I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
Real world, as you say, not so simple. Everything has to deal with certain degree of forecastable nonsense, e.g. a bridge has to cope not only with traffic and winds, but the possibility that someone will be drunk in charge of a ship and crash into it.
> AI is built on human knowledge so guess what it will keep doing.
Yes, and also brings its own additional mess on top of that. All machine learning takes a huge number of examples to get good, so an LLM isn't just "read all the online courses in how to run a business", but also likely has 50 business versions of the recent demonstration of common sense failure with "I live 100m from a car wash, should I walk or drive?"
> How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
Many such disciplines. Perhaps all except maths and computer science? Or even including maths and computer science, given stats is part of maths and even compsci has to deal with fault tolerance.
That’d be engineering.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
... said every "security" pedlar ever.
Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
But it doesn't say which password manager.
The most popular password manager is some text/word/excel document on the desktop.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.
My local all-eggs basket vendor agrees 100%.
Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?
Even if we take your silly example you clearly intend as a gotcha:
>For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.
Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.
... right up to the moment when they aren't.
I like to think of a law of conservation of productivity.
Before: yours 100%, hacker's 0%.
After: yours 0%, hacker's 100%.
Nonsense, of course. Hacker's boost is nearer 100,000%.
Fact is, modern computer power is inherently far more productive for bad than good. And the economic incentive follows.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
I doubt the CPR number alone will give you access to obtain credit and the like today, but you can absolutely go into a pharmacy and buy someone’s prescription medicine with just their CPR number, and you for sure can get access to a lot of data by calling various entities and providing your CPR number as proof of identity (but at least fewer now than used to be the case in the past).
If the CPR number was truly made public information, those cases would be much more obviously wrong. The fact that CPR numbers are de facto considered pseudo-secret makes things much worse.
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
The CPR alone is used for casual identification.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
However Im sad that now our national password is out :(
So the password could have been 32 alphanumerics with special characters and there still would have been a breach.
The password was not the problem here.
The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.
Oops, can I delete my comment, it was a copy paste mistake!
> Oops, can I delete my comment, it was a copy paste mistake!
What do you mean? You can safely post your passwords on the internet.
Equivalent to social security information in the US I guess.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.
edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.
It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.
Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.
Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
It was run by DXC Technology, the Danish branch of a US software house.
When doing a contract on such programs the Danish government must take the cheapest offer by rule
Since then I think medical data science is mainly a waste of tax payer's money.