`123456' password used in Danish CPR data breach

(cphpost.dk)

81 points | by baal80spam 1 hour ago

23 comments

  • zkmon 22 minutes ago
    I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

    It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

    • ano-ther 13 minutes ago
      With two people in the company, there is not a lot of room for corporate games though.

      > According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

    • ulfbert_inc 10 minutes ago
      You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)
    • kay_o 6 minutes ago
      Touch one hardware key for every interaction then, not 123456, the hell?
    • tialaramex 10 minutes ago
      > It's tussle between two counter-acting forces at play.

      It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

      • tossandthrow 6 minutes ago
        I would love to hear about a world where security and productivity are not counter acting forces.

        For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

        If you can just create a world for that simple case, then I will rest my case.

    • altmanaltman 7 minutes ago
      Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"
  • ionwake 5 minutes ago
    Im sorry I know Im getting old but when I say everyone is responsible they should be from the press who might focus too much on essentially the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.

    I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.

    You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it, is crazy. Its just moral/leadership decay.

    I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.

  • ano-ther 17 minutes ago
    So it was actually two weaknesses:

    * The non-password at a two-person IT company (Pays ApS)

    * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).

    • tuwtuwtuwtuw 3 minutes ago
      There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
  • zweifuss 40 minutes ago
    I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
    • sethammons 36 minutes ago
      What would that accountability look like?
      • gunalx 34 minutes ago
        Not existing preferably.
        • tossandthrow 18 minutes ago
          This is the likely outcome. It was a company employing 2 people.
        • tannertech 28 minutes ago
          Strange way to say prison time. Or if you meant capital punishment harsh but fair.
      • lifestyleguru 24 minutes ago
        Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
  • sokols 26 minutes ago
    I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
    • zweifuss 21 minutes ago
      A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
    • iLoveOncall 23 minutes ago
      Or simply make people who choose insecure passwords criminally responsible for the fallout.
  • piker 45 minutes ago
    That’s the same combination I have on my luggage!
  • shevy-java 0 minutes ago
    That's my password!!!

    Thieves give it back now!

  • nslindtner 0 minutes ago
    Another fact - was only discovered because the invoice for using the lookup was big
  • mattlondon 20 minutes ago
    If only they had insisted on an 8 character password!
    • LarsKrimi 12 minutes ago
      There are some unconfirmed rumors going that the maximum password length for the API was 8 characters...
    • fifilura 18 minutes ago
      1Password#

      Oops, can I delete my comment, it was a copy paste mistake!

      • lifestyleguru 13 minutes ago
        > **********

        > Oops, can I delete my comment, it was a copy paste mistake!

        What do you mean? You can safely post your passwords on the internet.

        • _kb 6 minutes ago
          hunter2
  • donalhunt 45 minutes ago
    In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.

    Equivalent to social security information in the US I guess.

    • gus_massa 3 minutes ago
      For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.

      Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.

    • lordnacho 31 minutes ago
      It's unique, but it encodes your birthday and sex.

      There's only 500 numbers it could be, assuming someone knows those other things about you.

      In any case, there are alternative systems for authorisation.

      • usrnm 22 minutes ago
        You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
        • piva00 20 minutes ago
          It's Denmark, it won't have 1k babies born the same day.

          It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.

          • ls65536 3 minutes ago
            That format looks like it would allow for up to 10k per day. Unless one of those X's is a check digit?
        • tannertech 20 minutes ago
          That's a problem for future Denmark!
  • INTPenis 45 minutes ago
    I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!

    Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

  • ZuoCen_Liu 4 minutes ago
    Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...
  • bricss 4 minutes ago
    If only there was an algorithm for password strength estimation > . <
  • caaqil 10 minutes ago
    It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
  • imdsm 46 minutes ago
    not ideal
    • tannertech 11 minutes ago
      yeah it's rather unfortunate isn't it
  • sneak 36 minutes ago
    The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
    • LarsKrimi 32 minutes ago
      Privatization

      It was run by DXC Technology, the Danish branch of a US software house.

      When doing a contract on such programs the Danish government must take the cheapest offer by rule

  • croes 26 minutes ago
    Did they have MFA?
  • tokai 30 minutes ago
    Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
    • GuestFAUniverse 22 minutes ago
      Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.

      Since then I think medical data science is mainly a waste of tax payer's money.

  • lifestyleguru 43 minutes ago
    For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
  • m00dy 44 minutes ago
    lol, it's a joke right ?
  • aussieguy1234 4 minutes ago
    They forgot to write it on a post-it note attached to the monitor /s