2.7M Medical Calls Breached in Sweden
hjorthjort.xyz
hjorthjort.xyz
TBH I find this “off with their head” mentality to be counter productive. Sure, if someone broke the law then administer justice. But it’s not addressing the root cause. What systemic weaknesses led to this scenario, and what systemic changes can we make to prevent it from happening again? That’s a much more productive discussion to have, although doesn’t appeal to our baser instincts and so won’t score easy political points.
And still there are people wanting more government control. Mind boggling
* How to pin-point one or a group of individuals to blame within the company? What if it is someone that has long moved to another company?
*Does finding a scapegoat and forcing someone out of their jobs resolve the matter? Whats the impact in that person's lives? Was it just for the masses to feel better?
To be honest, I think society is rewarding the wrong attitude in some cases. Someone in the reporter's position should have raised the issue to the relevant authorities and after the issue was resolved (at least partially), he should have made a request to publish an article talking about what happened, how many people could have been impacted, the actions he took. The outcome could have been that the reporter receives an award for his work and appreciation from society for raising awareness in the area, the government talking about concrete actions they have/will take, other companies and society works towards improving said issue.
I did not intend to say that we should go outside of the confines of the law here and lynch anyone. But I sincerely hope that our legal system has the power to punish gross negligence (I mean that in an everyday sense, not as a legal term) and that officials and CEO's can't get away with anything by just burying it under several levels of procurement. The company in question was obviously not competent enough to handle the data that they received, and it is gross negligence to take on this kind of project without doing a proper audit of their systems and methods. At the very least, their handling was against GDPR, which should result in fines.
Yet somehow, they ended up with the project. That is negligence on someone else's part. If you're hiring contractors to build a highway bridge, you should be held liable if you pick the local carpenter to do the job, just because they say they definitely know how to make it out of wood. I hope that the legal system can punish governmental officials and government contractors for handing off sensitive data to a party that isn't even aware of how incompetent they are, and that merely the procurement can be considered illegal.
If my hopes are not fulfilled, and one can indeed hand off all responsibility in a procurement process, then I instead hope we will see the law change in this regard.
As for people losing their jobs, I think that warrants no explanation.
Still, I agree: the issue isn't bad actors, the issue is the process, and it needs to be addressed. But part of a good system is not letting contractors getting away with bullshit, and making sure something is at stake when you take on a contract. If you can walk away from this wreckage without consequences, what's to stop you or anyone else from continuing to play fast-and-loose (which is usually the cheapest way to do things) with the public's data, raking in the payments and shrugging it off when things blow to pieces?
I understand I could have made that clearer, and I'll think about how to change my wording, or adding a footnote or something.
https://omni.se/medhelp-polisanmaler-tidning-efter-avslojand...
Of course if he hadn't, he wouldn't have been able to write a story about it and the security holes would not have become public knowledge.
The laws in these areas are insanely antiquated and this is not the first time investigated people in power have tried to use them to silence or smear journalists. Freedom of speech is threatened.
The case should be dismissed.
These accusations seem completely baseless. The data was public and could probably be found using one of several public search engines.
Apart from that, the journalists could also claim they were given the link by someone, in which case it would even be illegal to investigate the source. This lawsuit was not filed to win.
As an individual I wouldn't want to publish info on a security breach though.
Yeah, no, that's not how you do these things...
I know nothing about this particular case however. It may very well be a royal fubar every step along the way. It was just interesting how some thought the government responsible even for private companies found breaking the law.
It was discussed
[0] https://omni.se/medhelp-polisanmaler-tidning-efter-avslojand...
https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
A very objectionable fellow, but I'm sure they'll move on to more sympathetic ones now that the precedent is set.
That's the real precedent here. The feds can and will throw you in prison for years for not comitting a crime.
My (foreign layman's) take on it is that the lower court precedent still stands, as it was not formally overturned.
"Forælderen, Henrik Høyer havde blandt andet opdaget, at den infoskærm, som hver enkelt børnehave havde i systemet, var befængt med et sikkerhedshul, der tillod cross-site scripting. Ganske enkelt blev de beskeder, som man skrev til den fælles infoskærm, ikke renset for tegn, der gør det muligt at indsende Javascript-kode.
Det udnyttede Henrik Høyer til at skrive en simpel Javascript alertbox, der poppede frem med beskeden 'Ring til Infoba og sig at jeres nye intranet løsning er blevet hacket', hvorefter brugeren skulle trykke ‘OK’.
Det var der flere af pædagogerne, som så, og som undrede sig over, ifølge Infobas produktchef.
»Jeg skrev til Infoba og hørte aldrig fra dem. Så lavede jeg den her løsning, som måske var lige på grænsen for, hvad man må,« siger Henrik Høyer og fortsætter:
»Jeg lavede et harmløst javascript, men kunne have gjort det meget værre.«"[0]
(Sorry for the danish ya'll)
[0] https://www.version2.dk/artikel/foraeldre-finder-banale-sikk...
https://www.version2.dk/artikel/derfor-blev-henrik-hoeyer-fr...
on the other hand one could analyse all the calls and provide a helpful medical bot.