`123456' password used in Danish CPR data breach

(cphpost.dk)

175 points | by baal80spam 3 hours ago

39 comments

  • ionwake 1 hour ago
    Im sorry I know Im getting old but I say everyone is responsible. From the press who might focus too much on the whistleblower, to the poeple who OKed the company for 3rd party access, to the team responsible for regulation to the person who didnt order further checks.

    I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.

    You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.

    I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.

    • bombcar 1 hour ago
      There's a very "child-like" (not in a good way) form of responsibility that everyone seems to lean into as they climb up - very intent-based.

      I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.

      • ben_w 1 hour ago
        > I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.

        And now we have the same thing but the bosses 'hire' AI.

        Now I realise this is part of how unusual my thinking is.

        I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".

        The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.

        • soco 43 minutes ago
          You have a very engineer-like approach, like if you draw the line from A to B everything will work fine. Real world is different though. Humans will blissfully ignore the orders, business analysis is a lost cause since decades, and AI is built on human knowledge so guess what it will keep doing. Now what? How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
          • ben_w 17 minutes ago
            I indeed have a engineer-like approach, but engineering absolutely does not assume draw line from A to B and expect that's enough:

            Real world, as you say, not so simple. Everything has to deal with certain degree of forecastable nonsense, e.g. a bridge has to cope not only with traffic and winds, but the possibility that someone will be drunk in charge of a ship and crash into it.

            > AI is built on human knowledge so guess what it will keep doing.

            Yes, and also brings its own additional mess on top of that. All machine learning takes a huge number of examples to get good, so an LLM isn't just "read all the online courses in how to run a business", but also likely has 50 business versions of the recent demonstration of common sense failure with "I live 100m from a car wash, should I walk or drive?"

            > How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?

            Many such disciplines. Perhaps all except maths and computer science? Or even including maths and computer science, given stats is part of maths and even compsci has to deal with fault tolerance.

    • lukan 4 minutes ago
      "I dont understand why there is not massive reorganisations in systems when things go wrong"

      Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.

    • miohtama 1 hour ago
      Massive reorganisation will only happen if companies with poor security record go out of business, while competent ones win market share.

      Otherwise shareholders do not care, because they do not have skin in the game.

      Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.

    • asdf88990 31 minutes ago
      Rome wasn’t built in a day, not did it fall in a day. In a capitalist society you can gauge overall direction and success of the society but how well the market and private enterprise is doing, and well not merely in context of maximising shareholder value but as a fundamental part of the social fabric.
    • surcap526 6 minutes ago
      [dead]
    • tokai 1 hour ago
      Yeah that is a pretty weird opinion. Who cares about if he gets fired. He should be charged with criminal negligence and face prison time. Everyone is responsible for their own actions and its always possible to quit.
      • zweifuss 19 minutes ago
        The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
  • zkmon 2 hours ago
    I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

    It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

    • ulfbert_inc 2 hours ago
      You are presenting a false dilemma (probably unintentionally). While security can be at odds with usability, basic measures like password generation and management are a solved problem. In fact using password manager is more convenient than typing password manually, even 123456 :)
      • xandrius 1 hour ago
        Ha, I don't need to type 123456, it's stored in my navigator's password manager for convenience. Checkmate.
      • looperhacks 33 minutes ago
        Unless of course, you need to unlock your password manager, which is not integrated with your browser, because corporate IT doesn't allow browser extensions or desktop apps so you're bound to a web app ...
      • holowoodman 47 minutes ago
        Next step in typical security team fashion: Prevent password managers from working, by obscuring the password field, using click-to-type passwords or similar shenanigans, because fuck you, that's why...
    • ddosmax556 36 minutes ago
      It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.
      • Sick-Poster 23 minutes ago
        It is actually very hard to force password manager usage. You can encourage it, educate, but forcing it? How do you do that.
      • dwedge 21 minutes ago
        How do you force password manager usage?
        • misiek08 11 minutes ago
          Technically or socially? The second one is hard, the first one can be done easily - just require the passwords to be 14/16+ characters, multiple symbol domains and calculate tempo of input. Slower than 350ms between keystrokes - error message. Those who can type that fast already are using pw manager or you can just skip this 0.001%.
    • ano-ther 2 hours ago
      With two people in the company, there is not a lot of room for corporate games though.

      > According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.

    • tialaramex 2 hours ago
      > It's tussle between two counter-acting forces at play.

      It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]

      • tossandthrow 1 hour ago
        I would love to hear about a world where security and productivity are not counter acting forces.

        For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

        If you can just create a world for that simple case, then I will rest my case.

        • tialaramex 24 minutes ago
          Single-sign on is actually a really obvious and familiar example where you achieved better security (now all sixty five systems we use are protected by the same security, when we upgrade that security we're upgrading all sixty five systems) and yet you got better productivity because now I can get stuff done without battling two dozen authentication systems to do it, just sign in once.

          Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.

        • xoa 13 minutes ago
          >I would love to hear about a world where security and productivity are not counter acting forces.

          Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?

          Even if we take your silly example you clearly intend as a gotcha:

          >For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.

          People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.

          Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.

    • TehCorwiz 1 hour ago
      Productivity and Aesthetics could also be said to be counter acting forces. Or really anything that requires contemplation. I think the problem is in how some people define "productive". Is it productive to have significant security problems which cause more work?
    • kay_o 1 hour ago
      Touch one hardware key for every interaction then, not 123456, the hell?
    • tokai 1 hour ago
      Just because a task is hard it should never absolve anything. Guy could just have quit if he didn't want the responsibility.
      • zweifuss 23 minutes ago
        The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.
    • altmanaltman 2 hours ago
      Setting '123456' as a password on any non-trivial system is not "the shortest route possible to maximize their productivity." It would be setting the password as "000000"
      • nylonstrung 1 hour ago
        The guys who are really into keyboard layouts would argue vehemently that 123456 is more ergonomic as it's an "inward roll" vs 6 consecutive presses of a key that aligns to the pinky
      • ntoskrnl_exe 1 hour ago
        I'm not sure, I think it's a little more ergonomical to hit six different keys compared to hitting a single key precisely six times.
  • mvkel 5 minutes ago
    > According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company.

    So the password could have been 32 alphanumerics with special characters and there still would have been a breach.

    The password was not the problem here.

  • ptnpzwqd 1 hour ago
    It is easy to blame the company or individual responsible for making the leak possible, and of course also well justified, but I think the bigger problem is the way the CPR number is used.

    Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.

    • boxed 1 hour ago
      > Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong

      That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.

  • mhd 1 hour ago
    They should've just written it in Danish, nothing seems more secure than how they construct numbers. The 56 part would've been "six-and-half-triple-score" or something similarly insane.
    • krabat 6 minutes ago
      seks og halvtreds six plus two and a half times twenty
  • ano-ther 2 hours ago
    So it was actually two weaknesses:

    * The non-password at a two-person IT company (Pays ApS)

    * And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).

    • mrweasel 29 minutes ago
      The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.

      Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.

      The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.

    • tuwtuwtuwtuw 1 hour ago
      There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
      • nylonstrung 1 hour ago
        Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously
      • olau 1 hour ago
        Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.

        I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.

        • tuwtuwtuwtuw 1 hour ago
          I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers.
  • piker 2 hours ago
    That’s the same combination I have on my luggage!
    • justinclift 2 hours ago
      The Spaceballs piece about it: https://www.youtube.com/watch?v=a6iW-8xPw3k
    • dec0dedab0de 58 minutes ago
      I don’t normally upvote jokes on hn, but it’s saturday and I was about to say the same thing.
    • wrecked_em 1 hour ago
      Props to you, good sir. You beat me by one hour.
    • bryanrasmussen 1 hour ago
      the same price of a large pizza where I used to work as a delivery guy! Those pizzas were way expensive.
    • HPsquared 2 hours ago
      Funnily enough, luggage calls back to those TSA locks.
    • Sau1707 2 hours ago
      I bet you are not the only one!
  • zweifuss 2 hours ago
    I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
    • sethammons 2 hours ago
      What would that accountability look like?
      • gunalx 2 hours ago
        Not existing preferably.
        • tossandthrow 2 hours ago
          This is the likely outcome. It was a company employing 2 people.
        • tannertech 2 hours ago
          Strange way to say prison time. Or if you meant capital punishment harsh but fair.
      • lifestyleguru 2 hours ago
        Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
  • sokols 2 hours ago
    I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
    • zweifuss 2 hours ago
      A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
    • iLoveOncall 2 hours ago
      Or simply make people who choose insecure passwords criminally responsible for the fallout.
      • bryanrasmussen 1 hour ago
        and make the people who didn't put any sort of limits on how many records can be downloaded before there has to be a check on what is going on or any of the other stupid security holes that were found, make them criminally responsible as well. At some point you can be sure you'll be imprisoning someone for making a typing mistake (accidentally commented out some code) or a logic mistake (I should have said IS NOT, but instead I said IS) or just being tired.
  • verelo 1 hour ago
    Personal pet peeve undefined acronyms, "CPR": Central Person Register. For those who didn't know, like me, and had to look it up.
  • rr808 18 minutes ago
    At this stage all SSN, NI numbers, CPR etc should just be made public. Its assuming its some kind of secret is the problem. Its an ID not a password.
    • krabat 9 minutes ago
      CPR is code for "registersamkøring". Register matching. The small wellfare nation needing to be able to see the populace as a sum of abilities and leanings and willingness to be swayed and pushed to support present and future economic needs of the whole.
  • eviks 1 hour ago
    Yes, S in Government stands for Security, C - for Competence (or caring about your data), and D - for system Design
  • nashashmi 23 minutes ago
    Well, if you change to many settings, it will break. So don’t change anything. So it doesn’t break.
  • krabat 15 minutes ago
    Denmark comes from a long line of institutional trust: We say we do this, so we do it, so everyone else will naturally expect that.

    Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!

    We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.

  • mattlondon 2 hours ago
    If only they had insisted on a secure 8 character password!
    • LarsKrimi 2 hours ago
      There are some unconfirmed rumors going that the maximum password length for the API was 8 characters...
    • fifilura 2 hours ago
      1Password#

      Oops, can I delete my comment, it was a copy paste mistake!

      • lifestyleguru 2 hours ago
        > **********

        > Oops, can I delete my comment, it was a copy paste mistake!

        What do you mean? You can safely post your passwords on the internet.

        • _kb 1 hour ago
          hunter2
    • walrus01 1 hour ago
      hunter2#
  • wrecked_em 1 hour ago
    That's the kind of password an idiot would have on his luggage.
  • donalhunt 2 hours ago
    In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.

    Equivalent to social security information in the US I guess.

    • gus_massa 1 hour ago
      For some unknown reason, the SSN in USA is assumed to be secret. You go to the bank, say SSN=12345 and they give you a million dollars and then send the collector the the guy/gal with that number, and call it identity thief instead of bad bank security or fraud.

      Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.

    • Mashimo 59 minutes ago
      I'm not super familiar with SSN in US of A, but I think the Danish one is not has secret. Don't get me wrong, the leak is not good, but there is a limit to what you can do with it.

      Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.

      Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.

    • lordnacho 2 hours ago
      It's unique, but it encodes your birthday and sex.

      There's only 500 numbers it could be, assuming someone knows those other things about you.

      In any case, there are alternative systems for authorisation.

      • usrnm 2 hours ago
        You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
        • piva00 2 hours ago
          It's Denmark, it won't have 1k babies born the same day.

          It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.

          • polack 1 hour ago
            There have been collisions in Sweden, but that was due to lots of immigrants coming from the middle east that did not know when they where born. So many of them picked first of January. They “solved” it by overflowing to the next days.
          • madmoose 1 hour ago
            Immigrants who don't know their birthdate are assigned xxxx-01-01, so they have actually run out of numbers for January 1st in some years.
          • ls65536 1 hour ago
            That format looks like it would allow for up to 10k per day. Unless one of those X's is a check digit?
            • onionisafruit 1 hour ago
              They said sex is encoded in it, so it’s probably a sex digit.

              edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.

              It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.

        • tannertech 2 hours ago
          That's a problem for future Denmark!
  • INTPenis 2 hours ago
    I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!

    Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

  • largbae 40 minutes ago
    That's the stupidest combination I ever heard in my life! The kind of thing an idiot would have on his luggage!
  • caaqil 2 hours ago
    It's easy to blame the individual users but any system (designed by incompetent people) that accepts such a password as valid deserves whatever compromise it gets.
  • imdsm 2 hours ago
    not ideal
    • tannertech 2 hours ago
      yeah it's rather unfortunate isn't it
  • 0xbadcafebee 53 minutes ago
    Literally nothing will prevent this but software building codes and enforcement. That's why we have building codes. We let builders do whatever they wanted for decades and it ended in disaster, so we stopped letting safety be optional.
  • croes 2 hours ago
    Did they have MFA?
  • sneak 2 hours ago
    The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
    • LarsKrimi 2 hours ago
      Privatization

      It was run by DXC Technology, the Danish branch of a US software house.

      When doing a contract on such programs the Danish government must take the cheapest offer by rule

  • lifestyleguru 2 hours ago
    For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
  • shevy-java 1 hour ago
    That's my password!!!

    Thieves give it back now!

    • lstodd 1 hour ago
      My password is 123qwe so it's safe for now.
  • ZuoCen_Liu 1 hour ago
    Please enter Password: Password ↵ The password is incorrect: incorrect ↵ Incorrect password, please enter again: Again ↵ ...
  • tokai 2 hours ago
    Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
    • GuestFAUniverse 2 hours ago
      Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.

      Since then I think medical data science is mainly a waste of tax payer's money.

  • nslindtner 1 hour ago
    Another fact - was only discovered because the invoice for using the lookup was big
  • bricss 1 hour ago
    If only there was an algorithm for password strength estimation > . <
  • redanddead 1 hour ago
    Oh my fucking god
  • m00dy 2 hours ago
    lol, it's a joke right ?
  • asanineassasin 29 minutes ago
    [dead]
  • koolba 59 minutes ago
    [flagged]
  • CurbStomper4 1 hour ago
    [dead]
  • aussieguy1234 1 hour ago
    They forgot to write it on a post-it note attached to the monitor /s