- CSC, that handles a large part of Danish infrastructure including social security numbers, police backend, etc. has dismal security. They don't even update their software as security patches become available. Warg had access to their mainframe for 9 months without them having a clue about it. The only reason they found out was because the Swedish police called them and told them.
- username/password pairs for CSC's server were readily available on one of their subsites(!)
- Warg turned off the logs on the CSC mainframe, and they didn't notice. It appears that logs were turned off for months. As a result CSC doesn't know whether data has been altered. We're talking about all police systems, social security systems, and more.
- The police have not had their own investigative team at CSC, and haven't looked at the technical evidence. This has been done by CSC, which is an obvious problem.
- The Danish police was contacted by Swedish police three times during 2012 because the evidence from a Swedish case turned up files from CSC, and the Danish police didn't respond as they apparently didn't find the information important. During the courtcase the Danish police's chief IT investigator was caught lying about this.
- The prosecutor and judge were clueless, bordering on the hilarious, about technical issues. For instance the prosecutor refused to acknowledge that other user accounts except Wargs existed on the computer (there were 5 accounts), tried to paint putty as a hacking tool that only criminals would use, tried to establish Jacob Applebaum and Warg as friends because Applebaum retweeted one of Wargs tweets (only friends do that!), etc. etc.
These are just the highlights...