago [-]
> Are there no murderers, crazy ex-boy/girlfriends, targeted harrassment and spam calls in Sweden?
Of course, contrary to popular belief, Sweden is not a perfect country without violence and shit people!
It seems to be somewhat respected overall though, but I'm sure it'll eventually disappear. For the people who are stalked and what not, it's relatively easy to apply and get "protected identity" if you're affected by those things, and then eventually all those 3rd party websites remove the stale data.
Personally I solved this problem for myself by moving away from the country.
melvinroest 9 hours ago [-]
> Personally I solved this problem for myself by moving away from the country.
Quite drastic to move away from a country for just this. Did you only do it for just this? Or was this simply one of the factors why you moved away?
tuwtuwtuwtuw 12 hours ago [-]
There are. You can get a protected identity if you have that issue.
The current system has been in place around 1770. There's some pushback against it the last few years.
talon8635 1 hours ago [-]
Talk about creating our own problems lol. We’ve made a total mess of things. No onset normal people hate us technologists.
mrweasel 12 hours ago [-]
I have been advocating for Denmark to do the same for 15+ years. The fact that your social security number can be used for anything on it's own is a disaster. Mostly it can't anymore, because you have to do electronic signing with MitID, but it's still considered secret. If you own a home in Denmark, address information is already public, but a little hard to lookup.
The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.
sigmoid10 11 hours ago [-]
>Because the demo was done with politicians
I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.
encom 7 hours ago [-]
>I feel like this should be the default.
The autorities do not, and the guy who "leaked" the CPR number of Mette Frederiksen was thrown in jail.
On an unrelated note, I recently read about voyage of the Mayflower across the Atlantic. It's a captivating piece of history.
groomlake 11 hours ago [-]
The review conducted shows that the unauthorized access does not include the names and addresses of individuals who have chosen to register with name and address protection.
From the source
sajithdilshan 12 hours ago [-]
I was actually surprised when I heard about this for the first time. Also I've heard that even the salaries of people are publically available. That's really cool.
Gravityloss 12 hours ago [-]
This probably improves economic efficiency a lot. Want to build something and remember meeting a relevant expert 3 years ago at a party? Easy to find that person and start doing business...
dist-epoch 12 hours ago [-]
Yes, it's great for businesses, you can search for the cheapest labor, and helps you avoid paying someone much more than they previously earned.
SoftTalker 7 hours ago [-]
That's more of an American thing, wages in places like Denmark are much more set by the job classification and maybe seniority, not individually based on one's background and what one previously earned.
sajithdilshan 5 hours ago [-]
Really? What about the experience or specific domain knowledge one brings without seniority? Isn’t their specialised knowledge or talent not rewarded?
eutropia 2 hours ago [-]
the real reward is the equality of dignity we earned along the way.
it's a real cost, and a real benefit. I guess values vary on which is more important.
sajithdilshan 1 hours ago [-]
That's crazy, so in Denmark people work for dignity and not money? Like do you pay for groceries or rent or any other expense with dignity?
embedding-shape 11 hours ago [-]
And private individuals as well, as you can see what your colleagues earn without having to ask anyone, and can even see what your boss earns, or what the competitor to your current workplace earns! I have to say salary negotiations are a lot more straightforward (and fun) in Sweden as an employee than other places I've worked.
Overall the benefits for employees seems way broader than the benefits for the companies.
jandrewrogers 7 hours ago [-]
FWIW, wage transparency has been studied quite a bit in economics literature. The short version is that while it does reduce wage variance i.e. wide differences in pay for the same job, it also consistently reduces average wages.
On a purely economic basis, wage transparency primarily benefits employers because it reduces how much they need to pay based on actual performance in practice.
embedding-shape 7 hours ago [-]
> On a purely economic basis, wage transparency primarily benefits employers because it reduces how much they need to pay based on actual performance in practice.
Why would transparency reduce how much employers have to pay? Usually capitalists would make the opposite claim, by keeping salaries opaque, it's much easier for employers to underpay people, but you seemingly are making the opposite claim.
If I can see how much my employer pay others, doesn't that help me ensure I too get fairly compensated from the employer? How could the employer leverage this situation to pay me less than I already know I'm worth?
jandrewrogers 4 hours ago [-]
It follows from the wages being allocated from a relatively fixed pool of available money. What people think they are worth can be significantly different than what they are empirically worth, both high and low. There is some price discovery that needs to happen at the individual level.
When wages are opaque, an employee only needs to justify their worth to the employer. Employers pay for value net of wages, so they are often happy to pay someone much more if the individual value generated justifies it. When wages are transparent, an employee needs to justify their worth to everyone else because a higher wage is tacitly reducing their wage. This creates social pressure separate from the economic argument.
Other employees are incentivized to maximize their own wages regardless if it maximizes value for the employer. And there are many more average employees than high performers. Employers can leverage this social pressure to cram down the wages of anyone who wants to be paid above average because they no longer have to defend a lower wage on a purely economic basis. Empirically, this is what happens.
Anecdotally, I've seen this play out countless times at companies.
MentalM 5 hours ago [-]
> If I can see how much my employer pay others
Then your salary will be decided by lowest common denominator. Employer does not leverage this situation, employer reacts to the incentives this situation creating.
embedding-shape 4 hours ago [-]
> Then your salary will be decided by lowest common denominator.
Why would it? That's not what happens in practice, and you have raw data to point at, with things like "Person A is half a fast as me, and earns X, that's why I deserve X+N", not sure why you think there would be another outcome here, and it's clear you've never experienced this sort of environment yourself.
Boltgolt 12 hours ago [-]
You do have to request them and the person you requested them for will know you did so
kassner 11 hours ago [-]
It will be registered if you ask Skatteverket directly, but if you go via a company (i.e.: Eniro), the subject does not get to know it.
ahoka 10 hours ago [-]
I think this is the worst part about it. Some company making a profit selling my data should be illegal.
embedding-shape 8 hours ago [-]
> my data
You haven't sufficiently manage to enter the mindset of a Swede. Your salary information isn't "your data" in the first place, it's public information. The company is selling public information if you have this mindset, does it still make sense to make it illegal then?
I think what you want to argue for, is for salary information to not be public data anymore. Selling people's private data without authorization (or even handling it incorrectly) is already illegal and actively punished today when it happens, via the long and slow arm of the law.
Shiggy_ 5 hours ago [-]
Any data that personally identifies information about an individual is personal data.
That is not an opinion. That is a fact. It's not public information, and anyone arguing that is categorically, provably, wrong.
The entire country of Sweden can collectively come together and decide that 1+1=3, and I would give that about as much thought as these semantic games around private and personal data.
pelorat 4 hours ago [-]
It is considered personal data by the likes of the EU, the issue however a pesky little thing called the Swedish Constitution, specifically chapter 2 of the "Freedom of the Press Act" which basically states, in very simple terms:
1. Everyone(1) shall be entitled to have free access to official documents.
2. Official documents are all(2) documents held and produced by the authorities.
(1)=Everyone includes everyone in the world, you do not have to live in Sweden or be a citizen and you do not have to identify yourself.
In short, most government databases are databases of "official documents", including the citizenship registry maintained by the tax authorities.
Downside: All the mundane information about you is public property; address, birthdate, tax records, school grades, drivers license, passport photograph, martial status, court cases and pretty much everything else you can't think of.
Upside: Applies to all politicians as well.
sajithdilshan 3 hours ago [-]
I didn’t know that is enshrined in the Swedish constitution. I’m staring to like Sweden even more
Shiggy_ 2 hours ago [-]
Disturbing. Serious lack of respect for the rights of the citizenry of the country to privacy.
embedding-shape 4 hours ago [-]
Yeah, you can either assume your worldview is the only one that exists, then seemingly not understand why certain decisions are made or how things work elsewhere, and everything looks stupid and doesn't make sense to you. Or you can try to understand things from other perspectives, and maybe actually understand the reasoning behind it and what it means.
What is and isn't personal data is subjective, regardless what "truth" you believe you're sitting on. I won't claim you're right/wrong as there is no such concept for subjective things, I suggest if you want to understand instead of wave your hands around or whatever you're doing, you'd try to see things from another's perspective and forgo dogmas.
Shiggy_ 3 hours ago [-]
> What is and isn't personal data is subjective, regardless what "truth" you believe you're sitting on
Ontological games are just that - games. Personal and public data is not an opinion, and it's not subjective.
I legitimately think that it's harder to have a coherent definition of a chair than to define personally-identifying vs anonymous data, and pretending otherwise is stupid.
estetlinus 9 hours ago [-]
Yeah, Offentlighetsprincipen is quite Swedish, isn’t it? I like it. Not sure it was made for the 21st century though.
mingusrude 12 hours ago [-]
Personal numbers are not available from hitta.se.
