A Swedish citizen database is... you know. fun. But not exactly hard to get hold of.
[1] https://www.statenspersonadressregister.se/master/start/engl...
Scandinavian countries are extremely open and transparent in a way that might be shocking for Americans. For example, in Norway, I can check nearly anyone's brokerage account holdings, addresses, phone numbers, etc. on public websites. I can in theory look up anyone's tax filings.
Personal identification numbers do not tend to be considered private in the same way that social security numbers in the US are.
They'd say that if you earn a lot, you shouldn't take a cheap housing.
Any truth to that?
Nowadays I think mostly journalists use it to pull up information about politicians and other people that are in the public spotlight. There are of course the yearly "richest people in Norway" lists in various categories.
Media is also allowed to pull "top" lists like the 100 people with the most income in a city, 100 people with the most wealth in a city, etc.
There's also the underlying current of Jantelagen (Law of Jante) https://en.wikipedia.org/wiki/Law_of_Jante
There are so many ways to misuse these data. Are the residents not concerned about this?
Businesses in Scandinavia and many other countries would not treat someone knowing your personal information as any evidence of identity (because it's not); having all that information is not sufficient to impersonate you there - identity theft does happen but it would require stealing or forging physical documents or actual credentials to things like bank accounts; knowing all of what your mother or spouse would know is not enough to e.g. get credit or get valuable goods in your name.
By just accepting it as a normal fact of life that you will have some random stuff ordered in your name sooner or later with an invoice you'll have to dispute. Happened to a relative of mine, police do not care unless they order things above a certain value, without a police report you cannot get free ID protection, and then you'll have to sit for a long time in phone queues trying to cancel a subscription for a streaming service or whatever they ordered while get thrown around by support reps who go "you SURE you or someone in your family didn't order this?"
But they didn't change it, because "women should be able to look up the men that they date".
Last update I heard about something being done about it was this:
https://www.regeringen.se/pressmeddelanden/2024/11/utredning...
Not sure what the current status is.
They are absolutely trivial to get. One click on mrkoll.se.
But that seems like a completely different thing than a nefarious and anonymous person or group having access to the entire database.
Basically: obviously it's not desirable to have that full database in the hands of a malicious actor but I'm not sure it's such a big deal either. Again, it's public data by design.
[1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...
[2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...
> citizen PII databases and electronic signing documents were also collected but are being sold separately
And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.
Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible
That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.
> Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize
https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...
No. CGI has nothing to do with BankID.
IMO the most credible reports suggest that the source code and data involved are related to these four services:
https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Mina engagemang offers a user-friendly and flexible solution that allows your customers to manage their cases directly through a personal portal. Here, users can view, track, and interact with their ongoing cases, which enhances both transparency and efficiency in the communication process." -- some kind of ticket/case management system for gov't agencies
https://www.cgi.com/se/sv/business-process-services/elektron... "With our secure end-to-end e-ID and eSign services, we can help you streamline document and contract management, gain access to all desired e-ID issuers, and improve cost efficiency." -- this sounds like a bad thing to compromise, but is to the best of my understanding a system for digital signatures on documents, and has no relation to BankID
https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Gain better control over your organization’s representatives with our easy-to-use representative registry. By automating the identification and verification of representatives, you’ll gain a clear overview and enhance the security of your processes." -- sounds like some bullshit CRUD app for managing who can "represent" a gov't agency
https://www.cgi.com/se/sv/business-process-services/e-tjanst... "SHS is Sweden’s common standard for information exchange, enabling secure and efficient communication between government agencies, businesses, and organizations." -- this might be bad if real data was leaked
These are services used by various Swedish government agencies and it's pretty bad to have even a test instance of them hacked, but let's calm down. The entire Swedish state has not been compromised here.
That's incorrect. Skatteverket used CGI for BankID-login, I don't know if they still do. I have personal experience working on a BankID-login using CGI for another company and it is still active.
Edit: I just confirmed Skatteverket still uses CGI for BankID-auth. "funktionstjanster" is CGI.
Skatteverket, the Swedish tax authority, has been quoted in media as confirming that they use CGI's system for digital document signing but that none of their data nor that of any citizens has been leaked.
https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...
"One of the government agencies that uses CGI’s services is the Swedish Tax Agency, which was notified of the incident by the company. However, according to the Swedish Tax Agency, its users have nothing to worry about.
“Neither our data nor our users’ data has been leaked. It is a service we use for e-signatures that has been affected, but there is no data from us or our users there,” says Peder Sjölander, IT Director at the Swedish Tax Agency."
