10 ms·
Tell HN: MitID, Denmark's digital ID, was down
MitID is the sole digital ID provider, leading the entire country unable to log into their internet banking, public services, digital mail etc.
https://www.digitaliser.dk/mitid/nyt-fra-mitid/2026/feb/driftsforstyrrelser-mitid https://www.digitaliser.dk/mitid/nyt-fra-mitid/2026/feb/drif...
- deleted 7mo ago[deleted]
- aucisson_masque 7mo agoI guess that's the one thing you don't want to be down and yet it's down..
- plaguna 7mo agoFirst, we saw Russian hacking campaigns in Ukraine before the invasion of the country. [1][2] Are we seeing the same in Denmark/Greenland with the USA? [1] https://www.europarl.europa.eu/RegData/etudes/BRIE/2022/733549/EPRS_BRI(2022)733549_EN.pdf https://www.europarl.europa.eu/RegData/etudes/BRIE/2022/7335... [2] https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks
- ta9000 7mo agoTin foil is aisle ten friend.
- 5o1ecist 7mo ago[flagged]
- deleted 7mo ago[deleted]
- celpgoescheeew 7mo agogiven the very sparse info on the actual problem i find it suspicious as well.
- zenmac 7mo agoShould have stuck with NemID a previous paper alternative or only offered MitID as a digital alternative. The rush to go all digital is coming back to bite them in the .....
- lxgr 7mo agoHow would you use a paper ID online? (Securely, i.e. not the insane thing of taking a selfie holding it or something similarly bizarre in an age of powerful GenAI.)
- simongray 7mo agoNemID, the previous national 2-factor solution, used a small card with rows of pre-printed single-use codes. When you logged in to a bank or a public sector website, it would ask for a random code at a specific row and column number. Once the system registered that you had just a handful of codes left, a new card would be sent to you via snailmail. It worked fine for the time. The current system, MitID, depends on smartphones, though you can get an an external key generator as a backup too.
- LeonidasXIV 7mo agoYeah but functionally it is the same. If the website is down it doesn't matter if I got the OTP code from a piece of paper or the dongle.
- xorcist 7mo agoThe big drawback of one time passwords is that it doesn't protect against man-in-the-middle attacks such as phishing, which is in practice one of the most common attacks on systems of this scale. The logistics operation involved in distributing codes is also very expensive and inflexible. You may need to authenticate payments a dozen times in an hour one day, when you are on a farmers market which doesn't take card payments or you are out dining with friends, and another day not at all. Given all this, a good old public key infrastructure makes sense. But that is unfortunately also usually the first step to a complexity explosion.
- Gravityloss 7mo agoDon't banks have their own id:s as well? At least in another nordic country, you have quite many login possibilities to many services. Banks even provide cross-login.
- VorpalWay 7mo agoAs I understand it, BankID in Sweden is still run by one organisation co-owned by the big banks, and banks handle verification for issuance. There is still a single point of failure for the operation of the system.
- elygre 7mo agoSame in Norway.
- Gravityloss 7mo agoWell I'm in Finland and seems the system here has multiple independent services and is thus potentially more resilient.
- Anonyneko 7mo agoI was under the impression that all of those services and login methods rely on suomi.fi in the end, but I admit that I don't understand the system terribly well.
- wasmitnetzen 7mo agoThere is technically a second provider, Freja, but that is basically only supported by government agencies, and even that is spotty. There are talks about a state-provided one coming soon, because of EU E-ID laws.
- mousepad12 7mo agoNo. Many/most of them support login through hardware ID on your smartphone (i.e fingerprint/TPM-style pin), but the actual authorization of transfers or any privileged access is entirely MitID
- VorpalWay 7mo agoThe Swedish BankID has the same potential weak point. Any centralised system does. The way TLS on the Web works is better: as long as the CA is up some time during the period I need to renew it is fine. Digital IDs should really work that way (probably with relatively short life spans just like let's encrypt: the digital ID could need to be renewed once a week for example, and it would opportunisticly renew when less than half the time is left).
- lxgr 7mo agoFor anything as high stakes as eID you need real-time revocation checks, which brings you back to at least some level of centralization.