Hikikomori 11 hours ago [-]
Not in full as it doesn't have the last 4 partly random digits, though personal numbers aren't that useful even if it was the full one.
boramdd 8 hours ago [-]
If you login with an account (which you can create for free), you can also see the personnumber. See someone elses salary without them knowing about it for 39/49SEK, which is around 3-4$
Hikikomori 7 hours ago [-]
Not on hitta.se though. Other websites like ratsit have this, but you can also call skatteverket for free.
ntoskrnl_exe 13 hours ago [-]
Just that easily all the private conversations of everybody in the EU can leak if Denmark succeeds at outlawing E2E encryption with its Chat Control proposal.
Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.
Proof 11 hours ago [-]
Unfortunately, for the people who strongly believe that Chat Control is the way, they will use these types of events as further evidence as to why spying on everyone is the best deterrent.
raxxorraxor 12 hours ago [-]
I heavily doubt these people are open to self-criticism in any way. They have their program and are set to implement it.
ninalanyon 9 hours ago [-]
> I hope this will be eye opening to the responsible people.
Don't hold your breath.
bradhe 3 minutes ago [-]
That's, like, the whole country...
clan 13 hours ago [-]
For those not getting the scope of this. The following has been compromised for all living danish citizens and foreign nationals which have had recidence. And quite a few dead ones as well.
- Social security number
- Age
- Sex
- Family relations
- Physical address
- Protected addresses
- Sex change
This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.
kasperni 12 hours ago [-]
Nobody knows exactly what was accessed. What you have listed is what the register contains, not what was accessed. People with "Protected addresses" have specifically not been compromised.
clan 9 hours ago [-]
That is not what I have heard.
AFAIK those with protected addresses has not had their address compromised. But ID and name still is.
And with the rest exposed it is now trivial to see what adresses are "interesting".
deanc 11 hours ago [-]
In Finland, this would be enough to get you through the security checks at pretty much any institute via phone, possibly excluding banks.
nottorp 6 hours ago [-]
Finland uses whatever the equivalent of a SSN is as a password, US style?
deanc 5 hours ago [-]
Kind of. It's advised to keep it secret but I'd be astonished if most people haven't had it leaked whether they realise it or not. Usually when identifying with e.g. a telecoms provider you would give your SSN and then some additional piece of meta-data such as address. Chances are everyone has a combination of SSN + address + phone leaked.
delamon 13 hours ago [-]
They say that persons with protected address had not been leaked.
toyg 12 hours ago [-]
What's a protected address, witness relocation programs...?
LarsKrimi 12 hours ago [-]
When you change your address you can click a checkbox saying you want a protected name/address. This means that companies that have you as customers/clients won't be able to get the new address, mail won't be redirected, etc
I did it accidentally during my last move and it was a pain in the behind
And it expires after a year by default so it feels rather pointless
encom 6 hours ago [-]
If you own a danish domain name (.dk), unless you have protected address, all your info is a whois lookup away. Example lookup of ft.dk (danish folketing).
Domain: ft.dk
DNS: ft.dk
Registered: 1995-07-04
Expires: 2027-09-30
Registration period: 1 year
VID: no
DNSSEC: Signed delegation
Status: Active
Registrant
Handle: DATA REDACTED
Name: Folketinget
Address: Christiansborg Slot 1
Postalcode: 1218
City: København K
Country: DK
Phone: +4533375500
Email: webmaster@ft.dk
ID status: ID verified via electronic ID
Nameservers
Hostname: maleah.ns.cloudflare.com
Hostname: yichun.ns.cloudflare.com
This is why I've never posted anything from my own shitty website here. All of this is available from [myname].dk with my info on it. Also it's horrifying that our government is restricting access to its website behind fucking CloudFlare.
EDIT: I didn't redact anything from the lookup, this is the exact data I received.
Mashimo 12 hours ago [-]
You can just apply for protected address. I did that once, because I did not want that my .dk domains whois would show my name and address.
I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.
Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.
wodenokoto 12 hours ago [-]
I think it is worth mentioning that age and sex is encoded in the social security number.
There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.
consp 11 hours ago [-]
I learned a few days ago from a friend, when the other leak at the university was reported in the Danish media, that the "random" part is only 4 digits and as a bonus is sequential. So if you register in the country as foreign citizens together with your partner those are likely sequential.
Then again, in my country some municipalities handed out numbers starting with your birth year....
vintermann 12 hours ago [-]
A good time to remember that cramming data into your identifiers will come back to bite you... It hasn't really been necessary since databases replaced library catalogs anyway.
brabel 11 hours ago [-]
I think they do this to make it easier to remember your number. It’s really not private data in the Nordics as others mentioned, even your address and phone number and , on request, salary can be easily found out legally.
guytv 9 hours ago [-]
this is gold to countries that routinely fake other countries passports for "legends" (cover identities) for their intelligence officers working in "target countries".
IceDane 9 hours ago [-]
This is just wrong and should be flagged by mods. It's name, CPR and address.
Gender is encoded in the CPR number.
vasusai 12 hours ago [-]
[dead]
Mashimo 12 hours ago [-]
CPR number contains Age and Sex. It's date of birt DD MM YY. Plus four digits where you can read the sex from. I think it's even vs uneven numbers.
mrweasel 12 hours ago [-]
It's honestly worse. DDMMYYY (the last Y is from a lookup table to know if it's 18YY, 19YY or 20YY). If a person is born before October 2007 you can even do a checksum using the last digits to verify that the number is "correct" (not necessarily in use). And yes, last digit is an even number for women, and uneven for men.
jjgreen 11 hours ago [-]
.. decimal place for interestingly gendered?
mrweasel 10 hours ago [-]
I think you get to pick even or uneven yourself if you're don't identify as male or female and you can have a new CPR if you change gender.
There is some interesting details that may require you to change your name, if you want the last digit changed. That means if you're name is Kurt, you can't have a CPR number ending in an even number, because Kurt is only an approved name for men. If your name is Kim, Storm, Charlie, Orla, Lykke or some other unisex name it's not a problem.
Roark66 10 hours ago [-]
You know, recently a medical SaaS provider's system was hacked here in Poland as well. Medical records of 20mln people covering pre 2024 back leaked. The attackers claim to have got it via a vulnerability that any company could've had. Fine.
But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned.
Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data.
But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future.
Nothing.
Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure.
Quothling 12 hours ago [-]
As someone who spend a decade in the Danish public sector, among other things working in groups on national architecture. I'd say that we reap what we sow. IT and digitalisation is not taken very serious in our public sector. In most places it's placed under something, and until recently it didn't have it's own ministry. Right now it's even a shared ministry, and there is little focus on cyber security. What has arrived in recent years is solely based on the thread of hybrid attacks from Russia.
Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?
My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.
Mashimo 12 hours ago [-]
> IT and digitalisation is not taken very serious in our public sector.
I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.
Quothling 12 hours ago [-]
Maybe 10 years ago, but other nations have caught up. Italy has their Sistema di Interscambio. Germany and France have taken digital sovereignty serious. Spain is big on open source (and ruby for some reason). Estonia has been miles ahead for more than 10 years. It's true that we have some ease of use systems compared to most of Europe, but we also have a lot of horror stories.
That being said it's not like us being shit at cyber security doesn't mean other countries aren't also shit. Look at Australia getting hacked by AI. I know it's all the rage to blame OpenAI, but really, shouldn't Australia count itself fortunate it wasn't an enemy nation state? Or that their lacking security got exposed before it was.
mrweasel 11 hours ago [-]
You're conflating two different things here. What Denmarks excels at it implementing public IT solutions that makes processes smoother, like patient records, medical perscriptions, digital signature, a nation-wide digital identity, things like that. Digital sovereignty isn't part of this, and Denmark isn't particularly good at it, nor is it really valued that highly. Same for cyber security, I'd say that it's down to dumb luck that it's not worse. There is a city, Randers, they can't send email to the domain anders.dk (Anders being a pretty normal Danish name). Why? Because the butterfingered public employees in Randers could stop sending personal information about citizen to anders.dk, which has a catch-all email. They simply forgot the "r". The problem is the lax attitude to emailing sensitive information, probably via a Microsoft run Exchange server, but rather than fixing that, they just blocked the anders.dk domain.
Quothling 9 hours ago [-]
I don't think I'm combining different things. I think the lack of focus on digital sovereignty is just another symptom of a public sector which still doesn't prioritises IT. Which I think follows my original post about our CPR system reaping what it had sown. I don't think you are wrong, but I think as far as my point on taking digitalisation serious, which I think is a required part of a mature public sector, I think all these lacking areas tell the story of a public sector which used to be the best in the world, but has been far too complacent.
As far as Randers cyber security goes. I imagine it'd be "fun" to do an right of access to documents, on the amount of unique visits their Microsoft Defender has registered to chatgpt.com and claude.ai.
mrweasel 9 hours ago [-]
That makes sense. I'd agree that IT isn't prioriteres, unless it's in some project form, the daily operations isn't valued. We see this in how contracts are written, software is basically purchased on a contract and expected to be run that same contract for years. There's very little incentive for operators to provide anything but the bare minimum, because the price is more or less fixed regardless of effort.
Mashimo 11 hours ago [-]
Mhh, I don't know. In Germany they proudly proclaimed their BAföG / Student loans (SU in Denmark) is now digital. But what was digital was just the client side, on the government agency side they still would print out the applications. And because they where used to people sending in paper, they had to hire more people to help with the printing. AHHHHH. That is the state of German digitalisation.
