TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Five million Danish ID numbers sent to Chinese firm by mistake

184 点作者 mbanzon将近 9 年前

14 条评论

runesoerensen将近 9 年前
This is ridiculous. It&#x27;s not just Danish personal identification numbers, but <i>ID numbers and health records</i> for everyone who have lived in Denmark from 2010 through 2012.<p>Quick recap since it&#x27;s in Danish: A danish health authority, SSI, accidentally <i>mailed two CDs</i> containing <i>unencrypted CPR-numbers and health records for 5.28m residents</i> to the Chinese Visa Application Office.<p>The Chinese delivered the letter to the intended recipient, Statistics Denmark, another danish government authority.<p>The bubble cushioned mailer containing the CDs had been opened, but regardless the issue of course is the extremely reckless handling of very sensitive information.<p>Edit: Article reporting on this in English <a href="http:&#x2F;&#x2F;www.thelocal.dk&#x2F;20160720&#x2F;five-million-danish-id-numbers-sent-to-chinese-firm-by-mistake" rel="nofollow">http:&#x2F;&#x2F;www.thelocal.dk&#x2F;20160720&#x2F;five-million-danish-id-numbe...</a><p>Edit 2: The specification and structure of the data that was sent with these CDs. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;christianpanton&#x2F;status&#x2F;755742230044966912" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;christianpanton&#x2F;status&#x2F;75574223004496691...</a> (also in Danish, but this seems to include almost everything; the carelessness in handling this data appears to have been surpassed only by the extent and completeness of it)
评论 #12128582 未加载
评论 #12129544 未加载
评论 #12128715 未加载
评论 #12128703 未加载
评论 #12128899 未加载
评论 #12129406 未加载
评论 #12128560 未加载
mads将近 9 年前
As a Danish person living in China, I don&#x27;t know how to feel about this.<p>In some weird way, I think it was a good thing this got delivered to the China visa office and not next door to them, in which case we would probably never have heard about this mistake and for sure it wouldn&#x27;t be top post here. There is a good headline to be found in this story, as I have just discovered when browsing the Danish news.<p>If this information is handled so recklessly and so nonchalant, it makes me wonder what other people within Denmark also have access to this information. Students, secretaries, interns? Can I register as a scientist and get access? Who exactly has access to my information? I would like to know the answer to this question.<p>I know that visa office and have been there many times. It is not a Chinese government run operation but a private company handling the incoming paper work for visa applications, which get submitted for review at the Chinese run Chinese embassy :P
ksk将近 9 年前
I wonder if this would have been a story if a country other than China was involved. Of course, the information was carelessly handled but then again worse things have happened.. like sending a missile to the wrong address. The bias in the article is interesting, with the author of the article putting the words &#x27;by mistake&#x27; in quotes to signal that the mere act of opening the package is suspicious. Over the years I have blindly opened plenty of mailed packages only to realize that it was actually addressed to someone else.
评论 #12129866 未加载
pbhjpbhj将近 9 年前
The story from the Chinese Visa Application Office (CVAO) is that an employee opened the letter &quot;by mistake&quot;:<p>&gt;&quot;It said that it was contacted by an employee of the Chinese Visa Application Centre who said she opened the letter addressed to Statistics Denmark “by mistake” but then delivered the package to the statistics agency.&quot; (TheLocal, linked above, <a href="http:&#x2F;&#x2F;www.thelocal.dk&#x2F;20160720&#x2F;five-million-danish-id-numbers-sent-to-chinese-firm-by-mistake" rel="nofollow">http:&#x2F;&#x2F;www.thelocal.dk&#x2F;20160720&#x2F;five-million-danish-id-numbe...</a>). &#x2F;&#x2F;<p>Having worked as a civil servant I find this unlikely if it were properly addressed. In the office I worked at all mail came in via a mail room who checked and registered it and directed it to relevant personnel.