- progbits 7mo agoRevocation lists can be distributed.
- deleted 7mo ago[deleted]
- lxgr 7mo agoYes, but they still originate somewhere, and if that source goes offline, you're still at risk of accepting stolen credentials.
- VorpalWay 7mo agoYes, but under the assumption that downtime is typically short (a few hours), that small risk seems better than a foreign nation state actor being able to block essential services like identifying with healthcare, or sending transactions.
- jdmoreira 7mo agoSure... but it should degrade to work when the central services are down. You should still be able to authenticate with each individual service when the centralised service is down. There is no reason why you shouldn't be able to login to your bank under these circumstances.
- bjarteaarmolund 7mo agoSupposedly up again now
- jdmoreira 7mo agoThese things should be offline / resilient first right? Smartcards / YubiKeys. Never understood the logic for these to be centralised / online.
- consp 7mo agoRevocation.
- jdmoreira 7mo agocan be solved with a hybrid model that degrades when the central service is down. No?
- erk__ 7mo agoWell they provide that if you want. they have both a OTP dongle, a OTP loud speaker and one that uses FIDO U2F (though you need to pay for that one). https://www.mitid.dk/en-gb/get-started-with-mitid/how-to-use-mitid/?language=en-gb https://www.mitid.dk/en-gb/get-started-with-mitid/how-to-use...
- xorcist 7mo agoPKI works offline until you realize you need to handle revocations. For this and related reasons, such as enforcing protocol upgrades, most smartcard systems end up permanently online.
- VorpalWay 7mo agoYou can have a mixed system, such that revocation lists are downloaded and cached every hour or so, and you can even try to check online more often than that, but fall back to the downloaded lists if the system is down.
- mollerhoj 7mo agothis is not big news in dk, it will be up again soon - i dont know of any mitid services that are life-or-death enough to have people panicing about an hours downtime
- BSDobelix 7mo ago>this is not big news in dk Yep let's not learn from that incident and wait until is offline for like 2 weeks, and be assured that will happen.
- avh02 7mo agoyeah, everyone knows every European website is eventually down for 2 weeks. only the FAANG know how to keep websites up.
- BSDobelix 7mo ago>only the FAANG know how to keep websites up Really FAANG can stop a solar-storm? A war on infrastructure? Remember that your website not just needs running computers but energy too, and a net that brings that information to the peoples, and those peoples devices need power too. Just look at the Berlin outage where people had to go to hotpots with generators to load the phone: https://edition.cnn.com/2026/01/07/europe/berlin-power-outage-intl https://edition.cnn.com/2026/01/07/europe/berlin-power-outag... And that was a small attack on infra but 100'000 where affected. But sorry if i touched any of your sensitive areas...because it's Europe and not FAANG ;)
- deleted 7mo ago[deleted]
- avh02 7mo agonah, i generally agree with you on single points of failure, i just don't agree that it would go on as long as 2 weeks. 24-48 hours i can believe, but at the absolute worst case I'd also expect anyone with minimal competence to have a plan to spin things up from the latest offsite backup somewhere else. (minimal competence is a big statement though). Even redundant setups can go down altogether from a fatfinger or automation gone wrong (see almost any outage from FAANG) > stop a solar-storm never heard of those taking out a data center, but i'm not highly educated on that one. > A war on infrastructure government datacenter will be first in line for fuel, generators, etc. A destroyed gov. datacenter would be the start of much more serious things to worry about. > Just look at the Berlin outage where people had to go to hotpots yeah, this one _is_ a little embarassing, but people who have to go to hotspots != datacenters The original statement stands.
- dijit 7mo agoTerrifying to live in a digital economy when something like this happens. You're usually about 1 service away from realising that the "money you have" is just an int32, that, if everything works properly, you can modify. Otherwise you have nothing except a pretty little plastic card. (I'm aware that payments systems are not affected, but it's a sobering realisation that I've had a couple of times, but it works enough of the time that I forget about it... it's a bit like the meme about backups where a computer takes too long to boot, the person slowly builds panic and starts wishing they had backed up and published all their important work - then when the computer works they say "*phew*, thank god I don't have to do any of that".
