4 ms·
I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they
by JensRantil 7mo ago
I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.
- yaris 7mo agoI would guess that skatteverket.se, polisen.se, kronofogden.se are among those affected by the leak.
- brabel 7mo agoSome other comments mention BankID private keys . That would be the biggest disaster as that’s what everyone uses to identify themselves “securely” on all government services.
- mrkickling 7mo agoThe private keys in BankID are stored in users phones, not centrally.
- fmbb 7mo agoWell doesn’t Relying Parties using the BankID API for signatures and authentication have private keys to start the flows for users scanning QR codes etc? Could you, having the right private keys, impersonate some company soliciting a BankID signature? I’m not sure what you can do with that though. You cannot steal some other ongoing signature I guess.
- pastage 7mo agoYou can start a signing process saying you are who ever owned that certificate. E.g. if you call someone. You can not use those signatures to gain access, and it is rather in phishing.
- einr 7mo agoThat's an interesting guess that I assume is based on absolutely nothing?
- yaris 7mo agoYes, nothing and the facts that these are government services, they use BankID and they updated their websites with "maintenance work" announcements for tomorrow, Saturday. For kronofogden.se there was no maintenance planned just half an hour ago. Knowing swedish tendency to plan things months ahead I would _guess_ that this maintenance work has been rushed due to some circumstances.
- einr 7mo agoIt's quite possible that the maintenance is related, but I can nearly 100% assure you this has absolutely nothing to do with BankID. I don't know who suggested that but they are either poorly informed or actively trying to sow FUD.
- deleted 7mo ago[deleted]
- reliablereason 7mo agoNothing in particular, based on my understanding CGI a Swedish IT consultant company was hacked, they have contracts for and are the maintainers and developers of a bunch of various government departments IT services.
- antonvs 7mo agoCGI is Canadian, with global headquarters in Montreal.
- reliablereason 7mo agoWell they are Swedish here it is like a daughter company or something.
- antonvs 7mo agoMany global companies have subsidiaries in the countries they operate in. Aside from many other reasons, it helps make people in those countries think they're local!
- einr 7mo agoIt's not going to be a specific service or agency with a domain name, it's going to be services that are either internal and used by employees only, or that are integrated into other systems that you may be interacting with without knowing it.
- lysace 7mo agoThere is no such thing according to Peder Sjölander, IT Director at the Swedish Tax Agency: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-information-har-lagts-ut-pa-darknet https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform... – Neither our data nor our users' data has been leaked. It is a service we use for e-signatures that has been affected, but there is no data from us or our users there, says The information that source code was leaked from a joint government e-platform is not true, according to Peder Sjölander. – There is no such platform. I think the perpetrators in this want people to feel insecure. We feel confident that our data is safe and we have the situation under control before the tax return period opens next week.