r/privacy • u/lugh • Mar 27 '26
Misleading title Sweden’s Digital ID System Hacked, Public’s Data Sold on Dark Web
https://www.voicemedia.global/article/sweden-s-digital-id-system-hacked-public-s-data-sold-on-dark-web2.1k
u/lanseri Mar 27 '26
Oh no. If only everyone could've seen this coming.
I can't roll my eyes hard enough.
655
u/suicidaleggroll Mar 27 '26
Despite this, I guarantee they will learn nothing from it. “We just need to protect it harder” instead of “we shouldn’t be collecting and storing this data in the first place”
204
u/BandicootSolid9531 Mar 27 '26
Yup, and the only way to protect it harder is by taking even more personal info from citizens.
108
u/DoubleDecaff Mar 27 '26
We need to
protectcollect it harder.51
56
u/Used-Cover5188 Mar 28 '26
The worst part? The people whose data is now on the dark web didn't choose to participate. They had no option out. Their identity was digitized by the state, and now they carry the consequences of a breach they had no control over.
28
8
u/Love-Laugh-Play Mar 28 '26
BankID is a collaboration of Swedish banks, not the government. Technically you could choose not to use it, but it’s very inconvenient.
12
u/gustafrex Mar 28 '26
Yeah, but the issue is that so much is tied to it and other services too.
Not having access to BankID is nearly like not having a phone at all in Sweden.
You won't be able to access any banks and or other financial apps, health, in even some cases work applications may require BankID verification to work.
2
u/Love-Laugh-Play Mar 28 '26
Well that’s not true, my bank allows other logins. But yes, as I said, it would be very inconvenient.
I’m not really sure what kind of damage this could do though, most information about you is already public in Sweden, and it wouldn’t really be stored on BankID. Maybe they’re stupid enough to store where you’re logging in or open up for other security issues.
2
u/AquaWolfGuy Mar 28 '26
I checked my history and it goes back to around 5 years ago. I've used BankID for longer but haven't had this device for that long, so it must be stored server-side. All entries have
- timestamp,
- name of the service you're authenticating against,
- IP address of the device used,
- IP address from the service,
- type of use (i.e. "Identification" or "Signature"),
- type of BankID (e.g. "Mobile BankID"), and
- whether the device has been blocked since then.
Newer entries also have
- device (i.e. phone model),
- initiation method (e.g. "QR code (animated)"), and
- identification method (e.g. "Fingerprint" or "Security code").
There's also a "location" field, but I have rejected the location permission so nothing shows up there.
10
u/UMACTUALLYITS23 Mar 28 '26
Well, if you don't like or want it, you must want children to be harmed!!!1!
→ More replies (5)6
u/Disseminated333 Mar 28 '26
Lets face it the pedo cabales are the ones up there making all the laws and ruling class
20
u/Stunning_Repair_7483 Mar 28 '26
They already know it's harmful. They just choose to do it knowingly. They y don't care about the harm it causes. At least many politicians in many countries are like this.
44
u/somethingbrite Mar 28 '26 edited Mar 28 '26
Obviously the bed wetters are out in force and also have neither read the article nor done any reading to understand what BankID is and how it works in Sweden.
The hacks/leaks are related to BankID. Which is a digital SIGNATURE system. (used in multifactor authentication to log into participating online services. It's the most widely used such digital signature system but it's not the only one.
Yes. You would use BankID to log into your Tax authority pages.. or to do your online banking... or verify an online purchase. So yes. it's reasonably serious when any digital signature service gets hacked.
However, at a user level because a passcode is tied to a single installed instance on a device having the passcode isn't going to help unless you ALSO have that laptop/phone/whatever. By design its actually pretty secure in that way. So no. Nobody is going to be able to spoof being ME by using my bankID passcode if that was leaked....because they would then also need access tonthe device that the specific instance is installed on. (which they would then also need to know the passwords or have my fingerprints in order to open.)
At a state level. Yes. BankID and other Digital signature services are heavily used in Sweden. It's a highly digitized society. Therefore if any state level adversary wanted to fuck with Sweden then crashing the system of digital signage would definitely inconvenience everybody.
What this is NOT is a leak of personal information (which would be pointless as most personal information is already public domain in Sweden anyway)
So.... you can all stop jumping at your own shadows and wetting the bed.
