frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Denmark Data Breach Exposes 8.8M People's Personal Data

https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-o...
94•clan•2h ago•53 comments

Huawei and Qualcomm Announce Broad Patent License Agreement

https://www.huawei.com/en/news/2026/10/qualcomm-broad-patent-agreement
59•0xedb•2h ago•33 comments

Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s

https://github.com/Niko1221/Strata
809•snehesht•21h ago•356 comments

In the wake of Tippett Studios’ closure, a digital archive appears online

https://filmstories.co.uk/news/tippett-studios-in-the-wake-of-its-closure-a-digital-archive-of-an...
140•rdmuser•13h ago•17 comments

We ported the original Doom to SQL

https://cedardb.com/blog/sqldoom/
116•Vaslo•1d ago•14 comments

A browser-native classic Visual Basic VB6 IDE

https://wieslawsoltes.github.io/VB6/
245•wiso•15h ago•79 comments

Gods in the Classroom: Religion and Education in First Millennium BCE Babylonia

https://www.cambridge.org/core/journals/iraq/article/gods-in-the-classroom-religion-and-education...
38•pseudolus•3d ago•11 comments

The Tao of Backup

http://www.taobackup.com/index.html
144•vntok•2d ago•50 comments

Infidel goes wild

https://blog.zarfhome.com/2026/10/infidel-goes-wild
139•tobr•1d ago•22 comments

Replacement of petroleum based products with plant-based materials (2025)

https://onlinelibrary.wiley.com/doi/10.1002/eng2.70108
66•thelastgallon•5h ago•30 comments

Turn off Apple Intelligence on macOS 27 and get its disk space back

https://github.com/omlahore/RemoveMacAI
576•privacyisntdead•14h ago•399 comments

Tell HN: Bob Cringely has died

875•paveworld•1d ago•188 comments

First Implantable Cochlear Implant Launches

https://spectrum.ieee.org/fully-implantable-cochlear-implant
8•rbanffy•3d ago•4 comments

Decision models like Jev don't beat LLM-as-a-judge or traditional classifiers

https://developers.redhat.com/articles/2026/10/02/benchmarking-ai-decision-models-against-traditi...
66•tomncooper•2d ago•17 comments

Demystifying Tufte's data-ink ratio

https://tuftesrazor.scienceux.org/
49•s4074433•2d ago•18 comments

Powerless F1 drivers frustrated by Bahrain F1 software glitch

https://www.motorsport.com/f1/news/horrible-totally-unacceptable-powerless-f1-drivers-frustrated-...
205•llm_nerd•8h ago•172 comments

Improper redaction reveals Google Data Center water and electricity usage

https://www.1011now.com/2026/09/30/more-questions-than-answers-about-lincolns-google-data-center-...
397•sensanaty•14h ago•517 comments

Automating my 35mm film scanning pipeline

https://shannadige.com/blog/darkroom/
78•shannadige•1d ago•57 comments

'Neanderthals Among Us' review

https://www.historytoday.com/archive/review/neanderthals-among-us-peter-sahlins-review
76•pepys•1d ago•76 comments

What is going on with ceiling fans

https://mcmansionhell.com/post/829127919552151552/what-is-going-on-with-ceiling-fans
312•colinprince•4d ago•268 comments

Watson Jr. memo about CDC 6600 (1963)

https://www.computerhistory.org/revolution/supercomputers/10/33/62
44•mooreds•1d ago•23 comments

Show HN: Glashütte Trash Clock – A 30-minute pendulum clock made from trash

https://niklasroy.com/gtc/
199•r0r0•3d ago•30 comments

Self-hosted HTTP tunnels with SSH and Nginx

https://vincent.bernat.ch/en/blog/2026-http-over-ssh
141•renehsz•11h ago•32 comments

Safe Optimistic Lock Coupling

http://databasearchitects.blogspot.com/2026/04/safe-optimistic-lock-coupling.html
16•greghn•3d ago•0 comments

Bill Draper has died

https://www.nytimes.com/2026/09/30/technology/william-draper-dead.html
121•bookofjoe•21h ago•38 comments

