8 ms·
Source code of Swedish e-government services has been leaked
- robertlagrant 7mo agoThe source code is the least of it! From the article: > citizen PII databases and electronic signing documents were also collected but are being sold separately
- jetsetman192 7mo agoEncryption keys are mentioned as well.
- simonklitj 7mo agoMan, you've got to be a real low-life to sell all of that.
- blell 7mo agoYou've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
- xorcist 7mo agoIt's something akin to a service provider in SAML parlance, if we are to believe reporting. How can it be air-gapped? And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.
- UltraSane 7mo agoAt the high end you can use data diodes to isolate critical data.
- lukan 7mo agoIf you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.
- dns_snek 7mo ago> it is still easy to make misstakes. That's not an excuse though, any system handling data like that should be continuously reviewed and pentested by professionals. Hopefully they can show that this has been done otherwise it's just negligence.
- lukan 7mo agoIt was mainly an explanation, that "airgapping" does not magically provides better security, or is required (or possible) to use at all here.
- dns_snek 7mo agoAnd it's pretty clear to me that they were criticizing storage of sensitive data in a database that isn't properly secured and they simply misused the term "airgapped". The database in question was easily accessible from poorly maintained development infrastructure. > Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize
- fc417fc802 7mo agoImagine if the bank took such a cavalier attitude with the contents of my account.
- jjgreen 7mo ago"misstakes", love it, almost peotic
- dijit 7mo agoThe point of a system like this is specifically that it’s accessible and not air gapped. Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible
- deleted 7mo ago[deleted]
- fc417fc802 7mo agoIf you can't implement it securely then perhaps such an undertaking wasn't a good idea? In the vast majority of cases I don't see why PII ever needs to be available over the network for remote queries. For the purpose of verification isn't it sufficient to verify hashes or better yet to attest via smartcard?
- dijit 7mo agoYou can, they didn't; big difference.
- fc417fc802 7mo agoBy "can't" I mean "not capable" or "not going to in practice".
- AdamN 7mo agoYeah the source code isn't really such a big deal aside from helping to find vulnerabilities. The PII is a real disgrace.
- embedding-shape 7mo agoSeeming by other sources, it wasn't really information considered PII in Sweden (but would in other places), I'm not sure this is as a big deal as people try to make it out to be.
- worldsayshi 7mo agoI wonder if the focus on source code makes Swedish news slower to jump on this. I haven't seen it in domestic news yet. (Haven't looked too wide though)
- ACS_Solver 7mo agoI saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.
- worldsayshi 7mo agoIn Aftonbladet comments from CGI they seem to think that no production related data has been leaked: https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppges-vara-hackade-flera-myndigheter-aktiva https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...
- einr 7mo agosome report it's basically the code and certs responsible for BankID SSO No. CGI has nothing to do with BankID. IMO the most credible reports suggest that the source code and data involved are related to these four services: https://www.cgi.com/se/sv/business-process-services/e-tjanster/mina-engagemang https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Mina engagemang offers a user-friendly and flexible solution that allows your customers to manage their cases directly through a personal portal. Here, users can view, track, and interact with their ongoing cases, which enhances both transparency and efficiency in the communication process." -- some kind of ticket/case management system for gov't agencies https://www.cgi.com/se/sv/business-process-services/elektronisk-identifiering-och-underskrift https://www.cgi.com/se/sv/business-process-services/elektron... "With our secure end-to-end e-ID and eSign services, we can help you streamline document and contract management, gain access to all desired e-ID issuers, and improve cost efficiency." -- this sounds like a bad thing to compromise, but is to the best of my understanding a system for digital signatures on documents, and has no relation to BankID https://www.cgi.com/se/sv/business-process-services/e-tjanster/foretradarregistret https://www.cgi.com/se/sv/business-process-services/e-tjanst... "Gain better control over your organization’s representatives with our easy-to-use representative registry. By automating the identification and verification of representatives, you’ll gain a clear overview and enhance the security of your processes." -- sounds like some bullshit CRUD app for managing who can "represent" a gov't agency https://www.cgi.com/se/sv/business-process-services/e-tjanster/shs https://www.cgi.com/se/sv/business-process-services/e-tjanst... "SHS is Sweden’s common standard for information exchange, enabling secure and efficient communication between government agencies, businesses, and organizations." -- this might be bad if real data was leaked These are services used by various Swedish government agencies and it's pretty bad to have even a test instance of them hacked, but let's calm down. The entire Swedish state has not been compromised here.
- deleted 7mo ago[deleted]
- ptx 7mo agoWhat does "electronic signing documents" mean? Keys used for signing? Or merely some documents that were signed with electronic signing?