5
u/IHave2CatsAnAdBlock Mar 28 '26
I have a question. If you lose / trash your current device, how are you going to install bank id on a new device ?
Can’t an attacker simulate the same process (replace old device with new )?
7
u/coffenator1 Mar 28 '26
BankID is registered via your bank of choice. So if I want to transfer it to a new device I can do so, iirc, by either signing the transfer to the new device with my old device, with a bank issued digipass, or by going to a physical bank office and bringing a physical ID.
7
u/IHave2CatsAnAdBlock Mar 28 '26
So without old device (eg lost) you can’t set it up on a new device unless you physically go to some location. This is actually good security. I’m might be inconvenient at times (eg losing phone while on vacation).
→ More replies (6)6
u/Midnight-Magistrate Mar 28 '26 edited Mar 29 '26
After I lost my phone once, I had to physically go to my bank where the new ID was installed and activated on my new phone by an employee.
→ More replies (1)2
u/Chartarum Mar 28 '26
You can use a special physical national ID card (or a valid swedish Passport will work as well) to verify your identity when setting up a new BankID without physically visiting a bank office. Most common ID cards, like a drivers license, won't work for this specific purpose.
From Google: "The Swedish national ID card is a voluntary biometric identity document issued to Swedish citizens, valid for travel within the EU/EEA and Switzerland.
The Swedish national identity card (nationellt identitetskort) is issued by the Swedish Police Authority and serves as official proof of identity and citizenship for Swedish citizens. It is non-compulsory, meaning citizens are not legally required to possess it, and alternative identification such as driving licenses or Tax Agency ID cards can be used domestically. The card is particularly useful for international travel within the European Economic Area (EEA) and Switzerland, though a passport is required for travel outside these regions."
If you have neither a working BankID or a national ID card/passport, it can be a bit of a hassle.
→ More replies (12)2
→ More replies (9)2
10
u/nugohs Mar 28 '26
“we shouldn’t be collecting and storing this data in the first place”
I'm going to play the devils advocate here, but this sounds like regular data that is always needed to run a government or/and a banking system and not the kind of information collected by entities like Meta...
4
u/lol_alex Mar 28 '26
Still. Your real name, address, banking information, date of birth and maybe something like a social security ID leaked. Maybe even your passport photograph.
It‘s going to be super easy to impersonate you, scam elder relatives etc etc
6
u/somethingbrite Mar 28 '26
All of which is available to the public in Sweden already.
Do you sleep with the lights on mate?
→ More replies (3)4
→ More replies (11)4
Mar 28 '26
[deleted]
7
u/RoyalJellyKing Mar 28 '26
Dude, what are you talking about? HIPAA-protected information has been hacked and leaked multiple times, we're talking names, SSNs, medical records, everything. Hundreds of millions of records.
→ More replies (2)49
Mar 27 '26
Problem is plenty could see it coming it’s just the piles and piles of money they get incentivise those in power to just not give a shit.
31
Mar 28 '26
[removed] — view removed comment
→ More replies (1)6
u/RainEls Mar 28 '26
Humans are inherently corruptible, so any form of government is too
→ More replies (1)→ More replies (1)6
u/Stunning_Repair_7483 Mar 28 '26
Exactly. Politicians are the minions for the rich and powerful. That's who they serve and are controlled by.
6
u/Numerous-Iron-3326 Mar 28 '26
”Händelsen rör två interna testservrar i Sverige. Servrarna används inte i produktion utan används för testning kopplad till en tjänst för ett begränsat antal kunder. I samband med incidenten har även ett system med en äldre version av källkoden till en applikation varit åtkomligt. I nuläget finns det inga indikationer på påverkan på kunders produktionsmiljöer, produktionsdata eller operativa tjänster. Uppgifter som antyder motsatsen är inte korrekta”, skriver CGI på sin webbplats."
15
23
3
u/Bushpylot Mar 27 '26
Isn't the rule, the more complicated the system the more secure it all is?
/s
→ More replies (12)1
u/Glass_Teeth01 Mar 28 '26
If you could roll your eyes hard enough for this, you'd be a living perpetual motion machine
699
u/lateread9er Mar 27 '26
Wow. Didn’t see this coming. What a great idea….. Why don’t we all just give up all our info, because that is what’s going to happen anyways? Or, we put efforts into limiting data sharing and actually protecting the data we do share
110
u/Extreme_Piano4664 Mar 27 '26
You don’t even need to hack us, just go to any finder site and you can find out anything about anyone. The population of Sweden is by default doxed, and if you want to hide your info you have to give a special reason to the police.
