`123456' password used in Danish CPR data breach

(cphpost.dk)

62 points | by baal80spam 55 minutes ago

16 comments

  • zkmon 10 minutes ago
    I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

    It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

    • ano-ther 1 minute ago
      With two people in the company, there is not a lot of room for corporate games though.

      > According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

  • zweifuss 28 minutes ago
    I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
    • sethammons 24 minutes ago
      What would that accountability look like?
      • gunalx 21 minutes ago
        Not existing preferably.
        • tossandthrow 6 minutes ago
          This is the likely outcome. It was a company employing 2 people.
        • tannertech 16 minutes ago
          Strange way to say prison time. Or if you meant capital punishment harsh but fair.
      • lifestyleguru 12 minutes ago
        Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
  • sokols 14 minutes ago
    I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
    • zweifuss 9 minutes ago
      A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
    • iLoveOncall 11 minutes ago
      Or simply make people who choose insecure passwords criminally responsible for the fallout.
  • ano-ther 5 minutes ago
    So it was actually two weaknesses:

    * The non-password at a two-person IT company (Pays ApS)

    * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).

  • piker 33 minutes ago
    That’s the same combination I have on my luggage!
  • mattlondon 8 minutes ago
    If only they had insisted on an 8 character password!
    • LarsKrimi 0 minutes ago
      There are some unconfirmed rumors going that the maximum password length for the API was 8 characters...
    • fifilura 6 minutes ago
      1Password#

      Oops, can I delete my comment, it was a copy paste mistake!

      • lifestyleguru 1 minute ago
        > *****

        > Oops, can I delete my comment, it was a copy paste mistake!

        What do you mean? You can safely post you passwords on the internet.

  • donalhunt 33 minutes ago
    In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.

    Equivalent to social security information in the US I guess.

    • lordnacho 19 minutes ago
      It's unique, but it encodes your birthday and sex.

      There's only 500 numbers it could be, assuming someone knows those other things about you.

      In any case, there are alternative systems for authorisation.

      • usrnm 10 minutes ago
        You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
        • piva00 8 minutes ago
          It's Denmark, it won't have 1k babies born the same day.

          It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.

        • tannertech 7 minutes ago
          That's a problem for future Denmark!
  • INTPenis 33 minutes ago
    I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!

    Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

  • sneak 24 minutes ago
    The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
    • LarsKrimi 20 minutes ago
      Privatization

      It was run by DXC Technology, the Danish branch of a US software house.

      When doing a contract on such programs the Danish government must take the cheapest offer by rule

  • croes 13 minutes ago
    Did they have MFA?
  • imdsm 33 minutes ago
    not ideal
  • tokai 18 minutes ago
    Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
    • GuestFAUniverse 10 minutes ago
      Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.

      Since then I think medical data science is mainly a waste of tax payer's money.

  • lifestyleguru 30 minutes ago
    For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
  • m00dy 32 minutes ago
    lol, it's a joke right ?