- nunobrito 7mo agoIf that is case, then it would have been wrong from the beginning for any government to keep hold of the private keys for the signature on my citizen card. Because in that case they can sign documents on my behalf without my permission. In a court case, it would be near impossible for me to prove that the government gave my private key to someone else and that it wasn't me signing an incriminating document.
- ptx 7mo agoI apparently didn't phrase that very well. If what is the case? I was trying to ask which case was the case, not trying to claim that something specific was the case. I'm familiar with electronic signatures, and I know what documents are, but I have never heard the phrase "electronic signing documents" and don't know what that is supposed to mean. What kind of documents? Documents about signing, documents that were signed, documents in the sense that files containing keys could be considered documents, or what?
- nunobrito 7mo agoIn Portugal we were early adopters for digital signatures on citizen cards. You use the card reader, insert your gov-issued identification and can sign PDF papers which have legal validity since the private key from the citizen card was used. Now imagine someone signing random legal documents with your ID for things like debts, opening companies or subscritions to whatever.
- pastage 7mo agoSigned documents can be as simple as an ID of the transaction, a statement in text, PII data that identify what you sign, or a store of larger PDF files for download and verification. We do not know. I base this on how signing works technically in Sweden. CGI is not the only supplier of these services.
- teroshan 7mo agoDoes anyone know if there is the source code for the Swedish Armed Forces - Team Test [1] in the leak? It was a really fun collaborative flash-style game that got popular in my circle of friends for some reason back then. [1] https://flashism.wordpress.com/2010/03/09/swedish-armed-forces-team-test/ https://flashism.wordpress.com/2010/03/09/swedish-armed-forc...
- steve1977 7mo agoIs this the open source stuff everyone is talking about?
- rebolek 7mo agoMaybe they should go open source from the start, then there's nothing to leak. P.S.: And strangers will sometimes help you find vulnerabilities (and sometimes be very obnoxious but that's not open source's fault).
- ZaoLahma 7mo agoYeah. In these cases it's not like anyone is going to spin up their own instance and start competing with you. Government / handles society-critical things code should really be public unless there are _really_ good reasons for it not to be, where those reasons are never "we're just not very good at what we're doing and we don't want anyone to find out".
- matsemann 7mo agoWhen I worked for the government in Norway, it slowly changed to all code being developed in the open. 3k repos here now: https://github.com/orgs/navikt/repositories https://github.com/orgs/navikt/repositories When I started it was a big security theater. Had to develop on thin clients with no external internet access, for instance. Then they got some great people in charge that modernized everything. Only drawback is when you quit, you have to make sure to unsubscribe from everything, hehe. When quitting a private company I was just removed from the github org. Here I was as well, but I was still subscribed to lots of repos, issues, PRs,heh.
- jmusall 7mo agoVery cool! Do they accept external contributions, e.g. from Norwegian citizens? Also, was there any thought given to "digital souvereignty" (wondering because the repos are hosted on a US service)? I'm also surprised that you were able to (or expected to?) use your private GitHub account for your work.
- matsemann 7mo agoNot sure how it is now, but when I worked there ~8 years ago we weren't really equipped to accept contributions. Both from a licensing perspective (CLA), but also that we had our own timelines, projects and prioritizations in the team. So most applications were open source more in the sense of source available. Some utils (like generators for Norwegian mock data, or libraries handling Norwegian addresses or whatever) that were actively used by other companies could get some proper contributions once in a while, though.
- Lionga 7mo agoHow much GDPR fine will they pay? Oh wait it's gov so nothing / does no matter even if. Who will take responsibility and get fired and lose all pension etc.? Oh wait no one. Well the citizens need to suck it up.
- Habgdnv 7mo agoFew years ago a huge NRA database was left public with admin/1234 or similar by the Bulgarian NRA. They government fined itself some non-trivial amount, then in the source/destination IBAN they put the same value and paid the fine. They managed to find someone to blame and it was not the person who left the database but the person who found it. Turns out that if you leave the PII of a whole country open to the public it is not your fault and you get to keep your cozy job. It is already unlawful to access that, so if someone access it - it is his fault - he broke the law. Edit, i checked the facts: The Bulgarian government said that the it should pay too much to itself, and appealed the fine for few years until it somehow expired. And the guy (20 year at that time) they accused was later acquitted after they tried to ruin his life.
- balamolekule 7mo ago[dead]
- the_other 7mo agoAs the attack actor now has the data, they're liable for ongoing GDPR failures, on top of the theft. Then anyone they sell the data to becomes liable (on top of handling stolen goods). Could be a money-earner for the EU if they pursue it properly.