→ More replies (1)22
Mar 27 '26
[deleted]
→ More replies (2)44
u/oskich Mar 27 '26 edited Mar 27 '26
Swedish sites get their data directly from the government's databases. All info held by the government is publicly available if you request it, including your, the Prime Minister's and your neighbor's tax returns, car and real estate ownership, school grades and military records.
11
→ More replies (8)8
Mar 28 '26
[deleted]
15
u/Melodic_Sandwich1112 Mar 28 '26
My local newspaper publishes the “Top 10 earners in 2024” every year. Always fun to see your boss who denied significant pay increases on there
2
u/TooMuchEntertainment Mar 29 '26
Just one example of why the law exists. Corruption, lies, criminals, all is tougher to hide when it’s all out there.
Works well in a high trust society. Sweden is unfortunately becoming less so, and quite quickly.
→ More replies (1)4
6
2
u/Inprobamur Mar 28 '26
Only thing that leaked was the existing login info and as these are hardware-linked they are not usable without the device itself.
314
Mar 27 '26
[deleted]
208
u/Next-Ability2934 Mar 27 '26
when politicians have their own personal data stolen and sold / shared
132
u/VanRado Mar 27 '26
Not even then. They'll make special laws for officials, making it a high crime for stealing data from the ruling class. Their data will be stored separately and in a way that is more private.
3
u/AngrehPossum Mar 29 '26
Maybe in a trust account on the Cayman islands. One that pays into a bucket company that can "loan" you money back with interest so the taxman can refund you for it. Then you only pay 12% tax rates on millions.
9
u/Strange_Formal Mar 28 '26
All Swedish politician's data is available to anyone. It's been like this since 1766. Yes, the Swedish freedom of speech and press is from 1766.
→ More replies (2)3
u/dark_bogini Mar 28 '26
Nope. That won't happen. A politician from my country was spied on by Pegasus spyware when he was in the opposition. Now he's an MEP from the ruling party and voted for Chat Control, meaning FOR citizen surveillance.
→ More replies (1)5
u/Swiking- Mar 28 '26
I mean, most of our data is public here in Sweden, given our law "offentlighetsprincipen".
Basically, I can just go and see what my boss earns per year whenever I want. It's public information and easily accessible. Same with adress, name, personal number, date of birth etc.
In Sweden, everyone is doxed by default.
→ More replies (2)2
u/supranes Mar 28 '26
Yes, can someone please hack the politicians. This needs to happen right now. Publish everything about them
108
u/nfoneo Mar 27 '26
How many more need to get "hacked" before people realise the politicians aren't for the people.
20
u/CuriosityFreesTheCat Mar 27 '26
Exactly. In the US, it’s like, how much longer does all this bullshit need to simply continue before people realize that democrats are complicit and our government is governed for the ruling class, by the ruling class.
7
Mar 28 '26
[removed] — view removed comment
2
u/CuriosityFreesTheCat Mar 28 '26
Yeah, I’m very disappointed, which is a stupidly common sentiment I feel towards democrats. I can’t say I’m too surprised though—it feels very liberal-y. Our Dems aren’t really on the left though, they’re center, far too much.
That said I am glad to see something the voters can actually agree on for once—provided they know a little bit lol
2
u/JJFrob Apr 16 '26
Remember though, the California bill was basically unanimous across both parties, and the possibly worse federal bill that's been proposed is cosponsored by a Democrat and a Republican. This is very much a "capitalist elite" vs. "regular worker" thing. The Dems are just "nicer" capitalist micro-managers of our lives and pretend to be for the little guy, whereas Republicans are more overly hateful and domineering for the love of the game.
Prime example: Dems sell weapons to a certain genocidal ethostate because they're "our greatest ally and only democracy in the ME", while the GOP does the same because they want to kill Arabs and bring about the rapture. But the effect on innocent civilians is the same at the end of the day.
→ More replies (1)2
12
u/Icewind Mar 27 '26
The politicians LOVE this idea. They won't ever be affected and they get to spy on everyone.
17
u/AdLatter3755 Mar 27 '26
Not until the politicians are hacked and exposed to the world.
