logoalt Hacker News

ano-ther • today at 10:42 AM • 3 replies • view on HN

So it was actually two weaknesses:

* The non-password at a two-person IT company (Pays ApS)

* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).


Replies

mrweasel • today at 12:23 PM

The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.

Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.

The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.

tuwtuwtuwtuw • today at 10:56 AM

There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.

➕ show 3 replies
zerot-security • today at 1:45 PM

[flagged]