There are things I wish I could change in Denmark, mainly the power sockets and number system (Base 20 what the heck?) but Denmark is on a good course when it comes to IT understanding. Both the broader society and government implementations.
Yes yes, Estonia is better. But Denmark is still doing good.
spragl 9 hours ago [-]
Doing well has two dimensions (at least). One is the degree of digitalization, and here I think youre right, Denmark is doing well. The other dimension is security, and here Denmark is not doing so well.
As all security professionals know, people dont care about security, until they are hurt, and often even after that. Lost privacy doesnt hurt if you dont think too much about it.
What we are also seeing is that governments/administrations dont care about security (with exceptions). They really want to go ahead in the digitalization dimension, but not so much in the security dimension.
porsager 11 hours ago [-]
Another Dane here, and that is absolutely not true. Where's your source to back up this claim? (I'll show you mine if you show me yours)
Mashimo 10 hours ago [-]
> Where's your source to back up this claim?
Feel. Having lived in Denmark and Germany. And working for the public sector.
MitID is just chefs kiss how many other countries can you log in to your bank, student loan, and local municipality with the same sso. Country wide app for local transportation tickets of different types. EPJ / Elektronisk Patient Journal has it's fault, but compared to other countries[2] yet again not that bad.
Shit man, even something simple has going to the doctor for blood tests. I think you can get the results on the same day via app. Maybe next day. In Germany[1] you have to wait a few days, then the Dr. calls you with the results and then you can ask him if he can mail it to you.
What in Denmark actually requires you to get physically to the municipality? Weddings? Even divorces work online. Compare that to Germany, Austria, Italy etc.
Why do you think Denmark is not one of the leading countries in digitalization?
[1] Probably dependens on location / Bundesland.
[2] https://de.wikipedia.org/wiki/Elektronische_Patientenakte_(Deutschland)
I can't say how accurate these lists are. But they match my observations. Nordics lead.
porsager 33 minutes ago [-]
> And working for the public sector.
Ah - there we go..
Meanwhile living in Denmark we are not even able to get results for blood panels from our 14 year old daughter cause "the system was not made for it". You know I'd much rather have it in the mail than not at all.
Even so, we tried to get a MitID for her so hopefully she could log in to see them. How do we do that you ask? Meet up physically. Did they fuck it up the first time? Sure, but luckily only a week later we were able to get a time hoping we'd now be able to get access to her blood panels. Nope. Logging in with her MitID says she is not old enough to see her blood panels. How long has it been like this? More than 5 years.. But luckily a law was passed in 2023 to do something about it.. Has it happened yet? No, but it doesn't matter.. She'll be 15 before it's implemented anyway.
I could go on with similar stories from almost every system I have to touch in Denmark.
Quothling 10 hours ago [-]
MitID is great. It was developed and is still largely operated by the banking sector though. Though to be fair, the public sector was wise enough to adopt it rather than build their own. If you look at actual public sector projects like the recent taxation system for property tax you'll find things are quite a bit different.
KingMob 11 hours ago [-]
Can't speak for the Danish govt in general, but you should look up the history of the property tax scandal and the projects that tried to fix it. I was part of the third attempt to rectify the problem at SKAT.
Mashimo 11 hours ago [-]
Or how there still are over 200 people working fulltime on the corona mink .. "event"
That said, compared to other countries the tax / SKAT is also quite decent.
bryanrasmussen 10 hours ago [-]
Just to note - the population of Denmark is 6,032,304.
So essentially the whole population's data has leaked. Furthermore, the notice says mv, which is abbreviation for etc.
So it says "name, address, cvr number" etc.
That etc. is funny because the Danish government has a thing called NemID which you use to log into pretty much any online service, including banking, and you can install it on your phone, and when you lose it though you can verify by calling up and giving personal information to verify it is you.
Now there are a bunch of things about this system that are contemptibly stupid and annoying that I won't go into here because of my blood pressure. But now I wonder if the mv. of the personal data covers stuff you could conceivably be using to get a new NemID.
on edit: the really young have not had their data leaked, probably, and the excess of course covers people who used to live in Denmark and left.
cm2012 10 hours ago [-]
I am going to be very curious to see if there are any downsides or negatives at all to this hacking happening. In theory this information could be used to scam a lot of Danes. In practice these major hacks end up fizzling out, in my experience - the data being less useful or more duplicated than people thought.
fwn 4 hours ago [-]
Just because we cannot identify any disadvantages does not mean that there are none.
Imagine a foreign state-sponsored agent waiting at the door of a public or private decision-maker, convincing them to cooperate. Home addresses are no joke. Especially if you can grep through the whole family tree.
cm2012 3 hours ago [-]
It is more or less trivial to find someone's home address now if you try at all. Thats my point on duplicated data in hacks.
fwn 3 hours ago [-]
It really depends and I often struggle with it. How do you do it?
The German Melderegisters, for example, are now far more interested in the stated reason for your data request than they were ten years ago. (Which is a good thing!)
Many things that are trivial in theory, given the right conditions, etc. are anything but trivial once you actually try to do it.
ulrikrasmussen 10 hours ago [-]
I think you mean MitID, but yes. I have tried going through the process of getting a new MitID at the citizen service desk, and the questions I am asked to verify that it is me are almost all family related. If the leaked data reveals things like parent/child and spouse relationships then that process is cooked.
bryanrasmussen 5 hours ago [-]
according to this article which I linked earlier because I thought the non-Danish readers might appreciate it, it "can include" family relationships
ah yes, sorry, I worked on the NemID project and I often put NemID in place of MitID when I'm tired.
m12k 11 hours ago [-]
This comes only a few days after a data breach was reported at the Technical University of Denmark [1], exposing the personal records of current and past students, faculty and staff. That included their CPR numbers (government id at the central person registry), that could for example be used to look up their official place of residence. All in all, it seems likely that someone just got the table they needed to join on the first breach.
I see this as a good thing. It means that we'll (hopefully) get stricter security revolving around using these numbers. It'll no longer be enough just to yap out a 10 digit number to "verify" you are who you say you are. We already have a (albeit heavily critiqued) national 2FA system in place (MitID).
We'll have to start treating the CPR number as just a username, instead of a password. It should never have been "secret" in the first place.
yturijea 10 hours ago [-]
Totally agree, and I am unsure why it has not happened after the last breach we had, was it 8 years ago?
I dont see this breach as any significance as I thought it was all breached anyway earlier.
Any agree, it should be only a username and MitID is the verifier(password) and without both, it should simply be impossible to create any kind of binding contracts like loans etc. anything else is simply sloppy policy from the government. but again no politician understands IT, neither does the majority in EU about the implications of chat control...
spragl 10 hours ago [-]
What you write is correct, but it wouldnt make any difference in this case. The information would have been leaked anyway.
It will take a whole new approach to confidential information to really make a difference. I think we need to go the SSI way, and I think at some point we will.
jakub_g 13 hours ago [-]
In the past few months, there were several huge data leaks also:
- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)
- in France (from tax office), 678k people affected
With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.
Tangurena2 9 hours ago [-]
Or 153M driver's licenses & passports in the US leaked from IDScan.net:
- Germany, Berlin: personal information of civil servants, secret information about civil protection, emergency communication systems of the german gouvernment, overall 6 TB data
233mhz 12 hours ago [-]
Gun ownership records were leaked in france recently too, including identity and address.
archixe 13 hours ago [-]
The article mentions that they accessed the information through a Danish company whose access has been revoked now. I find it really surprising that a company could access these records without any limitations on which info or how many records they can pull.
12 hours ago [-]
haute_cuisine 11 hours ago [-]
Claude, calculate salaries, make no mistakes. (they probably forgot the last part)
I wonder if company used some kind of automation that decided it needs all CPRs for whatever it was doing.
hn_submit 10 hours ago [-]
I demand our representatives come up with legislation that puts hefty fines on data breaches.
Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.
As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.
6 hours ago [-]
Tehnix 7 hours ago [-]
They only thing I can think of that a person could get out of having my data is they can pick up my subscription at a pharmacy, where it’s normally enough to mention your CPR number, and then the pharmacy asks you to confirm what name it’s registered to.
Anything else like banking or anything official requires a MitID authentication, and no one malicious can just e.g. open a bank account in my name. They’d have to go through several authentication confirmations usually.
Are there other areas where we are lax about CPR still?
KingOfCoders 12 hours ago [-]
If people don't go to jail, there will be no change.
Gareth321 11 hours ago [-]
The EU would rather destroy our right to privacy than hold criminals accountable. If I sound bitter it's because I have become very bitter over the last decade. The EU appears very effective at picking on individuals and people who can't fight back, and absolutely toothless when it comes to taking on more powerful interests. There are very few cases of the EU tangibly improving my life over the last decade, and countless examples of making it worse.
KingOfCoders 10 hours ago [-]
"and absolutely toothless when it comes to taking on more powerful interests. "
Like Google and Apple?