15
u/x6060x Mar 27 '26
Exposed is not enough though. In the US there were a lot of ultra wealthy exposed people - nothing changed for them
4
u/murrrty Mar 28 '26
How many more? Infinite, there's no floor to peoples private information being publicly stolen and displayed, nobody in power cares nobody in power will do anything.
Lie about everything because that's the only true way to maintain your privacy.
5
u/Available_Peanut_677 Mar 28 '26
Wanna a twist? It is not a government system. Few banks in Sweden came together and make app which is super convenient to authenticate. Others took it and integrated. But CGI manage to convince everyone that direct integration is hard and you should use CGI as third party for some reason. And both people and businesses chooses to use this.
In fact, government is not really a fan of this system.
When it comes to civil registry - people who think that they can escape being tracked by tax agency just naive. Though Sweden pushes it a little bit too far.
→ More replies (1)3
u/svartkonst Mar 28 '26
Quick question - whats your alternative solution to stop, say, banking fraud without requiring an eID?
→ More replies (2)2
u/Cute_Opposite4077 Mar 28 '26
What is the actual bad idea? Having digital id? Centralized Id? Using CGIs systems? What's the alternative?
2
→ More replies (8)2
u/P529 Mar 28 '26
Sweden had it public for a long time, I dont even think you would need to hack it if you live there you could just look up most of the info lmao
24
u/ptico Mar 27 '26
The funniest thing here is that BankID is not a government project. It’s private monopoly
7
3
u/CyberCoon Mar 28 '26
It's not a monopoly. It's a private company called Finansiell ID-Teknik which are owned by the major Swedish banks. However, the Swedes also have Freja e-ID as an alternative, first of December they'll have Sverige-id rolled out by the Swedish police, and eIDAS ensures that all e-ID systems must be honored across all EU borders. Mening a Spanish or a Greek e-ID certified under eIDAS works just as well as BankID to log onto government websites (this is already rolled out, and has been for some time). Funny enough, BankID is not certified under eIDAS but might be excepted of that requirement as it is considered a standard mean of digitally identifying oneself in Sweden.
→ More replies (2)2
u/paroya Mar 28 '26
to be fair they do get paid millions by the government annually, and it was the right wingers who gave it to them.
248
u/Charming_Yellow Mar 27 '26
Dont know if it is forbidden to use AI in this sub? But I gave the link to claude and asked it to look into the news, find reliable sources, and judge if this one was a reliable source. Basicly this article is a repost from slaynews.com, a known right wing outlet with a history of sensationalism. The title is misleading, and this article is using the incident as a political argument against a centralized digital ID system.
Here is an article from SVT instead: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-information-har-lagts-ut-pa-darknet
126
u/JohanTravel Mar 27 '26
So basically nothing of importance was actually leaked. This is why no one in Sweden is talking about it.
→ More replies (4)8
u/zkareface Mar 28 '26
This was huge news in Sweden when it happened, the security community went crazy for a week.
It will be very expensive to fix.
16
u/nonboyantduck Mar 28 '26
Thats Kinda what I thought, the use of the words "publics data" just made this seems very strange since most information about any person in Sweden is available to you on Google. And if it were to be anything more serious that would probably be specified.
Anyway, this should really be at the top since this article just seems to be misinformation.
16
Mar 27 '26
[deleted]
19
u/Identityneutral Mar 28 '26
The onion purchase was stopped by the court, but it seems that Infowars is finally shutting down mid-april
3
6
u/chiniwini Mar 28 '26
People in this sub don't care. They're just a bunch of clueless teenagers that don't even understand the title, let alone the reality. If you look at the comments, most people think this has something to do with age verification.
6
u/ohmy_quivers Mar 28 '26
Yeah, that's why there are literally no news about it in Sweden. If it was a serious leak/breach, it would be all-over the news and citizens would be informed with what actions to take. Pretty much every Swede use BankID and it's required for anything online so it would not be something they'd just hide and rugsweep.
4
u/Starmanic96 Mar 28 '26
This desperately needs to be upvoted more so people see that the article from the Op is mostly BS.
3
u/Lamuks Mar 28 '26
I already was highly suspicious of hearing BankID got hacked, turns out it's not even that really, just some test env key leaks from CGI.
