frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Source code of Swedish e-government services has been leaked

https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/
47•tavro•1h ago

Comments

robertlagrant•46m ago
The source code is the least of it! From the article:

> citizen PII databases and electronic signing documents were also collected but are being sold separately

simonklitj•46m ago
Man, you've got to be a real low-life to sell all of that.
blell•31m ago
You've got to be a real low-life to collect all of that and put it in a database that is not air-gapped.
xorcist•24m ago
It's something akin to a service provider in SAML parlance, if we are to believe reporting. How can it be air-gapped?

And if we are to believe the hacked company, it is a development environment with test data in it. That remains to be seen, but is a risky thing to lie about. If there is production data in the leak, we will surely know about it.

lukan•17m ago
If you need the data, you cannot have it air gapped. And if it is air gapped, it is still easy to make misstakes.
dns_snek•5m ago
[delayed]
dijit•8m ago
The point of a system like this is specifically that it’s accessible and not air gapped.

Being able to validate that a citizen is a citizen and their ID is valid inherently requires the system be accessible

AdamN•45m ago
Yeah the source code isn't really such a big deal aside from helping to find vulnerabilities. The PII is a real disgrace.
worldsayshi•41m ago
I wonder if the focus on source code makes Swedish news slower to jump on this. I haven't seen it in domestic news yet. (Haven't looked too wide though)
ACS_Solver•38m ago
I saw it on SVT a few hours ago. DN and Expressen have also reported. The details about what exactly it is that got leaked are unclear (some report it's basically the code and certs responsible for BankID SSO) but this is certainly being reported domestically.
worldsayshi•35m ago
In Aftonbladet comments from CGI they seem to think that no production related data has been leaked:

https://www.aftonbladet.se/nyheter/a/ArvG0E/cgi-sverige-uppg...

jetsetman192•38m ago
Encryption keys are mentioned as well.
teroshan•38m ago
Does anyone know if there is the source code for the Swedish Armed Forces - Team Test [1] in the leak? It was a really fun collaborative flash-style game that got popular in my circle of friends for some reason back then.

[1] https://flashism.wordpress.com/2010/03/09/swedish-armed-forc...

steve1977•30m ago
Is this the open source stuff everyone is talking about?
rebolek•25m ago
Maybe they should go open source from the start, then there's nothing to leak.

P.S.: And strangers will sometimes help you find vulnerabilities (and sometimes be very obnoxious but that's not open source's fault).

Lionga•21m ago
How much GDPR fine will they pay? Oh wait it's gov so nothing / does no matter even if.

Who will take responsibility and get fired and lose all pension etc.? Oh wait no one.

Well the citizens need to suck it up.

Habgdnv•13m ago
Few years ago a huge NRA database was left public with admin/1234 or similar by the NRA. They government fined itself some non-trivial amount, then in the source/destination IBAN they put the same value and paid the fine. They managed to find someone to blame and it was not the person who left the database but the person who found it. Turns out that if you leave the PII of a whole country open to the public it is not your fault and you get to keep your cozy job. It is already unlawful to access that, so if someone access it - it is his fault - he broke the law.

Edit, i checked the facts: The Bulgarian government said that the it should pay too much to itself, and appealed the fine for few years until it somehow expired. And the guy (20 year at that time) they accused was later acquitted after they tried to ruin his life.

noosphr•19m ago
I like paper documents for this very reason.

It's very hard to steal everyone's documents when they weight about the same as a train.

latexr•12m ago
But it’s also very easy to lose all of them in a fire or flood. Different tradeoffs.
JensRantil•17m ago
I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.
corroclaro•15m ago
This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security".

Several government organisations / regional authorities and companies were down. Last I heard several medical journals for whole municipalities were just destroyed.

Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity, are suspicious of things like zero-trust, follow outdated engineering practices. Sigh.

bengale•8m ago
The tender process is what they are optimised for. They are professional project bidders with a bit of outsourced software development bolted on the back.
blin2h•12m ago
What forum is the original screenshot from? It reminds me of cs.rin.ru

Want to Win a New CanaKit Raspberry Pi 5 Starter Kit Pro?

