Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
show comments
zkmon
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
show comments
ano-ther
So it was actually two weaknesses:
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
show comments
piker
That’s the same combination I have on my luggage!
show comments
ptnpzwqd
It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
show comments
mr_mitm
Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
show comments
mhd
They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
show comments
sokols
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
show comments
mvkel
> According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company.
So the password could have been 32 alphanumerics with special characters and there still would have been a breach.
The password was not the problem here.
show comments
zweifuss
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
show comments
n0rdy
Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`.
If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`.
If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
show comments
verelo
Personal pet peeve undefined acronyms, "CPR": Central Person Register. For those who didn't know, like me, and had to look it up.
show comments
bazoom42
Something is fishy about this story though. The credentials used was allegedly leaked and purchased on the black market. But the it doesn’t matter how weak or strong the password is.
The information about the leaked password is from the guy claiming to be the hacker who anonymously talked to the media.
wrecked_em
That's the kind of password an idiot would have on his luggage.
mattlondon
If only they had insisted on a secure 8 character password!
show comments
eviks
Yes, S in Government stands for Security, C - for Competence (or caring about your data), and D - for system Design
rr808
At this stage all SSN, NI numbers, CPR etc should just be made public. Its assuming its some kind of secret is the problem. Its an ID not a password.
show comments
howard941
It flows nicely on the numeric pad
skc
We really missed a trick by not normalising the term passphrase.
WaitWaitWha
Beyond the weaknesses already mentioned, why did the system allow such weak passwords in the first place?
donalhunt
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.
Equivalent to social security information in the US I guess.
show comments
INTPenis
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
throw5976543f
Is this cultural?
When things like this happen in Asian countries, you always see a lot of people here comment about how “the culture” contributed to it.
So I’m wondering if there are any experts here who can explain if this is cultural too?
nashashmi
Well, if you change to many settings, it will break. So don’t change anything. So it doesn’t break.
largbae
That's the stupidest combination I ever heard in my life! The kind of thing an idiot would have on his luggage!
1970-01-01
Not using 2FA on the admin account is the real crime.
jester997
I guess I should change my password.
caaqil
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
lifestyleguru
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
jtrn
If only they had used "12345678"!
krabat
Denmark comes from a long line of institutional trust: We say we do this, so we do it, so everyone else will naturally expect that.
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
Hizonner
The first major violation of obvious security practices was having a registry like that in the first place.
The second was giving out access to "companies and associations" that might have "legitimate needs".
THEN we get to morons using passwords like that.
imdsm
not ideal
show comments
croes
Did they have MFA?
show comments
sneak
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
show comments
markm248
Always add a !
xoshbin
honestly you'd think by 2026 they would at least force a special char so the password becomes 123456!. im not even suprised anymore tbh, just disapointed.
0xbadcafebee
Literally nothing will prevent this but software building codes and enforcement. That's why we have building codes. We let builders do whatever they wanted for decades and it ended in disaster, so we stopped letting safety be optional.
shevy-java
That's my password!!!
Thieves give it back now!
show comments
ZuoCen_Liu
Please enter Password:
Password
↵
The password is incorrect:
incorrect
↵
Incorrect password, please enter again:
Again
↵
...
tokai
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
show comments
27183
hey that's my password too!
nslindtner
Another fact - was only discovered because the invoice for using the lookup was big
bricss
If only there was an algorithm for password strength estimation > . <
Zardoz84
Spaceballs CPR
redanddead
Oh my fucking god
m00dy
lol, it's a joke right ?
show comments
aussieguy1234
They forgot to write it on a post-it note attached to the monitor /s
Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
So it was actually two weaknesses:
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
That’s the same combination I have on my luggage!
It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
> According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company.
So the password could have been 32 alphanumerics with special characters and there still would have been a breach.
The password was not the problem here.
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
Unfortunately, the humans' laziness (or lack of long-term thinking) was, is and will be a bottleneck.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`. If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`. If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
Personal pet peeve undefined acronyms, "CPR": Central Person Register. For those who didn't know, like me, and had to look it up.
Something is fishy about this story though. The credentials used was allegedly leaked and purchased on the black market. But the it doesn’t matter how weak or strong the password is.
The information about the leaked password is from the guy claiming to be the hacker who anonymously talked to the media.
That's the kind of password an idiot would have on his luggage.
If only they had insisted on a secure 8 character password!
Yes, S in Government stands for Security, C - for Competence (or caring about your data), and D - for system Design
At this stage all SSN, NI numbers, CPR etc should just be made public. Its assuming its some kind of secret is the problem. Its an ID not a password.
It flows nicely on the numeric pad
We really missed a trick by not normalising the term passphrase.
Beyond the weaknesses already mentioned, why did the system allow such weak passwords in the first place?
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.
Equivalent to social security information in the US I guess.
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
Is this cultural?
When things like this happen in Asian countries, you always see a lot of people here comment about how “the culture” contributed to it.
So I’m wondering if there are any experts here who can explain if this is cultural too?
Well, if you change to many settings, it will break. So don’t change anything. So it doesn’t break.
That's the stupidest combination I ever heard in my life! The kind of thing an idiot would have on his luggage!
Not using 2FA on the admin account is the real crime.
I guess I should change my password.
It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
If only they had used "12345678"!
Denmark comes from a long line of institutional trust: We say we do this, so we do it, so everyone else will naturally expect that.
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
The first major violation of obvious security practices was having a registry like that in the first place.
The second was giving out access to "companies and associations" that might have "legitimate needs".
THEN we get to morons using passwords like that.
not ideal
Did they have MFA?
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
Always add a !
honestly you'd think by 2026 they would at least force a special char so the password becomes 123456!. im not even suprised anymore tbh, just disapointed.
Literally nothing will prevent this but software building codes and enforcement. That's why we have building codes. We let builders do whatever they wanted for decades and it ended in disaster, so we stopped letting safety be optional.
That's my password!!!
Thieves give it back now!
Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
hey that's my password too!
Another fact - was only discovered because the invoice for using the lookup was big
If only there was an algorithm for password strength estimation > . <
Spaceballs CPR
Oh my fucking god
lol, it's a joke right ?
They forgot to write it on a post-it note attached to the monitor /s