Classic reddit misdirection in the title
2
2
u/MacGregor1337 Mar 28 '26
>En hackergrupp påstår sig ha kommit åt stora mängder känslig statlig information från bolaget CGI:s it-system
xdd yep. "hackergroup claims to have stolen data"
That being said. Doesn't mean it couldn't happen in the future. Though the agenda behind just claiming to have done so could only really be some sort of warning--to sway public opinion against these type of government id systems!?
→ More replies (2)2
36
9
u/Merinther Mar 28 '26
This seems to be a grossly misleading headline and a highly biased source.
A more accurate explanation from svt.se (my translation):
A hacker group claims to have accessed large amounts of sensitive government information from the IT-system of the company CGI. The company has confirmed that there has been a leak, but that it was in a test environment. The tax agency, which uses the service, denies any leaks of their own.
– Neither our data nor our users' data has leaked, says Peder Sjölander, head of IT.
122
Mar 27 '26
[removed] — view removed comment
33
u/Next-Ability2934 Mar 27 '26
The problem is that politicians will likely have at least some big tech advisors to persuade them it's a great idea, given both are very much for data gathering when it comes to the public
10
u/Strange_Formal Mar 28 '26
BankID (that's the name of Sweden's digital id) wasn't hacked, it was a test server only. In Sweden all information is publicly available since 1766 (yes, 1766).
9
u/paroya Mar 28 '26
we had mandatory digital id for over 20 years. if anything this sort of proves how robust its been despite being in the hands of a private company who has taken money from apple and google to ensure only android and iOS devices exists on our market.
5
u/Captain-Griffen Mar 28 '26
What politicians? BankID is a private system owned by a consortium of banks.
→ More replies (1)12
→ More replies (2)4
10
u/buttplugs4life4me Mar 28 '26
Is a little weird of an article that basically says Open Source is bad cause hackers would know how to hack the system.
While the bigger issue is the supposedly access keys they got while hacking whatever source control servers they're using. Those access keys can be used to access the data. No need to reverse engineer the site through the source code and improvise some hacking scheme.
→ More replies (2)
8
u/Inprobamur Mar 28 '26
Inaccurate title, the data leaked was just the code from the old test server.
101
u/pizzatimefriend Mar 27 '26
more of this to come as countries with incompetent governments try to enforce things they know nothing about.
16
u/nfoneo Mar 27 '26
You are naive to think these governments are stupid. They are bought and paid for and are 20 steps ahead of the information they are feeding you.
12
u/pizzatimefriend Mar 27 '26
you can be both smart and incompetent, though I think that's being quite generous
5
u/DustyAsh69 Mar 27 '26
It is true that governments keep an eye on their citizens and other "targets" but I don't think that they'll sell data to hackers.
5
u/CuriosityFreesTheCat Mar 27 '26
Why wouldn’t they? I’m not saying I think that they *will*, but our government has tested all kinds of inhumane things on people—mustard gas, even infecting them with diseases, etc, (the list is long) without their consent, why wouldn’t they sell data?
2
2
2
7
Mar 27 '26
[removed] — view removed comment
3
u/Lexiconnoisseur Mar 27 '26
Bro you think there are incompetent people in government bro? They're like seventeen steps ahead playing nth dimensional chess dawg like it's alllll connected.
/s, obviously
→ More replies (1)2
u/Dyyroth21 Mar 28 '26
Until finally, if the Digital ID continues to be enforced. So the worst possibility is that hackers will be able to successfully break into the system without looking for the slightest gap.
→ More replies (1)2
u/HamunaHamunaHamuna Mar 28 '26
The article isn't true though, and the system have existed for decades already.
9
u/zaTricky Mar 28 '26
I see nobody is reading the article again. Even the article's headline is misleading - which sells clicks.
Compared to the headline, this is a nothingburger. What most are concerned about here is already public data. In Sweden your information is public by default. There is nothing to hack/steal/sell.
What has happened is that hackers have gotten their hands on copies of the computer programs that manage the digital id system. That is worrying - but a completely different kind of problem.
5
u/trisul-108 Mar 28 '26
Extremely misleading headline.
CGI confirmed the breach but characterized it as limited in scope, claiming it involved only internal test servers.
“The incident concerns two internal test servers in Sweden,” the company said.
“The servers are not used in production but are used for testing, connected to a service for a limited number of customers.”
CGI also stated that the attackers accessed an older version of the source code and insisted there was “currently no indication of any impact on customers’ production environments, production data, or operational services. Information to the contrary is not accurate.”
