A small Danish software company on Funen, which markets itself as "top-notch data protection", is at the center of the largest leak of Danes' CPR numbers and addresses in Danish history.
The company had legal access to the CPR register, which is what has been compromised.
DR's research shows that one of the passwords used by the company was part of another leak [...] it was simple and easy to decipher: "123456".
Ultimately, it is the authorities who are responsible for ensuring that companies with access to the CPR register meet a sufficient level of security. The National Unit for Serious Crime is investigating the case. They had no comment. There are currently no charges in the case.
The company also didn't use 2FA, and login page for their access was publicly available: article link.
The many troubling things a Danish CPR number (ID) can be used for include counterfeit, phising, scamming, obtaining even more personal information on you, even taking out loans: article link
I just need to remind everyone that the danish presidency of the Council of the EU were the ones that reintroduced Chat Control last year (on their very first day).
I had to google Chat Control because I hadn't heard of it before.
Thanks... I hate it. This isn't going to protect any children from pedophiles, it's just going to make it a thousand times harder for law enforcement to do their jobs.
So I just told my mom about this and asked her to guess the password. Her response: "12345". Off by a single digit. Frankly at that point you might as well use "password" as a password.
All I can think is that there's some idiot in the chain with too much power who would complain about passwords being too complicated. And that the actually trained experts were forced to use 123456 as a password to placate them, because they were too high-ranking and connected to just deny access to these critical systems or fire. It's the only explanation that makes sense to me, because the alternative is just... Absolute incompetence everywhere.
In case the title is not clear, it is not the CPR system that had that password. It was the admin system of the small private company where their access was misused through. The real problem is how lenient access to the system has been given and how little monitoring of usage analogies there is.
[OP] smoontjes | a day ago
Article in Danish, some translated snippets:
The company also didn't use 2FA, and login page for their access was publicly available: article link.
The many troubling things a Danish CPR number (ID) can be used for include counterfeit, phising, scamming, obtaining even more personal information on you, even taking out loans: article link
Previous thread: link
lostwax | 21 hours ago
Spaceballs_password_scene.gif
This has been a well known joke since the mid 80s, come on guys.
Akir | 19 hours ago
I know, I had the exact same urge to say that I have the same combination on my luggage.
Minori | 12 hours ago
My work password includes
123to satisfy the number requirement because it's easy to quickly type...Asinine | 11 hours ago
It's easy to incorporate things like this into a good password though. Also my [current] work password includes 123 too...
Protected | 20 hours ago
I just need to remind everyone that the danish presidency of the Council of the EU were the ones that reintroduced Chat Control last year (on their very first day).
Knockout_Mouse | 19 hours ago
I had to google Chat Control because I hadn't heard of it before.
Thanks... I hate it. This isn't going to protect any children from pedophiles, it's just going to make it a thousand times harder for law enforcement to do their jobs.
286437714 | 23 hours ago
I think this validates @smoontjes's point about Danish systems being 'hilariously bad'.
Regular bad would be Admin1!
123456 tips it over the edge
foryth | 9 hours ago
shoulda been hunter2
DefinitelyNotAFae | 7 hours ago
That just shows as ******* on my screen
CannibalisticApple | 22 hours ago
So I just told my mom about this and asked her to guess the password. Her response: "12345". Off by a single digit. Frankly at that point you might as well use "password" as a password.
All I can think is that there's some idiot in the chain with too much power who would complain about passwords being too complicated. And that the actually trained experts were forced to use 123456 as a password to placate them, because they were too high-ranking and connected to just deny access to these critical systems or fire. It's the only explanation that makes sense to me, because the alternative is just... Absolute incompetence everywhere.
winther | 17 hours ago
In case the title is not clear, it is not the CPR system that had that password. It was the admin system of the small private company where their access was misused through. The real problem is how lenient access to the system has been given and how little monitoring of usage analogies there is.