- davidguetta 7mo agoNow go read about fractional reserve banking
- sinnsro 7mo agoNow that the money is gone What are we supposed to do? After all that we've been through When everything that felt so right is wrong Now that the money is gone (money is gone)
- deleted 7mo ago[deleted]
- p0w3n3d 7mo agoWitnessing this or Texas floods, politicians in my country dare to say that `We don't need cash'
- u1hcw9nx 7mo agoImagine someone "enthusiastically digitized" (as much as possible) in a foreign country alone and then they lose their iPhone Plane tickets, all hotel reservations, they don't remember any phone numbers. They use ApplePay and other mobile payments. Cards may be in the same wallet case. Without a trusted device or Recovery Key, Apple may impose a security delay (24 hours to several days) before allowing a password reset. Getting new SIM and re-authenticating our life will be pain.
- azalemeth 7mo agoI'm a British expat with a Danish job. I really dislike MitID and the Danish centralised world of (very good) public services that come with it. Each person has a number, CPR, which effectively defines your life solely to the state. Visit a library, doctor, tax man, anything official, and your ID is recorded. Buy alcohol online, go grocery shopping, use your bank card -- and sign in with it. This undoubtedly makes things easier for the state -- and I've seen produce some pretty good epidemiology work where the government can link purchasing habits and health outcomes(!) -- but it's a privacy nightmare. MitID doesn't work on rooted android phones, or those running a custom rom. Reports from others who have disassembled it indicate that in fact a hard coded list of custom roms is checked against. It's a highly obsfucated binary, and by design is a single point of failure. If you sign in with an unauthorized device it helpfully centrally blacklists your IMEI. It's hard (but not impossible) to get a phone contract on Denmark without indirectly giving over your CPR number, so I imagine trying to get around this is frustrating. I didn't try and have a hardware dongle. One. By design, this whole system is a massive centralised single point of failure. It's absolutely key to Danish life. That all said, most Danes would vigorously defend privacy, say that the state doesn't abuse its powers, and they're probably right. It's a very vivid vision of the 1960s Nanny State, where Nanny knows best and has your best interests at heart. Most of the time, she does. They're frequently voted as some of the happiest people on earth, so clearly the recipe of pay a ton of tax and get things from it works well. I find the privacy lack rather shocking and I've never got used to it -- in quite some ways it's an incredibly authoritarian society although no Dane would ever say that, and tell me to drink more øl and get off the internet and go for a walk in a forest. They point out that the UK has far more CCTV cameras and that we have more prosecutions for bent policemen and politicians. There's truth in all of this. Either way, I'd be interested in seeing if they issue a post mortem on this. It'll cause a lot of issues for many, many people.
- Nekorosu 7mo agoInteresting. Swedish BankID, that I'd guess serves the same purpose, works just fine on GrapheneOS, as well as nation wide payment system Swish.
- 7mo ago
- wosined 7mo agoAnd who is the happy monopolistic receiver of this constant and unending stream of taxpayer money?
- UebVar 7mo agoThe french company IN Groupe.
- mingusrude 7mo agoIN Groupe is fully owned by the French state.
- deleted 7mo ago[deleted]
- jasonvorhe 7mo agoJust one of a dozen reasons to resist digital id.
- j45 7mo agoAt a more basic level, before software issues, digital wallets can run out of batteries. As can infrastructure. Electricity isn't guaranteed.
- jandragsbaek 7mo agoThe primary reason this is down is usally because of certificates running out, that has to be manually replaced
- balboah 7mo agoIn Sweden there’s at least one more competitor to BankID called Freja. There’s also some kind of EU-level system. Would be cool if multiple actors were allowed and shared the same kind of auth signing method so that there aren’t just one point of failure. Or something distributed like a blockchain type of signing method, at least I don’t think Bitcoin or Ethereum have downtime that often, and authorization should probably be read heavy only to check if some identity is still allowed
- himata4113 7mo agoMakes me appreciate that my government gives me like 17 different ways to authenticate including every bank that exists.