"and countless examples of making it worse."
Which would those be? I would be interested to know.
Gareth321 10 hours ago [-]
> Like Google and Apple?
Yes, like Google and Apple. If you would take a look at my submission history, you'll see exactly one. It was me celebrating the passing of the Digital Markets Act more than four years ago. This Act clearly lays out requirements for gatekeepers like Apple. I summarise these requirements in a comment in the submission:
* Install any software
* Install any App Store and choose to make it default
* Use third party payment providers and choose to make them default
* Use any voice assistant and choose to make it default
* User any browser and browser engine and choose to make it default
* Use any messaging app and choose to make it default
* Make core messaging functionality interoperable. They lay out concrete examples like file transfer
* Use existing hardware and software features without competitive prejudice. E.g. NFC
* Not preference their services. This includes CTAs in settings to encourage users to subscribe to Gatekeeper services, and ranking their own services above others in selection and advertising portals
To date, Apple has implemented only a handful of these, and they have done so with malicious intent. For example, they have made the creation and distribution of third party app stores to onerous that very few companies have navigated the gauntlet and actually used it. Third party browser engines are now technically supported, but so poorly that not even Google has endeavoured to create an iOS browser engine. The worst example is app distribution. The DMA requires gatekeepers to facilitate free distribution. Apple has failed to cmoply with this for four years, and has repeatedly appealed when admonished. The Commission has been sitting on their most recent "review" for over a year now, without any updates.
The net result of all of this is that Apple has retained almost all of their duopolistic market power, and has implemented almost none of the DMA requirements. They have given us the middle finger and our legislators have gone to sleep.
> Which would those be? I would be interested to know.
I'll give you me perspective as a Danish citizen.
The EU imposed working-time recording requirements, so now I have to log my working hours every week. I'm a full time employee and I work longer and shorter weeks. Now I have to waste time each week logging my hours. My company has to waste time each week logging hours and reporting them to the government and the EU.
The EU required bottle caps to remain attached to most plastic drinks containers, so now I have to wrestle with an attached cap every time I drink from one.
The EU banned ordinary disposable plastic cutlery, plates and straws, removing products I previously had the choice to buy.
The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners.
The EU introduced "Strong Customer Authentication" requirements, so routine online payments and banking increasingly require additional authentication steps.
The EU abolished the €22 VAT exemption on low-value imports, making even tiny purchases from outside the EU subject to VAT. This one in particular sucks because the company or local tax authorities impose huge minimum fees, making small cross-border purchases far too expensive now.
The EU imposed expanded producer-responsibility rules on packaging, adding recycling fees, reporting requirements and compliance costs that ultimately feed into the prices I pay.
The EU passed even more extensive packaging regulations covering recyclability, recycled content, packaging minimisation and reuse, adding another layer of costs and restrictions to ordinary products.
The EU imposed increasingly strict CO2 targets on car manufacturers, financially penalising manufacturers whose fleets exceed them and increasing the pressure to make petrol and diesel cars more expensive or stop selling them.
The EU created ETS2, which from 2028 will add a carbon price to road fuels and home heating, creating another cost that fuel and energy suppliers can pass on to me.
The EU imposed sustainable aviation fuel mandates and tighter carbon rules on airlines, increasing the regulatory cost of flying.
The EU brought shipping into its carbon-pricing system and introduced FuelEU Maritime, leading shipping companies to add explicit EU environmental surcharges that feed into the cost of goods I buy.
The EU imposed Ecodesign restrictions on appliances, including maximum power limits for products such as vacuum cleaners, reducing the range of products I am allowed to buy.
The EU passed a minimum-wage directive despite Denmark already having its own collective-bargaining model, forcing Denmark to fight the EU in court to protect a labour-market system that was already working without a statutory minimum wage.
alpaca128 3 hours ago [-]
> The EU abolished the €22 VAT exemption on low-value imports
Because it was abused by countless vendors that just wrote a random value below 22 Euros on the label no matter how much it cost.
> The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners
Not sure why you're blaming the messenger. Either way this can be solved by installing a browser plugin.
alt227 5 hours ago [-]
A lot of those things you listed the EU as doing sound like good things to me.
raxxorraxor 12 hours ago [-]
Problem is that the EU will even go further here and tries to implement that everyone is forced to id themselves despite the regular problems.
TacticalCoder 11 hours ago [-]
> If people don't go to jail, there will be no change.
The EU being the EU, it's those criticizing the leak by governments of public data that are going to be sent to jail.
KingOfCoders 10 hours ago [-]
"it's those criticizing the leak by governments"
If this is a general trend in the EU, what people went to jail for criticizing the leaks?
nhma 10 hours ago [-]
Oh no, the evil EU police will throw us all in EU jails!
iphonecorridor 9 hours ago [-]
We probably need to value privacy less. I went to a hospital in 3rd tier city in China and all the patients were in a room milling around a doctor with their charts. He’d randomly pick a person, look at their charts, do some basic tests (looking in throat etc), and write them scripts. All with everyone listening. Seemed wild. But pretty efficient! To get my visa, I had to have a chest xray, ab ultrasound, bloodwork, ekg etc etc… it was me in line with 100 other visa folks all going from one station to the next fully hearing results or seeing everyone else. Scary! But honestly it was one of the most efficient health experiences I’ve had and I still refer to the results! (Spotted “fatty liver” and got me to drink less.)
panzi 4 hours ago [-]
8.8 million people? Wikipedia says Denmark only has 6 million people! Historical data too? People from other countries that had any treatment in Denmark?
still-learning 3 hours ago [-]
Need to pay your cybersecurity people
clan 14 hours ago [-]
CPR is the national register of all people (Central Person Register).
CPR is the administrator. There is more information in the linked press release from the ministry:
Will Danes be compensated for the hassle, this causes them? (Probably not)
Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)
zunintoku 8 hours ago [-]
What's with the state jab, this was a business leaking it
hastily3114 12 hours ago [-]
As someone who works with CPR data in Denmark, this does not surprise me at all. Private companies access the data through an API, and anyone who works at such a company can look up CPR data as they please.
spragl 10 hours ago [-]
That is also my impression. So I wonder how they caught this. It will be interesting if they are going to say so at some point.
JeanCampos 10 hours ago [-]
The funny part is that the info just have any value in a system that works fairly well, but stolen data reduce the trust on the system, so decrease the value of that very thing that is being stolen...
I do not think we will ever go back to the wild west, but it is also hard to think a future that follows this very tendency.
Before we had natural disasters to worry about and now we have those + cyber ones.
cimi_ 12 hours ago [-]
Denmark's population is 6 million [0], where does the diff of 2.8M come from? :)
It's explained in the article, the dataset includes foreign nationals/temporary residents and some deceased people as well.
eric4smith 11 hours ago [-]
Wait... wait wait...
I thought the EU "protection" laws was supposed to prevent all of this?
hoppp 11 hours ago [-]
Probably everyone in Denmark got breached. That sucks but 2FA identity verification already exists to access personal info
HenrikPontoppid 10 hours ago [-]
I live in Denmark.
The 2FA verification system in place now has not had any reported breaches but is nevertheless an absolute joke. I use GrapheneOS on my personal phone which cannot use the government 2FA due to the arbitrary Android integrity API. I therefore use my old phone on which it works perfectly. The catch is that it hasn't been updated in over three years lol.
When the ministry responsible for the 2FA system was asked to allow it to be run on degoogled OSes, they refused saying it would be too costly to develop for "other systems". The responsible authority doesn't even know degoogled Android is still Android. And you expect these people to protect your private information and health records.
It was also leaked some time back that the Danish government let the NSA spy on every citizen in the country for literally nothing in return. Unconstitutional? Yes.
hoppp 10 hours ago [-]
Its the MitId app that don't run on Graphene OS?
Yeah, it's probably easy to bypass too, if they are not actively maintaining it there are definitely holes in the system.
I think bad and expensive government software systems are a global norm, still the Danish system is more private than the Swedish where all it takes is a name and everyone's home address can be searched for.
sgt 44 minutes ago [-]
Maybe even dhh got breached. If only this system had been vibe coded in rust, this would have never happened /s
yeah, a this rate, we can assume all digital information will be public at some point.
chrisjj 10 hours ago [-]
And unofficially - giving free rein to malicious misinformants everywhere.
Not long now before people get extorted for correction of doctored leaked sensitive personal details.
ionwake 12 hours ago [-]
Just so everyone understands the numbers thats basically everyone in Denmark.
Ekaros 12 hours ago [-]
Everyone in Denmark dead or alive... I wonder how many years or decades it takes to clean up the dead from there.
ionwake 12 hours ago [-]
You are right lol, damn!
IceDane 9 hours ago [-]
For some more context for non-danes:
Basically any company can access to an API that lets you look up CPR(~SSN) numbers, and a lot of companies have access.
What has most likely happened is such an integration has been abused - we do not yet know whether it's by mistake or by some malicious third party. It wouldn't surprise me in the slightest if this is just the result of someone's Claude agent telling them that they can improve lookup times if they just enumerate every CPR number and cache them, for example - but we don't know yet.
sedan_baklazhan 4 hours ago [-]
I’ve opened the story just to search for “Russia”
Of course, Russia is being blamed twice for this data breach in the comments.
