frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
49•baal80spam•52m ago

Comments

imdsm•30m ago
not ideal
donalhunt•29m ago
In Denmark, a CPR number (short for Det Centrale Personregister, or Central Person Register) is a unique 10-digit personal identification and social security number assigned to every resident and citizen.

Equivalent to social security information in the US I guess.

lordnacho•15m ago
It's unique, but it encodes your birthday and sex.

There's only 500 numbers it could be, assuming someone knows those other things about you.

In any case, there are alternative systems for authorisation.

usrnm•6m ago
You're contradicting yourself, how can it be unique if only 1000 can be assigned per given date of birth? What if more than one thousand babies are born in the country one day?
piva00•4m ago
It's Denmark, it won't have 1k babies born the same day.

It's the same in Sweden YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.

tannertech•4m ago
That's a problem for future Denmark!
INTPenis•29m ago
I love getting to the root cause of these incidents. Hate it when they just move on with no post mortem, the rest of us are trying to learn here!

Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?

piker•29m ago
That’s the same combination I have on my luggage!
Sau1707•18m ago
I bet you are not the only one!
justinclift•14m ago
The Spaceballs piece about it: https://www.youtube.com/watch?v=a6iW-8xPw3k
HPsquared•10m ago
Funnily enough, luggage calls back to those TSA locks.
m00dy•28m ago
lol, it's a joke right ?
lordnacho•20m ago
Completely real.
lifestyleguru•27m ago
For 1-2 years now strictly IT companies are on Copilot, non strictly IT companies on autopilot, and in neither case there are any pilots. Hopefully the default installation and configuration of everything will solve all your problems because there is nothing else.
zweifuss•24m ago
I’m less shocked than I should be. National ID registries can be incredibly convenient, but when something goes wrong, it can go terribly wrong. Despite my general misgivings, I hope the IT company is visibly held accountable.
sethammons•20m ago
What would that accountability look like?
gunalx•18m ago
Not existing preferably.
tannertech•12m ago
Strange way to say prison time. Or if you meant capital punishment harsh but fair.
lifestyleguru•8m ago
Intensify the "beware of scammers and identity thief" campaign. Go all in - unblockable SMS's, emails, and notifications. Treat any feedback and objection as an attack.
sneak•20m ago
The question really becomes: why do so many organizations seem to know absolutely nothing about well-publicized and well-documented best practices? How does a government completely lack controls or oversight for basic competence?
LarsKrimi•16m ago
Privatization

It was run by DXC Technology, the Danish branch of a US software house.

When doing a contract on such programs the Danish government must take the cheapest offer by rule

GuestFAUniverse•11m ago
What could go wrong? /S
tokai•14m ago
Its interesting, while private companies just blast our data out there, I cannot install the software I need to do my work because the state IT provider blocks it on security grounds. Its all very tiresome.
GuestFAUniverse•6m ago
Been there. Waited more than three years for a host to be properly accessible within a hospitals network. Project related.

Since then I think medical data science is mainly a waste of tax payer's money.

sokols•10m ago
I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
iLoveOncall•7m ago
Or simply make people who choose insecure passwords criminally responsible for the fallout.
zweifuss•5m ago
A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.
croes•10m ago
Did they have MFA?
zkmon•6m ago
I wouldn't the blame the guy. The security teams tend to serve entirely security related goals only, and they don't hesitate to stop all activity, if they are allowed to, to ensure the highest level of security. On the other side, there are people who have goals for productivity and getting work done. They don't hesitate to take the shortest route possible to maximize their productivity. If productivity is not your goal, then security is not my goal.

It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.

mattlondon•4m ago
If only they had insisted on an 8 character password!