Because in that case they can sign documents on my behalf without my permission. In a court case, it would be near impossible for me to prove that the government gave my private key to someone else and that it wasn't me signing an incriminating document.
I'm familiar with electronic signatures, and I know what documents are, but I have never heard the phrase "electronic signing documents" and don't know what that is supposed to mean. What kind of documents? Documents about signing, documents that were signed, documents in the sense that files containing keys could be considered documents, or what?
You use the card reader, insert your gov-issued identification and can sign PDF papers which have legal validity since the private key from the citizen card was used.
Now imagine someone signing random legal documents with your ID for things like debts, opening companies or subscritions to whatever.
Currently most Swede's use a private bank consortisum controlled ID solution for most logins and signatures.
https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...
– Neither our data nor our users' data has been leaked. It is a service we use for e-signatures that has been affected, but there is no data from us or our users there, says
The information that source code was leaked from a joint government e-platform is not true, according to Peder Sjölander.
– There is no such platform. I think the perpetrators in this want people to feel insecure. We feel confident that our data is safe and we have the situation under control before the tax return period opens next week.
[1] https://flashism.wordpress.com/2010/03/09/swedish-armed-forc...
P.S.: And strangers will sometimes help you find vulnerabilities (and sometimes be very obnoxious but that's not open source's fault).
Government / handles society-critical things code should really be public unless there are _really_ good reasons for it not to be, where those reasons are never "we're just not very good at what we're doing and we don't want anyone to find out".
It's very hard to steal everyone's documents when they weight about the same as a train.
Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?
"Fireproof file rooms and cabinets in the 1920s were crucial for protecting business and government records during the rapid expansion of the industrial era. The era saw a massive shift from flammable wooden office furniture to robust, steel-based storage designed to resist both fire and water damage."
That's a Google AI summary - but I've been in a fair number of buildings with such rooms. Thick concrete walls, heavy steel fire doors, no other openings, nothing but steel file cabinets in 'em, sealed electric light fixtures that look like they belong in a powder magazine (where one spark could kill everyone) - it's really simple tech.
And "high ground" was a reliable flood protection tech several centuries before that.
We have several historic examples of records being lost in disasters, and way more recent than 100 years ago.
https://en.wikipedia.org/wiki/National_Personnel_Records_Cen...
It makes no difference that we could’ve prevented that with better building construction. We didn’t, and hindsight does not bring the records back. We should plan for the world we want but cannot ignore the world we have.
I’m not defending digital as always better or criticising physical. Like I said, different tradeoffs, meaning there are advantages and disadvantages to both, there’s no solution which is better in all situations.
I am not saying that paper is magically perfect. Nor better in every situation. I am saying that paper is far easier (than digital) to do well for use cases like a national records collection. "Correctly" may include off-site backups - whether or not your threat model includes massive earthquakes, volcanoes, bombs, special forces, EMP weapons, biological agents, civil war, radioactive fallout, or enemy occupation. Or "Management wouldn't pay for a done-right facility".
As I noted in another comment, the largest downside to paper (within such use cases), is that it is far more difficult to get political support for old-fashioned stuff that just works, compared to anything that can be sold as cool/new/high-tech. Especially when the taxpayer-funded revenue streams from selling/installing/supporting the tech create incentives clearly contrary to the taxpaper's long-term interests.
Several government organisations / regional authorities and companies were down. Last I heard several medical journals for whole municipalities were just destroyed.
Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity, are suspicious of things like zero-trust, follow outdated engineering practices. Sigh.
So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the tender) or a region (Europe) if there is no obvious alternative.
You have to have people who care about this stuff.
If you don't care, the rest does not matter. It does not matter if, when and how you outsource if you don't care about the outcome. You can't just pay someone a salary, nor a consulting bill, check the box and say you've done your part.
And the other way around: These huge consulting conglomerates would get very few jobs if purchasers cared about the details, and not just that all the boxes are checked.
What?! Preposterous! How could you even make money out of that? No no no, that will not do. You will ask your AI agent some vague question, commit the result without review and push it to the client. And you’ll like it. If there’s any trouble, call Timothy, he’ll be on vacation with his family in Thailand. Some resort, “Lotus” something or other.
The tender process + clueless buyers + tender process law(s) cause this. Whole process needs a revamp for this to not be a problem.
Accountability now, send these people to prison
Who will take responsibility and get fired and lose all pension etc.? Oh wait no one.
Well the citizens need to suck it up.
Edit, i checked the facts: The Bulgarian government said that the it should pay too much to itself, and appealed the fine for few years until it somehow expired. And the guy (20 year at that time) they accused was later acquitted after they tried to ruin his life.