- tiku 7mo agoMeanwhile the Netherlands is selling the DigiD system to foreign companies and today it came out that we are also are going to outsource of of our key tax systems to an American company.
- macintux 7mo ago> …today it came out that we are also are going to outsource of of our key tax systems to an American company. That’s a remarkable failure to read the room, given the digital sovereignty initiatives across Europe.
- Muromec 7mo agoThere is even the digital sovereignty strategy of the Dutch government itself to migrate off the azure.
- Muromec 7mo agoIsn't it the hosting provide and not digid itself?
- kakoni 7mo agoFinland did that + lot more. Tax system from Gentax, EHR from Epic and social benefits from Salesforce.
- _slih 7mo agowhen your sole digital identity provider goes down, it's not a service disruption. it's a national infrastructure outage. the blast radius of a single authentication system is the entire country.
- dude250711 7mo agoThey went to Linux recently didn't they?
- Croftengea 7mo agoHow ironic to see "MitID remains inaccessible" and "You are in charge of your data" cookie banner on the same page.
- Tehnix 7mo agoI see a few people here complaining about the idea of a central digital identity service. As a Dane, having lived in other countries, MitID is an insanely superior to anything I've ever tried. It simplifies so many touchpoints with the government, and is honestly such a good upgrade going from nothing -> physical NemID card with codes -> digital MitID (literally "My ID"). The only real disruption I'd say is if you happen to be buying something online that triggers the 3DS prompt (an additional security layer to prevent cards getting stolen/scam). In Denmark the 3DS prompt for VISA at least uses MitID to verify you are the owner of the card, so that'll obviously not work when MitID is down. I'll say, it has been surprisingly stable though otherwise, and disruptions usually aren't a big impact (I literally wouldn't have known unless I saw this HackerNews post). As for a centralized identity system: I personally see this as an acceptable contract for living in a society. Most countries have SSNs anyways, your taxes and many other things are tied to this. Centralizing this identity allows the government to streamline so many things to give a better service to their citizens. For example, all official communication goes to your "DigitalPost" email inbox, your verify identity with "MitID", and every person or company has a registered "NemKonto" tied to them for any salary or government payouts. I maybe see people get tripped up at the concept that your government should actually care about the service they deliver. That's probably already the point where we diverge when talking about if these things are a good idea or not.
- winstonwinston 7mo ago> I see a few people here complaining about the idea of a central digital identity service. Digital identity service is fine for gov services. It’s not OK as a hard requirement for anything else such as banking. Digital ID in my country is down for about 7 days and counting. iOS app no longer opens after the recent update. I cannot pay tax without digital id app working but i can do banking and everything else.
- Tehnix 7mo ago> It’s not OK as a hard requirement for anything else such as banking. What’s the alternative that you think is okay for that then? Certain businesses have regulatory requirements to know and verify your identity (banking, telco). A UK poster gave an example of how they need to mail the bank a copy of their passport and other private information. I’d certainly much prefer simply using a digital login solution as an alternative to that. They can verify I am who I say I am, without needing my passport which I would consider a much bigger privacy invasion to hand out.
- xquce 7mo agoDane by choice (refugee). Would just add as a counterweight to the negative views from people outside the country. From a technical and user point of view, MitID have had less outages than Cloudflare, AWS and MS Azure in the last year. While I agree with the single point of failure, I also like that I setup my startup with all government and banking online via a login I had the last decade, painless and faster than most places without having to upload a single document in many a unsecured ways I heard from my US and Other European friends (outside the Nordic countries). Yes we Danes trust our institutions more than others and trust is given by default and then lost, rather then "earned" (I would argue bought) in other places.
- throwmitid1234 7mo agoThis is mostly a case of them not really reporting it, MitID is down quite frequently (now once a month ish, but in the first few years every week or so), or at least partially down . They now finally have their own status page, previously you had to get your status from a provider when they noticed that logins began to fail ;) They're very light on reporting issues, in this case Signaturgruppen a subsidiary of NETS, didn't even mark this as a full outage.