<p>Presumably the CVAO receive a lot of mail, they must have a dedicated system for recording [because we&#x27;re talking about legal documents and receipt dates therefore are important to record] and directing that mail. So a piece of mail comes in for &quot;Statistics Denmark&quot;, now what happens?<p>What I&#x27;d expect is it&#x27;s sent to a mail-room manager to handle. They can then either redirect the mail unopened or forward it to some other personnel. I really can&#x27;t see them just opening things &quot;by accident&quot; at all. They have a choice to honestly redirect unopened or to actually open it. Now, the opening may have been an individual&#x27;s simple curiosity, for sure.<p>Interested in any other analysis particularly with reference to how mail receipt is handled in other country&#x27;s civil service locations. I expect things have moved on somewhat, something like &#x27;tag with barcode, photograph and the computer records the article&#x27; is probably the current workflow?
评论 #12129880 未加载
sidek将近 9 年前
Worse, at least according to Google Maps, it is only a 17 minute drive or 28 minute bus ride between Statistics Denmark and the Serum Institute.<p>At such a small distance, if such large amounts of confidential information must be delivered, I feel that it ought to be hand-delivered.
plesner将近 9 年前
These things keep happening in Denmark but the thing is, very few people actually care here. Avoiding mistakes of this caliber isn&#x27;t rocket science but it does take a little effort and awareness and as long as nobody cares there is no motivation to make that effort.<p>In that sense this is just giving people what they&#x27;re asking for. They&#x27;re not asking for security so they&#x27;re not getting it.
Symbiote将近 9 年前
Google Translate gives me, &quot;Data Protection Agency takes no further action&quot;.<p>Is that true? No-one is fined or prosecuted for this? Or even sacked?
评论 #12128710 未加载
评论 #12129228 未加载
评论 #12128714 未加载
danielweber将近 9 年前
To save other people the google search, population of Denmark is 5.6 million.
评论 #12129644 未加载
rascul将近 9 年前
Here is the Google translated version <a href="https:&#x2F;&#x2F;translate.google.com&#x2F;translate?sl=auto&amp;tl=en&amp;js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=https%3A%2F%2Fwww.datatilsynet.dk%2Fafgoerelser%2Fafgoerelsen%2Fartikel%2Fanbefalet-brev-afleveret-til-en-forkert-modtager%2F&amp;edit-text=&amp;act=url" rel="nofollow">https:&#x2F;&#x2F;translate.google.com&#x2F;translate?sl=auto&amp;tl=en&amp;js=y&amp;pr...</a>
1337biz将近 9 年前
Just came here to ask what do you guys&#x27; think about centralized health care records?<p>It seems impossible to prevent these kinds of &quot;stupid&quot; mistakes from happening.<p>My doctor still works mostly on a paper based system, so in the worst kind of situation just his patients data are lost.<p>Are there any alternatives that prevent those kinds of leaks - esp. considering that even the NSA got out-Snowdened.
Zekio将近 9 年前
The Danish personal identification numbers are useless for identifying someone since we pretty much give them out to anyone who asks for it, and they can be calculated using some methods, which have been done to some politicians just to show the flaws in the system behind them.
评论 #12129999 未加载
neximo64将近 9 年前
Absolute incompetence.
Angostura将近 9 年前
So, to summarise - burning it to CD is actually fine, but they should have used an in-house courier.
评论 #12130750 未加载
评论 #12129341 未加载
评论 #12129092 未加载
评论 #12129782 未加载
评论 #12129045 未加载
ben_jones将近 9 年前
Disclaimer: I 100% believe in the idiom &quot;don&#x27;t attribute to malice what could equally be caused by ignorance&quot;.<p>But I think all those involved should have permanent monitoring on their bank accounts and living status incase a suspiciously large wire were to come from a Chinese entity. This is happening way to often not to become a source of plausible deniability to future criminals. &quot;It was an accident officer I swear!&quot;. Sympathies to all those effected by this incident.