How to scale intent, quality, and artistry with AI [video]

https://www.youtube.com/watch?v=GLvFTMtw4Jk
86•simonjgreen•1d ago•31 comments

Interview with Chicken Scheme Maintainer Sjamaan/Peter Bex

https://alexalejandre.com/interviews/peter-bex/
42•veqq•2d ago•11 comments

Lace and Labor: Lessons from the actual Luddites

https://articlesofinterest.substack.com/p/lace-and-labor
20•surprisetalk•4d ago•1 comments

Sales of sub-€25,000 electric car models set to rise sevenfold

https://www.transportenvironment.org/articles/wave-of-affordable-electric-cars-is-boosting-consum...
56•geox•2h ago•82 comments

Blindsight (Watts Novel)

https://en.wikipedia.org/wiki/Blindsight_(Watts_novel)
90•mooreds•17h ago•100 comments
Open in hackernews

Denmark Data Breach Exposes 8.8M People's Personal Data

https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger
90•clan•2h ago

Comments

johnwalker67•2h ago
I am so done, my cpr is leaked oh no. Like I don't
clan•1h ago
This is were security meets the real world. The number is not secret but people have been taught to keep it confidential. And when you know the last 4 digits social engineering har become a lot easier.
Ekaros•1h ago
On positive side maybe now there is no reason to use it for authentication anymore. When it was always unsuitable for that reason.
clan•42m ago
I used to agree.

But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.

This will be easy to exploit on a scale.

Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.

aDyslecticCrow•1h ago
CPR isn't the problem, the rest of it is.
clan•1h ago
CPR is the national register of all people (Central Person Register).

CPR is the administrator. There is more information in the linked press release from the ministry:

https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.

The only current english language sources are paywalled:

https://www.thelocal.dk/20261005/hackers-get-personal-info-o...

https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...

Non-paywalled but major danish news outlet (National Brodcaster):

https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...

lode•1h ago
Another non-paywalled English article from a Danish source: https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
clan•1h ago
For those not getting the scope of this. The following has been compromised for all living danish citizens and foreign nationals which have had recidence. And quite a few dead ones as well.

- Social security number

- Age

- Sex

- Family relations

- Physical address

- Protected addresses

- Sex change

This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.

delamon•38m ago
They say that persons with protected address had not been leaked.
toyg•16m ago
What's a protected address, witness relocation programs...?
LarsKrimi•4m ago
When you change your address you can click a checkbox saying you want a protected name/address. This means that companies that have you as customers/clients won't be able to get the new address, mail won't be redirected, etc

I did it accidentally during my last move and it was a pain in the behind

And it expires after a year by default so it feels rather pointless

kasperni•30m ago
Nobody knows exactly what was accessed. What you have listed is what the register contains, not what was accessed. People with "Protected addresses" have specifically not been compromised.
archixe•1h ago
The article mentions that they accessed the information through a Danish company whose access has been revoked now. I find it really surprising that a company could access these records without any limitations on which info or how many records they can pull.
ntoskrnl_exe•49m ago
Just that easily all the private conversations of everybody in the EU can leak if Denmark succeeds at outlawing E2E encryption with its Chat Control proposal.

Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.

raxxorraxor•3m ago
I heavily doubt these people are open to self-criticism in any way. They have their program and are set to implement it.
aiiotnoodle•44m ago
I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.

I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.

There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.

amelius•39m ago
I mean why does every hotel need to make a copy of my passport?
Razengan•34m ago
And why are politicians immune to all of this shit??

Why can’t WE spy on them 24/7?

lynx97•27m ago
If democracy really worked, and your desire to spy on politicians is shared by enough people, supposedly, you should be able to create your own party which has that explicit goal. Maybe find a few other goals, or you will end up like the pirates :-)

I am writing this because I don't think democracy works as advertised.

sparkling•17m ago
jakub_g•41m ago
In the past few months, there were several huge data leaks also:

- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)

- in France (from tax office), 678k people affected

With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.

233mhz•19m ago
Gun ownership records were leaked in france recently too, including identity and address.
rvz•39m ago
Let me guess, the Danish government will find a way to prove that GDPR doesn't apply to them.