- noosphr 7mo agoI like paper documents for this very reason. It's very hard to steal everyone's documents when they weight about the same as a train.
- latexr 7mo agoBut it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.
- HelloUsername 7mo ago> it’s easy to lose all of them in a fire or flood Wouldn't a fire or flood affect everything? Both data stored on paper and hard disks?
- jagged-chisel 7mo agoThe good news is you can keep offline, offsite digital copies, which is much more convenient than offsite paper copies.
- Gabrys1 7mo agoI think what the comment meant was that it's harder for an individual to lose their paper documents compared to losing the electronic ones. It just shifts who's responsible for keeping them safe
- bell-cot 7mo agoProblems with well-known solutions 100 years ago: "Fireproof file rooms and cabinets in the 1920s were crucial for protecting business and government records during the rapid expansion of the industrial era. The era saw a massive shift from flammable wooden office furniture to robust, steel-based storage designed to resist both fire and water damage." That's a Google AI summary - but I've been in a fair number of buildings with such rooms. Thick concrete walls, heavy steel fire doors, no other openings, nothing but steel file cabinets in 'em, sealed electric light fixtures that look like they belong in a powder magazine (where one spark could kill everyone) - it's really simple tech. And "high ground" was a reliable flood protection tech several centuries before that.
- JensRantil 7mo agoI am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.
- yaris 7mo agoI would guess that skatteverket.se, polisen.se, kronofogden.se are among those affected by the leak.
- brabel 7mo agoSome other comments mention BankID private keys . That would be the biggest disaster as that’s what everyone uses to identify themselves “securely” on all government services.
- mrkickling 7mo agoThe private keys in BankID are stored in users phones, not centrally.
- fmbb 7mo agoWell doesn’t Relying Parties using the BankID API for signatures and authentication have private keys to start the flows for users scanning QR codes etc? Could you, having the right private keys, impersonate some company soliciting a BankID signature? I’m not sure what you can do with that though. You cannot steal some other ongoing signature I guess.
- pastage 7mo agoYou can start a signing process saying you are who ever owned that certificate. E.g. if you call someone. You can not use those signatures to gain access, and it is rather in phishing.
- einr 7mo ago
- corroclaro 7mo agoThis keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security". Several government organisations / regional authorities and companies were down. Last I heard several medical journals for whole municipalities were just destroyed. Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity, are suspicious of things like zero-trust, follow outdated engineering practices. Sigh.
- bengale 7mo agoThe tender process is what they are optimised for. They are professional project bidders with a bit of outsourced software development bolted on the back.
- Maxion 7mo agoA lot of outsourced development. The tender process + clueless buyers + tender process law(s) cause this. Whole process needs a revamp for this to not be a problem.
- vladms 7mo ago> Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity So what you think would be the solution ? From what I see (both public tender or not), I would claim that "any large IT project/company will suffer from security issues", so not sure what is the added value to single out a process (the tender) or a region (Europe) if there is no obvious alternative.
- xorcist 7mo agoI have (the start of a) solution, but it's a boring one: You have to have people who care about this stuff. If you don't care, the rest does not matter. It does not matter if, when and how you outsource if you don't care about the outcome. You can't just pay someone a salary, nor a consulting bill, check the box and say you've done your part. And the other way around: These huge consulting conglomerates would get very few jobs if purchasers cared about the details, and not just that all the boxes are checked.
- blin2h 7mo agoWhat forum is the original screenshot from? It reminds me of cs.rin.ru
- bubbi 7mo ago[dead]
- agluszak 7mo agoe-government services should be open-sources by default!
- nunobrito 7mo agoNow there is an additional reason for that. Public money, public code.
- 1718627440 7mo agoI sometimes also would like that, but you might reconsider that stance when your country is in war with another one.
- wasmitnetzen 7mo agoSwedish news has some quotes from authorities that nothing of value has been leaked, and a quote from the service CGI that it only concerns test servers.[1][2] [1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-information-har-lagts-ut-pa-darknet https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform... [2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-om-incident-kopplad-till-interna-testservrar https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...
- whizzter 7mo agoAs a Swede this is giving me shudders, the statements reeks of paper-pushers and certification-chasers that don't seem to understand fundamental risks of how how threat actors can move around once having established footholds, hopefully there's more competent people down in the trenches.
- cactusplant7374 7mo agoAre we allowed to vibe code some positive changes and submit them for review?
- sandos 7mo agoI dont know nothing about this particular leak, but I have worked at Skatteverket. Let me just say, the likelihood that CGI would have any _actual_ real personal data is close to 0%, at least on servers outside of Skatteverket. I had access to absolutely nothing even working inside. I have never worked in a more closed-down system, maybe excepting the swedish military "complex". No, actually that was less locked down in a way, at least once you were "inside" the system.