I am not disappointed.
m00dy 8 hours ago [-]
Danes have never been good at cybersecurity.
ByeByeSpace 5 hours ago [-]
GDPR already says companies should only keep data they actually need. Breaches like this suggest the fines still aren't big enough to change how they behave.
rimliu 11 hours ago [-]
And guess who are pushing for the Chat Control.
nephihaha 12 hours ago [-]
Isn't that more than the current population of Denmark? Who were the other exposed people?
kzrdude 7 hours ago [-]
People like me, who have a CPR-nr from the time I used to work in Denmark.
KingMob 11 hours ago [-]
Foreign residents and dead people, apparently.
LarsKrimi 12 hours ago [-]
Altman at it again?
_s_a_m_ 10 hours ago [-]
so more data breached than people live in Denmark..
4 hours ago [-]
rvz 13 hours ago [-]
Let me guess, the Danish government will find a way to prove that GDPR doesn't apply to them.
But this is incredibly bad.
shiandow 12 hours ago [-]
It does apply but they were allowed to have this data and GDPR does very little to protect it in that case.
tamimio 7 hours ago [-]
Lol, I remember few months ago here in HN and some swedish or danish user telling how they are happy with the amazing cashless system and society there and how it’s better than cash.. there you go, breaches happen and so it blackouts.
That being said, one of the issues is private companies are allowed to request personal and private information, no matter how security is, it’s eminent to get hacked or phished, like revoult, I wanted to use their platform weeks ago and they requested to “verify my ID” refused and didn’t use it, few weeks later and they suffer a data breach because some idiot employee emailed the data to someone saying they are gov.. you can never trust, zero trust in fact. Instead, there should be a way (like tokenization) to prove the identity without the 90s method of scanning the ID like how we used to fax things back then, except it was more secure that way ironically.
amelius 11 hours ago [-]
"Something is rotten in the state of Denmark"
tokai 9 hours ago [-]
At least they didn't mail a CD containing data on 5 million danes directly to the Chinese this time.
It really is a nothing burger this data has been leak multiple times, and is easy for any bad actor to get their hands on at any time should they need to.
derin-picment 12 hours ago [-]
[flagged]
Wittie 12 hours ago [-]
[flagged]
13 hours ago [-]
CurbStomper4 9 hours ago [-]
[dead]
celpgoescheeew 6 hours ago [-]
[dead]
alexx-devv 12 hours ago [-]
[dead]
aaron695 13 hours ago [-]
[dead]
mistermaster1 11 hours ago [-]
[dead]
goreyee 10 hours ago [-]
Almost said the n-word reading that danish title...
johnwalker67 14 hours ago [-]
I am so done, my cpr is leaked oh no. Like I don't
clan 14 hours ago [-]
This is were security meets the real world. The number is not secret but people have been taught to keep it confidential. And when you know the last 4 digits social engineering har become a lot easier.
Ekaros 13 hours ago [-]
On positive side maybe now there is no reason to use it for authentication anymore. When it was always unsuitable for that reason.
clan 13 hours ago [-]
I used to agree.
But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.
This will be easy to exploit on a scale.
Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.
aDyslecticCrow 13 hours ago [-]
CPR isn't the problem, the rest of it is.
thiagoperes 12 hours ago [-]
it feels this will keep happening specifically to Europe for three reasons:
a) most countries took an anti-AI approach
b) they reject frontier models in favor or "Sovereign" solutions
c) they're replacing software with weaker/more vulnerable options
public servant engineers are token poor and will be out of the latest defense tools
Mashimo 12 hours ago [-]
I don't think this is AI related at all. What makes you say that?
chrisjj 10 hours ago [-]
Scorned AIs taking revenge? :)
sunbum 10 hours ago [-]
The data got leaked by a private company.
Rendered at 22:08:26 GMT+0000 (Coordinated Universal Time) with Vercel.
I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.
There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.
All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.
The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.
This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?
I should not have to love the bomb because the bomb will kill me.
I don’t get that comparison with data being available everywhere
Also,it can help you uncover and put behind bars your dangerous political enemies. That the tables may turn and the shoe may be on the other foot soon, that's too abstract of a thought to occur to most of them.
On the other hand, said data can be today use because various entities use extremely shitty authentication methods, like just insert your birthday and first name and voila you have a credit with our bank (not an actual example, just for illustration purposes).
There are situations in many a person's life that if revealed to the public would have life-altering consequences.
Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data.
How are you jumping from Minecraft (probably one of the most watchtime-generating content types out there) being displayed on your main page to… your personal information being known to everyone?
intermediaries that will be compromised
Except that YouTube doesn't need any of that to recommend Minecraft videos to you. One mundane explanation that seems more likely is that it's the type of content that on average works best on people they don't yet have information on.
Reminds me a little of these "phones listen to everything we say, otherwise I wouldn't have been shown this ad" anecdotes that don't hold up against empiric evidence.
Microsoft would definitely sell data on which IPs have Minecraft users, as would your DNS provider, cloudflare, or your ISP.
It could also be coincidence, though my experience is YouTube's suggestion algo is very tightly tracked to use data. (What I was fed on a guest account recently was a mix of fascist propaganda and AI nonsense masquerading as reportage.
If phones weren't listening technology like audio beacons couldn't have been invented or useful (https://medium.com/@williamwais01/ultrasonic-beacons-the-sil...).
Surveillance capitalism has been so successful because it's so opaque. It would take a whistleblower for you to know when and how the data companies have is used against you, or how they got that data in the first place. Their tactics can be used in ways that are highly targeted and transient, especially for data collection companies like Google.
Even for something as basic as search results what I see when I search may not be what you see, and what I today might not be what I see when I take the same actions tomorrow.
This can make identifying what our phones are doing almost impossible. A possible explanation for the "phones listen to everything we say, otherwise I wouldn't have been shown this ad" phenomenon might be that a phone picked up an audio beacon being broadcast while something played on a TV, which sparked a related conversation in the person carrying the phone. The conversation wasn't recorded, but topic being discussed was successfully logged anyway. There are countless other data points available that could be used in the same way. In cases like that it would clearly not be coincidence that Google showed an ad when it did, but the spying involved was even more involved and invasive than just listening to what was being said.
There's nothing to stop Google from having small clusters of phones listening to everything for certain periods of time under certain circumstances. They wouldn't have to send all that audio data back to their servers to be effective, just monitor for a sample of specific words/phrases (processed on device) and send back a flag when something is overheard. That kind of behavior would be extremely hard for researchers to catch.
The truth is that we're not allowed to know how and when we're being surveilled, but we are being watched all the time, and that data is collected to be sold or used against us at every opportunity. It doesn't do any good to tell the person imprisoned in the panopticon that he's being paranoid and that it's all coincidental. Even when it happens to be, feeling watched is the natural response.
Honestly I wish I would get more targeted ads for the stuff I look for, when I look. Instead, for some, it happens that after I buy them, I get repeated ads after couple of weeks or even months (like, invoice is on gmail, photos of the object on my phone, but nooo they want to trick me, so they still send me more ads of the same shit that I will not buy again in years).
Seriously, I think the tracking is as crappy as most software is. Sure, it might identify one/two keywords and throw ads at you, but it does it a dumb volume way that corporations work, not in a smart "we know everything about you way", that a true geek might implement.
Right now the amount of data about you companies have is just massive. Everywhere you are at every moment of the day, who you were with, what you talk about, everything you buy, and every website you visit, what your mood is, what your level of education is, how you react to stress, it's all too much information for companies to extract useful data out of right now. AI is going to help with that. Unfortunately, like everything else AI does, it will do it pretty badly and with lots of errors and hallucinations. The companies using AI won't care though as long it works enough times on enough people that they make money.
To make matters worse, ads are only a small part of what all that data is used for. It's the thing that's most visible to you though, so you can imagine that if your ads show that companies think the wrong things about you that HR departments and other companies you interact with offline probably do too.
Doesn't that just make your browser very unique?
Did you play minecraft on the same network? If so, I'm not sure why the results are surprising or why it would negate all your efforts. If someone else played minecraft on your network you would also see a minecraft video on your main page I would imagine.
For example, matrix sucks ass. It's terrible. Everything about it is a bad experience. Of course you'd want to eventually stop using it and go back to the previous life.
But that is not the correct take-away.
The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.
Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.
You as a normal individual simply cannot replicate the kinds of services that an Executive Protection services provide [0][1].
[0] - https://www.pinkerton.com/services/high-net-worth-individual...
[1] - https://vespergroup.se/en/
Probably wouldn't last long though, as they would be furious, that us lowly human beings are able to glean anything about them. The double standard of this is not obvious to them.
That's denying most culprits the opportunity to use the collected data against you.
Like always on VPN, turning off personalization, ad guards and using open source products where possible.