But this is incredibly bad.

shiandow•25m ago
It does apply but they were allowed to have this data and GDPR does very little to protect it in that case.
Quothling•35m ago
As someone who spend a decade in the Danish public sector, among other things working in groups on national architecture. I'd say that we reap what we sow. IT and digitalisation is not taken very serious in our public sector. In most places it's placed under something, and until recently it didn't have it's own ministry. Right now it's even a shared ministry, and there is little focus on cyber security. What has arrived in recent years is solely based on the thread of hybrid attacks from Russia.

Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?

My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.

Mashimo•12m ago
> IT and digitalisation is not taken very serious in our public sector.

I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.

hastily3114•29m ago
As someone who works with CPR data in Denmark, this does not surprise me at all. Private companies access the data through an API, and anyone who works at such a company can look up CPR data as they please.
KingOfCoders•19m ago
If people don't go to jail, there will be no change.
LarsKrimi•18m ago
Altman at it again?
thiagoperes•16m ago
it feels this will keep happening specifically to Europe for three reasons: a) most countries took an anti-AI approach b) they reject frontier models in favor or "Sovereign" solutions c) they're replacing software with weaker/more vulnerable options

public servant engineers are token poor and will be out of the latest defense tools

Mashimo•11m ago
I don't think this is AI related at all. What makes you say that?
gnull•14m ago
In Sweden, to avoid this kind of malicious leaks, we leak the residents' data officially. https://hitta.se lets you look up personal numbers, names, addresses, birthdays and sometimes phone numbers of any resident. The residents are not asked for consent, the data goes there automatically (some of my friends had success with having it removed from hitta, but it comes back once you change residence address).

It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.

What's the big deal, Danes? What do you have to hide?

(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)

sajithdilshan•11m ago
I was actually surprised when I heard about this for the first time. Also I've heard that even the salaries of people are publically available. That's really cool.
wodenokoto•25m ago
I think it is worth mentioning that age and sex is encoded in the social security number.

There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.

vasusai•21m ago
Where did you get that from? All I saw was: names, addresses and CPR numbers.

Additionally it was via third party access granted to private companies.

https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

Mashimo•16m ago
CPR number contains Age and Sex. It's date of birt DD MM YY. Plus four digits where you can read the sex from. I think it's even vs uneven numbers.
Because you are a slave, Neo.
ElDji•28m ago
It is a basic police requirements on most countries. Hotels must collect visitor id's and keep it for several weeks.
toyg•20m ago
Yeah, it's old-school people control. This said, these days it could be done electronically, without the hotel storing physical information: at check-in, you put your passport in goverment-issued, (hopefully) tamper-proof machines, the hotel confirms length of stay, police server gets the info and that's it; early checkouts, the hotel must notify via some web portal. It would be relatively easy to implement.

But nobody really cares enough to spend money modernising this sort of system.

carlosjobim•10m ago
All these giant data leaks are coming from the government's "tamper proof" systems!
peri-cl•9m ago
I'm not clear why a free society needs to track peoples' movements at all.

Maybe HN's still on the pro-privacy side on the car-tracking cameras stuff, but, with regards to where people sleep at night, that frog has been thoroughly boiled.

GJim•5m ago
> This said, these days it could be done electronically

Are you 'avin a laugh mate?

A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.

The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.

tokioyoyo•28m ago
I said it before as well, but it’s because nothing “publicly really bad” happened despite the leaks and stolen information over the past decades. After Equifax breach, everyone got tired, because company survived, and whatever identity theft happens from time to time gets swept under the rug. It didn’t impact most people’s lives, despite leaking half of the US’s SSNs and etc. Then fatigue kicked in, and with subsequent leaks everything just mellowed down, so nobody cares.

I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.

strideashort•20m ago
I recently needed a lawyer on something that involved lots of highly sensitive PI.

Sending my file over to lawyers in a semi-safe way has proved impossible.

And in any case, i received an answer with lots of PI over a plain email…

Absolutely maddening

Hamuko•15m ago
I’m never going to a therapist after one company leaked all of the patient data / therapy notes for 33k patients.
ratg13•15m ago
This is just a general American complaint that has merit on its own, but has nothing to do with the article and is just derailing any discussion about the article itself and driving the conversation to your own personal concerns about something completely separate.

In this case, the EU does have consequences for data breaches where proper protocols are not followed.

Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.

In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.

In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.

In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.

suslik•6m ago
I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point.

All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.

The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.