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
54•baal80spam•52m ago•33 comments

REA Reverse – Engineer Anything

https://rea.tools/
446•modinfo•10h ago•175 comments

Telegram Desktop vulnerability allowed any user's file to be stolen

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
188•g-b-r•7h ago•88 comments

Cloudflare acquires Deno

https://deno.com/blog/cloudflare
1244•ilreb•21h ago•631 comments

WSL3 Performance is about 5-60% faster than WSL2 depending on the workload

https://tonym.us/wsl2-vs-wsl3-benchmarks.html
42•tonymet•2d ago•17 comments

Triple-A Minesweeper

https://minesweeper.mikelacher.com/
1001•robin_reala•18h ago•197 comments

Eye of Sauron: Long-Range Hidden Spy Camera Detection (2024)

https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-qibo
168•ortusdux•2d ago•38 comments

Food processing influences metabolism and brain activity

https://news.vt.edu/articles/2026/10/research_fralinbiomed_upfhutelin.html
44•gmays•5h ago•24 comments

Cube Type – Isometric Typography Generator

https://typeincube.com/
18•eustoria•1d ago•1 comments

Computers Cannot Make Decisions

https://wiki.cateat.fish/art:computers_cannot_make_decisions
90•heavensteeth•4h ago•75 comments

Can you use autoregressive diffusion to generate market data?

https://blog.janestreet.com/can-you-use-autoregressive-diffusion-to-generate-market-data/
94•jsomers•19h ago•27 comments

Show HN: Carrier-Explode: iPhone, Pixel and Galaxy carrier settings decoded

https://carrierexplode.com/
332•simplyalec•16h ago•42 comments

Typesafe AI raises $870M at $7.5B

https://typesafe.ai/blog/series-ai
378•tosh•17h ago•277 comments

Compiling Rust to readable C with Eurydice

https://lwn.net/Articles/1055211/
83•peter_d_sherman•11h ago•18 comments

How to head into VR without wearing a headset

https://www.kyushu-u.ac.jp/en/researches/view/414/
35•Betelbuddy•3d ago•15 comments

I tried to move my notes out of Emacs. I failed. Again

https://baty.net/posts/2026/10/i-tried-to-move-my-notes-out-of-emacs-i-failed/
33•speckx•2d ago•32 comments

Clinical trial of a prion disease drug candidate begins enrolling participants

https://www.broadinstitute.org/news/clinical-trial-prion-disease-drug-candidate-begins-enrolling-...
75•luu•10h ago•13 comments

Noto means "no tofu": fixing dotted circles in Myanmar text

https://www.datocms.com/blog/handling-less-common-scripts
3•steffoz•3d ago•0 comments

Pointing AI at archives found a forgotten meteorite, lost rhinos, and more

https://jessewaites.com/blog/post/i-pointed-ai-at-400-years-of-archives/
148•piratebroadcast•23h ago•76 comments

What mathematicians should know about the Lean Theorem Prover: reliability & AI

https://terrytao.wordpress.com/2026/10/09/what-mathematicians-should-know-about-the-lean-theorem-...
120•matt_d•17h ago•23 comments

Scam American companies are using to manipulate ingredient lists

https://twitter.com/WallStreetApes/status/2108594998656807078
125•bilsbie•17h ago•141 comments

Show HN: Proton Drive for Linux

https://oss.lsantos.dev/proton-drive-linux-fs/
86•khaosdoctor•2d ago•30 comments

'Wallace and Gromit,' 90% Alone

https://animationobsessive.substack.com/p/wallace-and-gromit-90-alone
220•vinhnx•20h ago•29 comments

The role of cat eye narrowing movements in cat–human communication (2020)

https://www.nature.com/articles/s41598-020-73426-0
86•bushwart•3d ago•36 comments

Our $445M Series D

https://oxide.computer/blog/our-445m-series-d
661•ahlCVA•21h ago•296 comments

Vegetative Electron Microscopy WTF? (2025)

https://www.sciencebase.com/science-blog/vegetative-electron-microscopy.html
16•adunk•1d ago•1 comments

YouTuber Says Cops Visited Him After He Built a Flock-Style Camera to Track Cops

https://gizmodo.com/youtuber-says-cops-paid-him-a-visit-after-he-built-flock-style-camera-to-trac...
578•gumby•13h ago•312 comments

Sorry, I'm in a meeting

https://iminafleeting.com/
913•splintersio•1d ago•256 comments

Show HN: The rarest tech books and docs you've probably never read

https://readrare.com/
134•miletus•17h ago•48 comments

Communication Between the Compiler, the Build System, and Beyond

https://shrub.industries/words/problem.html
17•shrub900•3d ago•3 comments