43 votes

Denmark government hack leaked 8.7 million citizen's ID's: the password was "123456"

12 comments

  1. smoontjes
    Link
    Article in Danish, some translated snippets: The company also didn't use 2FA, and login page for their access was publicly available: article link. The many troubling things a Danish CPR number...

    Article in Danish, some translated snippets:

    A small Danish software company on Funen, which markets itself as "top-notch data protection", is at the center of the largest leak of Danes' CPR numbers and addresses in Danish history.

    The company had legal access to the CPR register, which is what has been compromised.

    DR's research shows that one of the passwords used by the company was part of another leak [...] it was simple and easy to decipher: "123456".

    Ultimately, it is the authorities who are responsible for ensuring that companies with access to the CPR register meet a sufficient level of security. The National Unit for Serious Crime is investigating the case. They had no comment. There are currently no charges in the case.

    The company also didn't use 2FA, and login page for their access was publicly available: article link.

    The many troubling things a Danish CPR number (ID) can be used for include counterfeit, phising, scamming, obtaining even more personal information on you, even taking out loans: article link

    Previous thread: link

    22 votes
  2. [4]
    lostwax
    Link
    Spaceballs_password_scene.gif This has been a well known joke since the mid 80s, come on guys.

    Spaceballs_password_scene.gif

    This has been a well known joke since the mid 80s, come on guys.

    15 votes
    1. Akir
      Link Parent
      I know, I had the exact same urge to say that I have the same combination on my luggage.

      I know, I had the exact same urge to say that I have the same combination on my luggage.

      6 votes
    2. [2]
      Minori
      Link Parent
      My work password includes 123 to satisfy the number requirement because it's easy to quickly type...

      My work password includes 123 to satisfy the number requirement because it's easy to quickly type...

      1 vote
      1. Asinine
        Link Parent
        It's easy to incorporate things like this into a good password though. Also my [current] work password includes 123 too...

        It's easy to incorporate things like this into a good password though. Also my [current] work password includes 123 too...

        1 vote
  3. [2]
    Protected
    Link
    I just need to remind everyone that the danish presidency of the Council of the EU were the ones that reintroduced Chat Control last year (on their very first day).

    I just need to remind everyone that the danish presidency of the Council of the EU were the ones that reintroduced Chat Control last year (on their very first day).

    14 votes
    1. Knockout_Mouse
      Link Parent
      I had to google Chat Control because I hadn't heard of it before. Thanks... I hate it. This isn't going to protect any children from pedophiles, it's just going to make it a thousand times harder...

      I had to google Chat Control because I hadn't heard of it before.

      Thanks... I hate it. This isn't going to protect any children from pedophiles, it's just going to make it a thousand times harder for law enforcement to do their jobs.

      6 votes
  4. [3]
    286437714
    Link
    I think this validates @smoontjes's point about Danish systems being 'hilariously bad'. Regular bad would be Admin1! 123456 tips it over the edge

    I think this validates @smoontjes's point about Danish systems being 'hilariously bad'.

    Regular bad would be Admin1!

    123456 tips it over the edge

    13 votes
    1. [2]
      foryth
      Link Parent
      shoulda been hunter2

      shoulda been hunter2

      5 votes
      1. DefinitelyNotAFae
        Link Parent
        That just shows as ******* on my screen

        That just shows as ******* on my screen

        5 votes
  5. CannibalisticApple
    Link
    So I just told my mom about this and asked her to guess the password. Her response: "12345". Off by a single digit. Frankly at that point you might as well use "password" as a password. All I can...

    So I just told my mom about this and asked her to guess the password. Her response: "12345". Off by a single digit. Frankly at that point you might as well use "password" as a password.

    All I can think is that there's some idiot in the chain with too much power who would complain about passwords being too complicated. And that the actually trained experts were forced to use 123456 as a password to placate them, because they were too high-ranking and connected to just deny access to these critical systems or fire. It's the only explanation that makes sense to me, because the alternative is just... Absolute incompetence everywhere.

    9 votes
  6. winther
    Link
    In case the title is not clear, it is not the CPR system that had that password. It was the admin system of the small private company where their access was misused through. The real problem is...

    In case the title is not clear, it is not the CPR system that had that password. It was the admin system of the small private company where their access was misused through. The real problem is how lenient access to the system has been given and how little monitoring of usage analogies there is.

    8 votes