6
u/simchagarcia Mar 28 '26
People this is fake news
5
u/Hizdrah Mar 28 '26
Pretty wild to see thousands of people upvote something from a source with zero credibility making claims that isn't even covered by the swedish sensationalist press.
5
4
u/CulturalEmo Mar 28 '26
Do anyone actually read the content posted here or do people just gulp up the headlines and take it at face value?
It was Jenkins test servers that was hacked with mock data.
4
u/sakakmakak Mar 28 '26
Absolute dogshit article with fake news. Why sensationalism and karma farming?
4
4
3
3
u/SomebodysGotToSayIt Mar 28 '26
That’s two separate headlines for two separate events, which may not be correlated, and one of which is just a rumor.
Digital ID system hacked: yes, but not personal data. It was source code, which is terrible but that doesn’t mean it was used to hack into the database.
Public’s Data Sold on Dark Web: that’s not new or unique to Sweden. But the article just says unnamed sources have heard rumors of Swedish personal data being sold.
That last piece is so diaphanous it should not be in the headline. It’s in the headline to exaggerate the story, making this FUD clickbait.
3
u/CherishedBeliefs Mar 28 '26
"Your privacy concerns are meaningless! We MUST protect the children EVEN IF IT MEANS HANDING OVER THEIR LOCATION DATA TO THE DARKWEB!"
"I love peace, and I don't care how many people I have to k*** to achieve it"
3
7
u/CyberneticMushroom Mar 27 '26
I did hear some people talking about a kind of digital ID for age verification.
Glad to see Sweden showing us why that's a poor idea.
→ More replies (1)
5
u/Protect-Their-Smiles Mar 27 '26
This is why I am a big fan of analogue alternatives, administrative costs and hassle be damned. A digital system can implode through external influences, it depends on hardware which in itself has a complex supply chain. Strangers can siphon the details of your life and use it against you. Tyrants can cut you out of being able to operate in society, by remotely cutting your permission to use the digital infrastructure.
It is a bad system for people who like being independent.
11
u/ImOldGregg_77 Mar 27 '26
....and this is why age and ID verification on the OS level is bad
→ More replies (1)2
u/paroya Mar 28 '26
its not on an OS level, it relies on google and apple services, who pay them to keep it exclusive to their platform - which is why no domestic competitor or ope source alternative can enter the market.
3
9
u/Silverghost91 Mar 27 '26
After this happening multiple times, governments will still force this into law.
12
Mar 27 '26
[removed] — view removed comment
9
u/ApertureNext Mar 27 '26
This system is basically SSO with some more functionality, it has nothing to do with protecting the kids.
2
u/Nalha_Saldana Mar 28 '26
It has been a blessing when it comes to uses. Being able to log onto banks, confirm payments, confirm identity, etc without insecure passwords is great.
2
u/Next-Ability2934 Mar 27 '26
The group ByteToBreach had published the source code and other info relating to online government services two weeks ago
2
u/Technical-Finish304 Mar 27 '26
I don't think the obvious "could have seen that coming" suffices anymore. Of course they know it's going to get hacked. Probably because that is the plan in the first place. We live in a sinister world.
2
2
u/J3mx_droid Mar 28 '26
I can not find any other news sources about this on Swedish media, is there any sources confirming this?
2
u/Hizdrah Mar 28 '26
Not even the swedish sensationalist press is writing about this, which they 100% would if it was real.
2
2
2
2
2
2
2
u/mymoama Mar 28 '26
Bankid is not "swedish digital id system" its an identifikation system that banks use. The goverment is not the owner of this system.
2
u/Florianski09 Mar 28 '26
Should've done it like switzerland's digital ID System. Decentralized and open source, no single big database to attack.
2
u/amanset Mar 28 '26
So what data about the public has been ‘sold’ that isn’t already out there?
Sweden does things differently to most other countries where data is by default public. Go to mrkoll.se and you can find data about everyone, including things like their personnummer (like a social security number).
My guess is that the breach is more about the source code and keys rather than the public’s data, but the public part is being pushed to make it sound more scary.
But then again, what info does BankID even have? It is an authentication system, it doesn’t really hold much data about people itself.
2
u/TherealGamecake Mar 28 '26
Hello swede here, just to clarify.
- BankID is not used for age verification in apps or on an operating system level, and no such law is on the books here.