1•pgedge_postgres•15s ago•0 comments

Prompt engineering vs. context engineering: a practical guide for AI builders

https://memgraph.com/blog/prompt-engineering-vs-context-engineering
1•taubek•46s ago•0 comments

Solder Ninja Pen: USB-powered soldering iron compatible with Weller RT tips

https://www.crowdsupply.com/sitron-labs/solder-ninja-pen
1•oxplot•8m ago•0 comments

OSS Document Scanner

https://www.akylas.fr/OSS-DocumentScanner/
1•farfromrefuge•10m ago•1 comments

Line: Language with Intuitive and Natural Expression

https://github.com/Qc-17/LINE
1•Qc17•11m ago•1 comments

40 Years of Wireless Evolution Leads to a Smart, Sensing Network

https://spectrum.ieee.org/telecom-history-1g-to-6g
2•canarymark•12m ago•0 comments

Analysis → Implementation → Reflection – a practical technique for agentic AI

https://blog.scottlogic.com/2026/03/05/analysis-implementation-reflection-practical-techniques.html
1•ColinEberhardt•13m ago•0 comments

Phoenix Arizona is likely to see its earliest 100f(38c) day on record, in March

https://www.cnn.com/2026/03/12/weather/record-heat-west-eastern-cold-whiplash
3•b33f•14m ago•0 comments

Automating the Ticket-to-PR Cycle for Power Platform Code Apps with Azure DevOps

https://agent22.sh/blog/automating-power-platform-code-app-development-with-agent22/
1•cubixle•14m ago•0 comments

Hacking the Job Interview

https://xdg.me/hacking-the-job-interview/
1•ZacnyLos•16m ago•0 comments

"Agentic" is only a marketing term

https://www.yourbroadideas.com/agentic-is-only-a-marketing-term
4•mcauldronism•16m ago•0 comments

Ask HN: Got cancer, a new job,new boss in less than a year What do I do now?

2•Goleniewski•16m ago•0 comments

Gaming on the New MacBook Neo [video]

https://www.youtube.com/watch?v=uOe-Ock4pnw
2•throwaway270925•17m ago•1 comments

Ask HN: How are remote engineers outside US/EU landing paid startup contracts?

1•valentinza•18m ago•0 comments

Show HN: Wardstone – Prompt injection and jailbreak detection API

https://wardstone.ai
1•jaaackrl•19m ago•0 comments

Show HN: Who watches the watchmen? A public decision track record for AI agents

https://www.agent-smith.org/
2•hleichsenring•19m ago•0 comments

Selling Selfcontext.com Domain

https://selfcontext.com/
1•AVancans•21m ago•0 comments

The Controllability Trap: A Governance Framework for Military AI Agents

https://arxiv.org/abs/2603.03515
1•zvr•25m ago•0 comments

Each time an AI was given a task to invent best-seller web app

https://spireason.neocities.org/apples
1•tvali•27m ago•1 comments

YC Startup School India

https://events.ycombinator.com/yc-sus-india
1•twapi•28m ago•0 comments

Fork: One CLI to Build Firmware for Any MCU

https://github.com/TareqRafed/fork
1•grog6•31m ago•0 comments

I mass-replaced FFmpeg's MJPEG decoder with Claude Code – 4K LOC, 8% the speed

https://github.com/0xD8C4A475/liberated-mjpeg
2•istenesimi•33m ago•2 comments

Need feedback to build a product for founders to track decision-making

1•shreyast6•33m ago•0 comments

The AI-Powered Kubernetes IDE

https://github.com/koreide/Kore
2•eladbash•35m ago•3 comments

AI toys for children misread emotions and respond inappropriately

https://www.bbc.co.uk/news/articles/clyg4wx6nxgo
4•fredley•35m ago•0 comments

9B parameter coding agent model fine-tuned on top of Qwen3.5-9B

https://huggingface.co/Tesslate/OmniCoder-9B
2•brainless•35m ago•0 comments

Searching for a Well Designed API

1•willx86•38m ago•2 comments

Qualcomm exploit chain brings bootloader unlocking freedom to Android flagships

https://www.androidauthority.com/qualcomm-snapdragon-8-elite-gbl-exploit-bootloader-unlock-3648651/
2•ledoge•39m ago•1 comments

Things I do when I'm writing code that don't look like writing code

https://danq.me/2026/03/06/writing-code-is-not-the-bottleneck/
1•speckx•42m ago•0 comments

Show HN: Flowly – Smooth scrolling for third-party mice on macOS

https://flowlyapp.dev/
1•simonij•42m ago•1 comments