The real next frontier is to maintain one or more carefully curated personas with various companies to optimize how they treat you. Wear shabby clothes and fake beards when grocery shopping so that the cameras think you're poor. Security will be all over you, but the digital price tags will give you lower prices as long as you don't have your cell phone on you and they can't get a good face ID because then they won't be able to pull up your actual income level.
Create and maintain specially crafted social media accounts filled with fake hobbies and AI generated photos but never express an actual opinion on anything at all so that future employers can see you have a "presence" but they won't see anything that might disqualify you a job, like your political views.
Buy multiple high/low end devices and rent a closet or PO box in both rich and poor neighborhoods so that you can selectively hand out a mailing address that will make you appear either poor or well off.
Pay someone to take your cell phone out them on friday night so that you can appear more socially active otherwise you'll be flagged as anti-social which can impact employment, raise your health insurance rates, etc.
- Don't volunteer your intimate details left and right;
- Feel entitled to deny requests for unnecessary data (and advocate for such rights if you're in position to)
- Otherwise don't sweat it, because you can't actually control what others know about you, you never could
The reasonable position will be slow marched into hell same as the rest of them, just a few steps behind.
And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.
I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.
Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.
Security is their business while security for the state is a cost factor.
Being at the mercy of some ignorant politician is not the best way to talk about data security.
Berlin, Denmark - those are the known one. And there are many more to come.
And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.
X got fined for a missing blue mark. Berlin? Denmark? Others?
A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.
So it is relatively easy to get data on them as well just by filtering out the other data.
In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.
And remember: being the one who is not using google when being around other guys who do - magic.
So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.
Pick your fate.
How many state data breaches vs corporate data breaches? There are hundreds of state entities with my data (probably thousands), and yet private companies with my data have been hacked more times.
...and yet private companies with my data have been hacked more times, so far.
Also they might have not been targeted....
That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not.
Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist.
1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though.
2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen.
One thought here that I don't personally agree with, but might be important regardless:
Imagine a society without secrets or privacy at all for example.
I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world.
Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important?
They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.
At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.
A relative killed herself after her therapist was hacked[1] and the data was leaked. If that is inconsequential, I do not know what isn't.
[1] https://en.wikipedia.org/wiki/Vastaamo_data_breach
I don't know how deep palantir can build profiles on someone, like digging into comment histories and extrapolating you are x y or z sort of stuff. I'm sure they've learned a lot about people via public irc logs and discord servers. But the only screenshots I've seen have been way more simple than that, basically a facebook UI that gives them buttons for all the apps with the phone # that has been identified as you the user, so it would be your list of social media apps accounts and they just click in and read messages. These screenshots have popped up in court cases recently.
We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Carry a dumb 2fa. I've always been on the "dont ask for my phone number to use your service" bandwagon but absolutely now.
And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore.
Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.
The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.
I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.
You dont get it bro, its not a good vibe.
And if I had bean in management I would have fired anyone involved with that decision.
Why is it so often HN that I point something obvious out , like Rockstar having clearly failed management and a complete loss of control, but instead of agreement or silence I always get flak from some random user who just doesnt get it, and then a year later the company starts falling apart.
Im just a guy who recognises patterns and im not even smart.
So you knew that fierfox never came with google analytics but you decided to claim it anyway...
You download firefox. In firefox, you go to settings->Extensions to download extensions and get exposed to google analytics, is that correct? If that's true, how is it not insidious that in order to download the thing that blocks google analytics, you have to get exposed to google analytics?
Because many "obvious" things are just plausibly sounding bullshit. For example:
> Rockstar having clearly failed management and a complete loss of control
That's both very broad and generic, and completely unfalsifiable, and comes with nothing backing it up. It's just an unsubstantiated opinion. These things are fine when drinking in friends, or otherwise socializing by bonding over ramblings.
If you want to convince someone of something, the standards of evidence (not to mention, clarity of thinking) are a bit higher.
This site will start falling apart if we don't keep things civil.
Oh, I love the bit where a programmer always proudly chimes in with this statement as if it means anything.
I get wanting to be conspiratorial, but its not cool to go after others that challenge your conspiracy, even if its "obvious"
And then add on that fact that my doctor recently started using some kind of AI voice transcription app that listened to our entire conversation. Except that it hallucinated details I absolutely did not say, which are now in that doctor's records and I'm sure will be taken at face value in the future.
It's maddening.
If your doctor is worth seeing at all, they will be glad for the corrections.
But whenever possible, I lie. Different name, birthdate, every question about "favorite pet"? A lie. "They" have tons of data on me, but more and more is wrong. Let it leak.
Sending my file over to lawyers in a semi-safe way has proved impossible.
And in any case, i received an answer with lots of PI over a plain email…
Absolutely maddening
If it's one older guy, good luck. You're probably better off doing everything by FAX honestly.
It was .7z with strong pwd. The normal zip is supposedly too weak according to llms
I know it’s modern American tech tradition to make fun of the GDPR, but this is genuinely one of the things it stipulates: You’ll get at least a slap on the wrist, or potentially much worse, if you needlessly keep data around longer than necessary to do the task you had collected it for in the first place.
But nobody really cares enough to spend money modernising this sort of system.
I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
When I toured apartments they would often take a photocopy of my ID. Okay, overkill. But realistically I have no idea where that photocopy is stored.
Probably in a OneDrive somewhere to this day.
Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet!
This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.
I was asked for my passport in a Premier Inn this summer because they thought I was a foreigner but when I pointed out that I was a UK citizen they dropped the requirement.
In Europe it was mostly Italy and Poland that wanted to see my passport.
You can try to say no, but I don't think you can anymore. I go through this a dozen times a year on my travels there.
This is Spain.
Why can’t WE spy on them 24/7?
I am writing this because I don't think democracy works as advertised.
mind that there was a breach recently where all the data was being leaked *the moment it was collected*
so simply controlling retention is not enough. The very fact of data being taken is already a vulnerable part
I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.
That's the world we live in.
"Police and thieves", collaborating one way or another (leaking data collected by big brother and then having big brother being very soft on crime is one way to collaborate with evil people), "to scare the nation with their guns and ammunition" (as in the reggae song).
As much as I don't like the cryptocurrency ecosystem, I don't think facilitating and encouraging kidnapping and torture is the way to go.
Shame on the french government.
Two sides of the same coin.
The cryptocurrency ecosystem is used to not only avoid taxation but to enable criminal activity. How many people are being held hostage and the ransom will be payed thanks to cryptocurrencies?
I do not like the cryptocurrency ecosystem either. And I totally agree that it should be abolished. It is just a way to finance crime and terrorism.
However, next week, I started getting calls from other Lycamobile numbers, where it sounded like the same Indian guy, but now he presented himself as a police officer who wanted to arrest my bank account :)
The moral of the story: if you have a phone number, it's been already sold to some shady call center in South-East Asia and it's just a matter of time before they will try to scam you or use your phone for some nefarious purpose. I don't think Lycamobile is unique in how bad their system is and how much they want to extract every last penny from you buy outsourcing every service to foreign companies with zero responsibility and questionable work ethics.
Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods). Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock (a dock for a doc), calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click).
Excuse me?
If you weren't paying with cash whoever paid for the prescription (govt, insurance) has a record of it. The pharmacy that filled the prescription has a record of it as well as the doctor who wrote it.
How can you presume we do not pay with cash?! How can you remotely suppose one sane mind would not use cash for all sensitive private transactions - books, medicines, preferential (profiling) products etc.?
We use cash in general because nobody in Dignity would accept their own daily matters to be recorded and given to multiple untrusted parties¹, not to mention potentially retrievable by even more untrusted parties - of course the matter is much more evident for all transactions over confidential items!
(¹EU here: 12 public-hybrid-private DBs as per the PSD2 legislation.)
Are the elements in your set aware of what they are doing?
And why did you post that replying to mine, what is the message? We knew that you in the cashless are many.
Is it a cry for help - as you know what you are doing but cannot care? Ok: reread the "Book of Joe", which obviously you have heard of, and take your side. Both of them, really: one for morals, one at least for the mentions of the beast requiring its mark for transactions.
Our civilisation needs to face up to the fact the reason is simply: its stored on a connected computer.
Thats the wording of GDPR.. that you should delete data after you dont need it anymore for the original purpose..
Unfortunately, it seems noone is enforcing it enough.
In the US, you can freeze your credit, making this impossible (even for yourself).
> things that are out of your control
That's because of corruption. A system that doesn't want to change because some tits can't be let go of. A well working system would render control back to you.
In this case, the EU does have consequences for data breaches where proper protocols are not followed.
Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.
In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.
In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.
In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.
Abusing privacy is the lucrative norm. The laws won't help you and the government is busy with its corporate agenda.
It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.
What's the big deal, Danes? What do you have to hide?
(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)
And since everyone's name, address and phone number was in the phone book (At least for their city) people didn't find it weird when it popped up online. Sure, to do the same thing for the whole country you'd need dozens of phonebooks for different areas, but it was just the same information.
Which makes me wonder: weren't there phonebooks in US cities and in other countries before? Were they incomplete/opt-in?