- halffullbrain 7mo agoAs someone who was part of developing the “start your business”-registration system in DK, I’m pleased to hear that! (It really is pretty complex, but a lot of effort went into making it both user friendly and reliable)
- kkfx 7mo agoNot a cryptobro but... The only acceptable digital identity is or local (smart-card) or a blockchain kept by any connected citizen on his/her own iron. The Orwellian dream of the nazi will cause pain also to those who push it.
- dang 7mo agoCan anyone tell us the current status? I put "was down" in the title to be conservative, since usually these things get resolved after a few hours. I converted this to a Tell HN post since there didn't seem to be a good 3rd party article about it in English (yet, at least). The submitted link is in the toptext. (Submitted title was "MitID, Denmarks sole digital ID, has been down for over an hour and counting".) (p.s. In case anyone is wondering, I think this was a good submission with aspects worth discussing. It set off the flamewar detector, so I turned that off and re-upped the post a bit.)
- Doerge 7mo agoThe linked page has 3 down updates, then says it's back up again after the 3rd one. So presumably resolved.
- mousepad12 7mo agoHi dang, Thanks for the edit. It is indeed up again, and I appreciate you recognizing that the thread had/have some great discussion aspects about e-ID in general. It was completely down from 10:40 to 12:17 GMT+1
- olegyakovik 7mo ago[dead]
- chr15m 7mo agoThis type of centralisation presents a classic tail risk. It's wonderful and works perfectly well for everybody and the government does nothing wrong with it. It's all fine and good until the day it isn't. Some authoritarian gets voted in, or the country gets invaded, or a corporation buys off politicians, or an immoral law is passed which you disagree with, and suddenly the digital ID is a point of leverage used to coerce you. Liberal democracy is a very young experiment and people do not realise how fragile it is. In the 1940s less than 10% of countries were democratic, and we could go back there again easily.
- throwmitid1234 7mo agoMitID is not great, I worked on the implementation for one of the providers. I am surprised this is even a frontpage topic, 3 years after it was rolled out, we saw downtime every week or so. So much so that we implemented automatic pop ups for our customers, and no on-call, signaturgruppen a subsidiary of NETS didn't even file this incident as a major outage lol. There is also no alternative, you simply can't access banking apps without MitID, so without it people in Denmark are just screwed, 3D Secure (online payments doesn't work for most merchants), login to government and banking sites doesn't work. The main issues are that we have a central provider NETS whom are known for NemID its predecessor, and card payments in Denmark. They're huge in this space, at least for Denmark. The government and the banks wanted more control over MitID, so the responsibility was split between the major banks, Digitalstyrelsen (the government), and NETS. Basically, customers, middle man and NETS the vendor. It was truly a shit show. The middleman (Digitalstyrelsen - Agency for Digital Government was technically illiterate, either by contract, or because they wanted to be in control, had inserted themselves in-between customer and vendor, and now we suddenly couldn't provide feedback, or talk to the vendor at all, this meant that the vendor had full control over how they interpreted the contract. During development they shipped a version of the product that had a single flag set to false, preventing a login. NETS weren't allowed to ship a fix for this for 3 months. Many of the customers had to use burp suite during their testing simply to progress with development. Finally when the vendor had "delivered" to their contract, the customer was sitting back with a half-baked product, and because it was Digitalstyrelsen that was the primary arbiter of whether they'd fulfilled the contract, NETS got away with having delivered at that point 1 year past schedule. I've never had so many support tickets. For such a technically tiny product, we saw so much trouble getting people to use MitID over NemID. It was incredible. What is even more insane is that each provider implementation of MitID is technically an independent implementation, some are React, Preact (if using nets provided version), etc. All the providers have to provide a pixel perfect replication to be allowed to issue MitID credentials. Also this was designed when OAuth was really hot, so most implementations are like 3 levels deeply nested of OpenID Connect and OAuth2, it gets pretty nuts. Talk about an amount of wasted effort. As with many other huge projects especially government lead. It is just a big power play, and as it turns out, power wins. In this case NETS.
- irenetusuq 7mo ago[dead]
- jbverschoor 7mo agoI assumed it would use pki / cryptographic signing instead of something that can be down
- Kate5477 7mo ago[dead]