- deleted 7mo ago[deleted]
- yaris 7mo agoKnowing swedish people's mindset I'm not surprised at all by the breach. What can be mildly surprising is that no major e-gov service has expressed concerns on their websites. Only on skatteverket.se, which is Swedish Tax Service website, there is a vague note on "maintenance work" planned for coming Saturday. Maybe totally unrelated though.
- queuep 7mo agoInteresting, care to elaborate?
- corroclaro 7mo agoI'm pretty sure they did an internal analysis by 8 AM at all these places and came to the conclusion that they're OK. Of course, they might be wrong!
- WhereIsTheTruth 7mo agoAs long as cronyism remains the primary qualification for leadership, nothing will ever change, worse, it's only going to get worse Accountability now, send these people to prison
- elwebmaster 7mo agoAnything taxpayer funded should be open source to begin with.
- fsflover 7mo agohttps://publiccode.eu https://publiccode.eu
- teroshan 7mo agoSimilarly taxpayer funded contracts for any type of infrastructure (obviously I have digital infrastructure powered by proprietary solutions in mind) should only be awarded if interoperability is guaranteed to prevent lock-in and abuse.
- wayfwdmachine 7mo agoOk, some important context for non-Swedes. Anyone can get access to all Swedish (non-protected but those are a very VERY small subset) personal identification numbers by simply signing an agreement with SPAR[1] (the Swedish national people database). Identification numbers per se are not particularly useful or hard to get, they are effectively public information. Using SPAR you can also get the home (and any additional) addresses of individuals A Swedish citizen database is... you know. fun. But not exactly hard to get hold of. [1] https://www.statenspersonadressregister.se/master/start/english-summary/ https://www.statenspersonadressregister.se/master/start/engl...
- petcat 7mo ago> by simply signing an agreement with SPAR But that seems like a completely different thing than a nefarious and anonymous person or group having access to the entire database.
- wayfwdmachine 7mo agoYeah, nefarious or anonymous people have never used the internet so they could never find out that this was all public information.
- petcat 7mo agopublic information if they signed an agreement with the Swedish government?
- einr 7mo agoNo, public information for anyone. You realize that if it's public information, then it's public, and anyone can re-publish it online? There are websites for that. I can get the complete identification number, home address, phone number, etc for any Swedish citizen (that does not have a protected identity) in less than a minute.
- 7mo ago
- olalonde 7mo agoAnyone knows what their tech stack looks like?
- bkummel 7mo agoI see comments about Swedish personal identification numbers. But the article is about source code that's leaked, not a database of numbers, right? I was thinking: should government source code not be open source anyway?
- johnisgood 7mo agoIdeally they should be open.
- FateOfNations 7mo agoThe same attackers are releasing the database of personal information separately (for a fee). That said, Sweden takes a different approach to PII, so most of that information would have already been public. You can generally just look up any resident and their ID number and other biographical details in a public directory (among other things… their tax returns are also public records).
- FpUser 7mo agoUnless they hardcode passwords and other juicy details in their source code what's all the fuzz about? It is a publicly funded thingy anyways.
- hollow-moe 7mo ago"Government surprisingly fulfills its duty by making publicly funded source code public"
- GuB-42 7mo agoFirst reaction: How come the source code is not public in the first place, accessible to every Swedish citizen? They paid for it! But it turns out that more than the source code was leaked.
- Lliora 7mo agoWorked on a similar platform. The real risk isn't the code - it's the config files. Government deployments have hardcoded staging credentials, VPN endpoints, and encryption keys that don't get rotated when code leaks. Source is whatever. Those env files are the skeleton key.
- Schlagbohrer 7mo agoWhy was all that software not open source already?
- vladde 7mo agoCGI has a lot of consultants in both government and municipal places (i've worked at both), and some of our main tools like time reporting was built as a addon to our personnel system by consultants at CGI. half my team are consultants from CGI, 4 out of 7 people. also: hi tavro! it's been a few years, how have you been :D
- butz 7mo agoMost important question: do Swedish e-government services use curl?
- PeterStuer 7mo agoMisleading title, as my first thought was "why is Sweden's egov not open source to begin with?". Turns out it's about data.
- Surac 7mo agofollowing AI corp logic that everything in the internet is open source we have a open source goverment in europe now
- deleted 7mo ago[deleted]
- dspearson 7mo agoIt's odd to me, as a Brit, to see that this stuff was not mostly public anyway. (looking at you https://github.com/alphagov https://github.com/alphagov)
- rognjen 7mo agoHot take: all government code should be open source.
- rkomorn 7mo ago[dead]