The key thing about the Swedish phonebooks were that they were opt-out, so people were basically all in the phone book. So even before the internet, it was just very natural that your name, address and phone number was public. "Getting someone's number" as in moves and TV wasn't a thing. You could just call anyone if you knew their name.
And, importantly, they were physical in a time when it was hard to collect and collate the data in all of them. In 1990, there were about 5,000 distinct "white pages" phone books in the US. And OCR was pretty crappy.
Also, in all the places that I lived, mobile numbers didn't end up in the phone books, only residential landlines did. I don't know if that was universal.
Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.
The owner just thanked me, and said was going to have a chat with the driver. Never saw that car speeding nearby again.
The debt information is there so that when the owner sells the car the buyer can check to see if they actually really do own it outright.
Especially great that you can see what employees at competitors earn, what your peers at your workplace earn and what your boss earns. Become a hell of lot easier to ensure you're not exploited. Helps that Sweden has a really strong union-culture as well.
In a high trust culture I get this. But what about if you're in a low trust culture with quite some "not so orderly behavior" (if you will).
Wait, aren't Sweden like literally the world leader by rapes count?
There is a huge difference in most countries.
Sweden may well be one of the few countries where being raped isn't shameful/your fault for dressing too lightly/punishable by death.
Sounds like someone who needs to lay off the X/twitter feed.
In the US you can get the exact same info and probably more by simply paying a private corporation/middle man (background check services).
It seems like a huge trend in many sectors. We have the same setup as other countries, but shittier for consumers because there are lifeless leaches as middle men to make a quick buck.
Of course, contrary to popular belief, Sweden is not a perfect country without violence and shit people!
It seems to be somewhat respected overall though, but I'm sure it'll eventually disappear. For the people who are stalked and what not, it's relatively easy to apply and get "protected identity" if you're affected by those things, and then eventually all those 3rd party websites remove the stale data.
Personally I solved this problem for myself by moving away from the country.
Quite drastic to move away from a country for just this. Did you only do it for just this? Or was this simply one of the factors why you moved away?
The current system has been in place around 1770. There's some pushback against it the last few years.
The problem with this leak mostly going to be those with hidden addresses or secret phone numbers. Last time something similar happened was when it was shown that you could pretty much just guess a persons social CPR number if you had their birthday. Normally you could narrow it down to 6 or 8 possible numbers then use the phone companies websites, pretend to create a new account, enter the CPR number and check if you guessed correctly. Because the demo was done with politicians, then phone companies no longer ask for CPR upfront.
I feel like this should be the default. Responsible disclosure to the affected company, followed immediately by disclosure to every politician in the dataset. Once we start collecting high profile cases this way instead of waiting X days for a faceless corporation to release a fix, companies will think twice about their security and the data they collect if that could make them end up on the shit list of the local government.
The autorities do not, and the guy who "leaked" the CPR number of Mette Frederiksen was thrown in jail.
On an unrelated note, I recently read about voyage of the Mayflower across the Atlantic. It's a captivating piece of history.
it's a real cost, and a real benefit. I guess values vary on which is more important.
Overall the benefits for employees seems way broader than the benefits for the companies.
On a purely economic basis, wage transparency primarily benefits employers because it reduces how much they need to pay based on actual performance in practice.
Why would transparency reduce how much employers have to pay? Usually capitalists would make the opposite claim, by keeping salaries opaque, it's much easier for employers to underpay people, but you seemingly are making the opposite claim.
If I can see how much my employer pay others, doesn't that help me ensure I too get fairly compensated from the employer? How could the employer leverage this situation to pay me less than I already know I'm worth?
When wages are opaque, an employee only needs to justify their worth to the employer. Employers pay for value net of wages, so they are often happy to pay someone much more if the individual value generated justifies it. When wages are transparent, an employee needs to justify their worth to everyone else because a higher wage is tacitly reducing their wage. This creates social pressure separate from the economic argument.
Other employees are incentivized to maximize their own wages regardless if it maximizes value for the employer. And there are many more average employees than high performers. Employers can leverage this social pressure to cram down the wages of anyone who wants to be paid above average because they no longer have to defend a lower wage on a purely economic basis. Empirically, this is what happens.
Anecdotally, I've seen this play out countless times at companies.
Then your salary will be decided by lowest common denominator. Employer does not leverage this situation, employer reacts to the incentives this situation creating.
Why would it? That's not what happens in practice, and you have raw data to point at, with things like "Person A is half a fast as me, and earns X, that's why I deserve X+N", not sure why you think there would be another outcome here, and it's clear you've never experienced this sort of environment yourself.
You haven't sufficiently manage to enter the mindset of a Swede. Your salary information isn't "your data" in the first place, it's public information. The company is selling public information if you have this mindset, does it still make sense to make it illegal then?
I think what you want to argue for, is for salary information to not be public data anymore. Selling people's private data without authorization (or even handling it incorrectly) is already illegal and actively punished today when it happens, via the long and slow arm of the law.
That is not an opinion. That is a fact. It's not public information, and anyone arguing that is categorically, provably, wrong.
The entire country of Sweden can collectively come together and decide that 1+1=3, and I would give that about as much thought as these semantic games around private and personal data.
1. Everyone(1) shall be entitled to have free access to official documents.
2. Official documents are all(2) documents held and produced by the authorities.
(1)=Everyone includes everyone in the world, you do not have to live in Sweden or be a citizen and you do not have to identify yourself.
(2)=Some restrictions apply (natsec, medical, etc).
In short, most government databases are databases of "official documents", including the citizenship registry maintained by the tax authorities.
Downside: All the mundane information about you is public property; address, birthdate, tax records, school grades, drivers license, passport photograph, martial status, court cases and pretty much everything else you can't think of.
Upside: Applies to all politicians as well.
What is and isn't personal data is subjective, regardless what "truth" you believe you're sitting on. I won't claim you're right/wrong as there is no such concept for subjective things, I suggest if you want to understand instead of wave your hands around or whatever you're doing, you'd try to see things from another's perspective and forgo dogmas.
Ontological games are just that - games. Personal and public data is not an opinion, and it's not subjective.
I legitimately think that it's harder to have a coherent definition of a chair than to define personally-identifying vs anonymous data, and pretending otherwise is stupid.
Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.
Don't hold your breath.
- Social security number
- Age
- Sex
- Family relations
- Physical address
- Protected addresses
- Sex change
This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.
AFAIK those with protected addresses has not had their address compromised. But ID and name still is.
And with the rest exposed it is now trivial to see what adresses are "interesting".
I did it accidentally during my last move and it was a pain in the behind
And it expires after a year by default so it feels rather pointless
EDIT: I didn't redact anything from the lookup, this is the exact data I received.
I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.
Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.
There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.
Then again, in my country some municipalities handed out numbers starting with your birth year....
Gender is encoded in the CPR number.
There is some interesting details that may require you to change your name, if you want the last digit changed. That means if you're name is Kurt, you can't have a CPR number ending in an even number, because Kurt is only an approved name for men. If your name is Kim, Storm, Charlie, Orla, Lykke or some other unisex name it's not a problem.
But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned.
Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data.
But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future.
Nothing.
Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure.
Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?
My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.
I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.
That being said it's not like us being shit at cyber security doesn't mean other countries aren't also shit. Look at Australia getting hacked by AI. I know it's all the rage to blame OpenAI, but really, shouldn't Australia count itself fortunate it wasn't an enemy nation state? Or that their lacking security got exposed before it was.
As far as Randers cyber security goes. I imagine it'd be "fun" to do an right of access to documents, on the amount of unique visits their Microsoft Defender has registered to chatgpt.com and claude.ai.
There are things I wish I could change in Denmark, mainly the power sockets and number system (Base 20 what the heck?) but Denmark is on a good course when it comes to IT understanding. Both the broader society and government implementations.
Yes yes, Estonia is better. But Denmark is still doing good.
As all security professionals know, people dont care about security, until they are hurt, and often even after that. Lost privacy doesnt hurt if you dont think too much about it.
What we are also seeing is that governments/administrations dont care about security (with exceptions). They really want to go ahead in the digitalization dimension, but not so much in the security dimension.
Feel. Having lived in Denmark and Germany. And working for the public sector.
MitID is just chefs kiss how many other countries can you log in to your bank, student loan, and local municipality with the same sso. Country wide app for local transportation tickets of different types. EPJ / Elektronisk Patient Journal has it's fault, but compared to other countries[2] yet again not that bad.
Shit man, even something simple has going to the doctor for blood tests. I think you can get the results on the same day via app. Maybe next day. In Germany[1] you have to wait a few days, then the Dr. calls you with the results and then you can ask him if he can mail it to you.
What in Denmark actually requires you to get physically to the municipality? Weddings? Even divorces work online. Compare that to Germany, Austria, Italy etc.
Why do you think Denmark is not one of the leading countries in digitalization?
Edit: Just looked at some real benchmarks. One from EU where they put DK at 7th out of EU27 https://composite-indicators.jrc.ec.europa.eu/explorer/indic... And one UN E-Government Survey from 2024 where they rank first. https://publicadministration.un.org/egovkb/en-us/Reports/UN-... (I just looked at an overview)I can't say how accurate these lists are. But they match my observations. Nordics lead.
