117 points baal80spam 1 hour ago 77 comments
donalhunt 1 hour ago | parent
Equivalent to social security information in the US I guess.
lordnacho 1 hour ago | parent
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
usrnm 1 hour ago | parent
piva00 1 hour ago | parent
It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.
ls65536 48 minutes ago | parent
onionisafruit 29 minutes ago | parent
edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.
It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.
polack 33 minutes ago | parent
madmoose 30 minutes ago | parent
tannertech 1 hour ago | parent
gus_massa 48 minutes ago | parent
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
INTPenis 1 hour ago | parent
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
piker 1 hour ago | parent
Sau1707 1 hour ago | parent
justinclift 1 hour ago | parent
HPsquared 1 hour ago | parent
bryanrasmussen 28 minutes ago | parent
wrecked_em 8 minutes ago | parent
lifestyleguru 1 hour ago | parent
zweifuss 1 hour ago | parent
sneak 1 hour ago | parent
tokai 1 hour ago | parent
GuestFAUniverse 1 hour ago | parent
Since then I think medical data science is mainly a waste of tax payer's money.
sokols 1 hour ago | parent
iLoveOncall 1 hour ago | parent
bryanrasmussen 29 minutes ago | parent
zweifuss 1 hour ago | parent
croes 1 hour ago | parent
zkmon 1 hour ago | parent
It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
ano-ther 59 minutes ago | parent
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
tialaramex 56 minutes ago | parent
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
tossandthrow 52 minutes ago | parent
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
ulfbert_inc 55 minutes ago | parent
xandrius 37 minutes ago | parent
altmanaltman 53 minutes ago | parent
ntoskrnl_exe 34 minutes ago | parent
nylonstrung 23 minutes ago | parent
kay_o 52 minutes ago | parent
tokai 42 minutes ago | parent
mattlondon 1 hour ago | parent
ano-ther 1 hour ago | parent
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
tuwtuwtuwtuw 49 minutes ago | parent
olau 40 minutes ago | parent
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
tuwtuwtuwtuw 28 minutes ago | parent
nylonstrung 21 minutes ago | parent
caaqil 55 minutes ago | parent
ionwake 51 minutes ago | parent
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
bombcar 44 minutes ago | parent
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
tokai 6 minutes ago | parent
aussieguy1234 50 minutes ago | parent
ZuoCen_Liu 49 minutes ago | parent
bricss 49 minutes ago | parent
nslindtner 46 minutes ago | parent
ptnpzwqd 37 minutes ago | parent
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
boxed 9 minutes ago | parent
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
mhd 22 minutes ago | parent
eviks 11 minutes ago | parent
wrecked_em 11 minutes ago | parent