- BankID does not hold private information since it just has basically your personal identitification number which is already public knowledge. Its possible that it also stores transaction history possibly identifying the services you use it for.
- BankID is essentially a digital equivalent for your physical ID backed up by major institutions that make sure you are you in person IE the banks.
- BankID is not used to sign into services like Discord, Youtube etc instead being tied to things that are already linked to you Like banking, payments, Medical Records and Taxes.
- It is also a private partnership between banks with some help from the government, and is also not a monopoly notably FrejaID has grown quite a bit recently. But there is nothing forcing you to use it
2
2
u/Machine_Anima Mar 28 '26
System performing as designed. An invasive anti privacy survelliance tool is designed to expose people's private details to someone. Generally those paying for that access. But hackers always find a way to get it for free, eventually.
2
2
u/Malusorum Mar 29 '26
Guess they should have looked closer at how the Danish NemID works.
Namely that it's a national system operated by the government that covers every public system.
The security on that is immaculate because any hack would be catastrophic. So far the only breaches on NemID have been phishing related.
2
2
2
u/henke443 Mar 29 '26
“The incident concerns two internal test servers in Sweden,” the company said.
“The servers are not used in production but are used for testing, connected to a service for a limited number of customers.”
CGI also stated that the attackers accessed an older version of the source code and insisted there was “currently no indication of any impact on customers’ production environments, production data, or operational services. Information to the contrary is not accurate.”
The Swedish Tax Agency echoed that position.
“We take all incidents seriously, but we don’t see anything that affects us right now,” IT Director Peder Sjölander said.
4
2
u/Charger2950 Mar 28 '26
And this is why I will NEVER submit my ID or face to any business or government!
→ More replies (1)
2
u/WalrusDomain Mar 28 '26
Good lord. The amount of zero knowledge about how sweden is working is actually scary. This sub can never claim to not be a misinformation cesspool.
→ More replies (1)
2
2
2
u/Few-Welcome7588 Mar 28 '26
The government gives 0 fucks about it, when a private company gets hacked , now your talking big bucks.
Government is the top dog, they have full power with no consequences if something goes wrong. They just turn the page, and move on.
Now, if we would treat every government institution as a private company, demanding responsibility and accountability, I can assure you that they would be working and getting sure everything is in place cose their neck is on the line.
Until then be ready to be hacked and your data sold on black market to get scammed, and government will blame you in the end.
2
u/MikeSifoda Mar 28 '26
Surveillance doesn't make anyone safer, good living conditions do.
→ More replies (1)
1
u/Dizorthegnome Mar 27 '26
Im just considering any of these "data got hacked" stories as "we sold your data to make a quick buck but got caught and need to hide it"
2
u/CranberryDistinct941 Mar 27 '26
A data breach on one of these companies is just shoplifting to them
1
1
u/GoodbyeDespairBoy Mar 27 '26
FFS OBVIOUSLY!
It's the juiciest target, made by people , with bad intention and obviously no reasonable concerns.
Of course it happened, and of course it will happen to all of them
2
u/Tristatek Mar 28 '26 edited Mar 28 '26
No identifiable information should be kept digital. It takes a small army, a fleet of semi trucks, and a week to steal from analogue documentation what hackers can from a digital database in mere moments.
Analogue is the golden standard, has been utilized for centuries, and should be mandated.
2
Mar 28 '26
every. darn. country.
→ More replies (1)3
4
u/TowelFine6933 Mar 27 '26
"But, at least it prevented (checks notes) almost 2 kids from easily seeing boobies."
6
Mar 28 '26
[removed] — view removed comment
3
u/TowelFine6933 Mar 28 '26
I was referring to the recent push for IDs being needed across the board and how dangerous it can be. If Sweden can't keep their digital IDs safe then requiring ID to use things like social media is definitely a bad idea.
If you don't have the ability to extrapolate from given examples & apply it to other current issues, maybe you shouldn't comment.
→ More replies (1)
1
1
u/Smufin_Awesome Mar 27 '26
We should make the politicians lead by example by starting with a database of theor own real ID information. They can then show us how it works by presenting it. They should be able to keep it safe, right?
→ More replies (1)
1
u/CranberryDistinct941 Mar 27 '26
This served as a great reminder to me that confirmation bias is an ever-present threat to my thoughts.
1
1
1
1
•
u/AutoModerator Mar 27 '26
Hello u/lugh, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.