Ah - there we go..
Meanwhile living in Denmark we are not even able to get results for blood panels from our 14 year old daughter cause "the system was not made for it". You know I'd much rather have it in the mail than not at all.
Even so, we tried to get a MitID for her so hopefully she could log in to see them. How do we do that you ask? Meet up physically. Did they fuck it up the first time? Sure, but luckily only a week later we were able to get a time hoping we'd now be able to get access to her blood panels. Nope. Logging in with her MitID says she is not old enough to see her blood panels. How long has it been like this? More than 5 years.. But luckily a law was passed in 2023 to do something about it.. Has it happened yet? No, but it doesn't matter.. She'll be 15 before it's implemented anyway.
I could go on with similar stories from almost every system I have to touch in Denmark.
That said, compared to other countries the tax / SKAT is also quite decent.
So essentially the whole population's data has leaked. Furthermore, the notice says mv, which is abbreviation for etc. So it says "name, address, cvr number" etc.
That etc. is funny because the Danish government has a thing called NemID which you use to log into pretty much any online service, including banking, and you can install it on your phone, and when you lose it though you can verify by calling up and giving personal information to verify it is you.
Now there are a bunch of things about this system that are contemptibly stupid and annoying that I won't go into here because of my blood pressure. But now I wonder if the mv. of the personal data covers stuff you could conceivably be using to get a new NemID.
on edit: the really young have not had their data leaked, probably, and the excess of course covers people who used to live in Denmark and left.
Imagine a foreign state-sponsored agent waiting at the door of a public or private decision-maker, convincing them to cooperate. Home addresses are no joke. Especially if you can grep through the whole family tree.
The German Melderegisters, for example, are now far more interested in the stated reason for your data request than they were ten years ago. (Which is a good thing!)
Many things that are trivial in theory, given the right conditions, etc. are anything but trivial once you actually try to do it.
https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
[1] https://www.dtu.dk/english/newsarchive/2026/10/cyberattack-o...
We'll have to start treating the CPR number as just a username, instead of a password. It should never have been "secret" in the first place.
Any agree, it should be only a username and MitID is the verifier(password) and without both, it should simply be impossible to create any kind of binding contracts like loans etc. anything else is simply sloppy policy from the government. but again no politician understands IT, neither does the majority in EU about the implications of chat control...
It will take a whole new approach to confidential information to really make a difference. I think we need to go the SSI way, and I think at some point we will.
- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)
- in France (from tax office), 678k people affected
With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
I wonder if company used some kind of automation that decided it needs all CPRs for whatever it was doing.
Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.
As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.
Anything else like banking or anything official requires a MitID authentication, and no one malicious can just e.g. open a bank account in my name. They’d have to go through several authentication confirmations usually.
Are there other areas where we are lax about CPR still?
Like Google and Apple?
"and countless examples of making it worse."
Which would those be? I would be interested to know.
Yes, like Google and Apple. If you would take a look at my submission history, you'll see exactly one. It was me celebrating the passing of the Digital Markets Act more than four years ago. This Act clearly lays out requirements for gatekeepers like Apple. I summarise these requirements in a comment in the submission:
* Install any software
* Install any App Store and choose to make it default
* Use third party payment providers and choose to make them default
* Use any voice assistant and choose to make it default
* User any browser and browser engine and choose to make it default
* Use any messaging app and choose to make it default
* Make core messaging functionality interoperable. They lay out concrete examples like file transfer
* Use existing hardware and software features without competitive prejudice. E.g. NFC
* Not preference their services. This includes CTAs in settings to encourage users to subscribe to Gatekeeper services, and ranking their own services above others in selection and advertising portals
To date, Apple has implemented only a handful of these, and they have done so with malicious intent. For example, they have made the creation and distribution of third party app stores to onerous that very few companies have navigated the gauntlet and actually used it. Third party browser engines are now technically supported, but so poorly that not even Google has endeavoured to create an iOS browser engine. The worst example is app distribution. The DMA requires gatekeepers to facilitate free distribution. Apple has failed to cmoply with this for four years, and has repeatedly appealed when admonished. The Commission has been sitting on their most recent "review" for over a year now, without any updates.
The net result of all of this is that Apple has retained almost all of their duopolistic market power, and has implemented almost none of the DMA requirements. They have given us the middle finger and our legislators have gone to sleep.
> Which would those be? I would be interested to know.
I'll give you me perspective as a Danish citizen.
The EU imposed working-time recording requirements, so now I have to log my working hours every week. I'm a full time employee and I work longer and shorter weeks. Now I have to waste time each week logging my hours. My company has to waste time each week logging hours and reporting them to the government and the EU.
The EU required bottle caps to remain attached to most plastic drinks containers, so now I have to wrestle with an attached cap every time I drink from one.
The EU banned ordinary disposable plastic cutlery, plates and straws, removing products I previously had the choice to buy.
The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners.
The EU introduced "Strong Customer Authentication" requirements, so routine online payments and banking increasingly require additional authentication steps.
The EU abolished the €22 VAT exemption on low-value imports, making even tiny purchases from outside the EU subject to VAT. This one in particular sucks because the company or local tax authorities impose huge minimum fees, making small cross-border purchases far too expensive now.
The EU imposed expanded producer-responsibility rules on packaging, adding recycling fees, reporting requirements and compliance costs that ultimately feed into the prices I pay.
The EU passed even more extensive packaging regulations covering recyclability, recycled content, packaging minimisation and reuse, adding another layer of costs and restrictions to ordinary products.
The EU imposed increasingly strict CO2 targets on car manufacturers, financially penalising manufacturers whose fleets exceed them and increasing the pressure to make petrol and diesel cars more expensive or stop selling them.
The EU created ETS2, which from 2028 will add a carbon price to road fuels and home heating, creating another cost that fuel and energy suppliers can pass on to me.
The EU imposed sustainable aviation fuel mandates and tighter carbon rules on airlines, increasing the regulatory cost of flying.
The EU brought shipping into its carbon-pricing system and introduced FuelEU Maritime, leading shipping companies to add explicit EU environmental surcharges that feed into the cost of goods I buy.
The EU imposed Ecodesign restrictions on appliances, including maximum power limits for products such as vacuum cleaners, reducing the range of products I am allowed to buy.
The EU passed a minimum-wage directive despite Denmark already having its own collective-bargaining model, forcing Denmark to fight the EU in court to protect a labour-market system that was already working without a statutory minimum wage.
Because it was abused by countless vendors that just wrote a random value below 22 Euros on the label no matter how much it cost.
> The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners
Not sure why you're blaming the messenger. Either way this can be solved by installing a browser plugin.
The EU being the EU, it's those criticizing the leak by governments of public data that are going to be sent to jail.
If this is a general trend in the EU, what people went to jail for criticizing the leaks?
CPR is the administrator. There is more information in the linked press release from the ministry:
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.
The only current english language sources are paywalled:
https://www.thelocal.dk/20261005/hackers-get-personal-info-o...
https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...
Non-paywalled but major danish news outlet (National Brodcaster):
https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...
Will Danes be compensated for the hassle, this causes them? (Probably not)
Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)
I do not think we will ever go back to the wild west, but it is also hard to think a future that follows this very tendency.
Before we had natural disasters to worry about and now we have those + cyber ones.
[0] https://www.dst.dk/en/Statistik/emner/borgere/befolkning/bef...
[0] https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
The 2FA verification system in place now has not had any reported breaches but is nevertheless an absolute joke. I use GrapheneOS on my personal phone which cannot use the government 2FA due to the arbitrary Android integrity API. I therefore use my old phone on which it works perfectly. The catch is that it hasn't been updated in over three years lol.
When the ministry responsible for the 2FA system was asked to allow it to be run on degoogled OSes, they refused saying it would be too costly to develop for "other systems". The responsible authority doesn't even know degoogled Android is still Android. And you expect these people to protect your private information and health records.
It was also leaked some time back that the Danish government let the NSA spy on every citizen in the country for literally nothing in return. Unconstitutional? Yes.
Yeah, it's probably easy to bypass too, if they are not actively maintaining it there are definitely holes in the system.
I think bad and expensive government software systems are a global norm, still the Danish system is more private than the Swedish where all it takes is a name and everyone's home address can be searched for.
https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
Not long now before people get extorted for correction of doctored leaked sensitive personal details.
Basically any company can access to an API that lets you look up CPR(~SSN) numbers, and a lot of companies have access.
What has most likely happened is such an integration has been abused - we do not yet know whether it's by mistake or by some malicious third party. It wouldn't surprise me in the slightest if this is just the result of someone's Claude agent telling them that they can improve lookup times if they just enumerate every CPR number and cache them, for example - but we don't know yet.
Of course, Russia is being blamed twice for this data breach in the comments.
I am not disappointed.
But this is incredibly bad.
It really is a nothing burger this data has been leak multiple times, and is easy for any bad actor to get their hands on at any time should they need to.
But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.
This will be easy to exploit on a scale.
Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.
public servant engineers are token poor and will be out of the latest defense tools