logoalt Hacker News

ptnpzwqd • today at 11:08 AM • 1 reply • view on HN

It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.

Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.


Replies

boxed • today at 11:35 AM

> Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong

That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.

➕ show 1 reply