Source code of Swedish e-government services has been leaked (darkwebinformer.com)

by tavro 246 comments 233 points
Read article View on HN

246 comments

[−] wasmitnetzen 64d ago
Swedish news has some quotes from authorities that nothing of value has been leaked, and a quote from the service CGI that it only concerns test servers.[1][2]

[1]: https://www.svt.se/nyheter/inrikes/uppgift-statlig-it-inform...

[2]: https://www.cgi.com/se/sv/news/cybersakerhet/cgi-informerar-...

[−] JensRantil 64d ago
I am a Swedish citizen. Lived here for almost 40 years. It is a bit unclear to be what the "the Swedish e-government platform" is. Would have been great if they at least could have published which domain name the service has.
[−] teroshan 64d ago
Does anyone know if there is the source code for the Swedish Armed Forces - Team Test [1] in the leak? It was a really fun collaborative flash-style game that got popular in my circle of friends for some reason back then.

[1] https://flashism.wordpress.com/2010/03/09/swedish-armed-forc...

[−] rebolek 64d ago
Maybe they should go open source from the start, then there's nothing to leak.

P.S.: And strangers will sometimes help you find vulnerabilities (and sometimes be very obnoxious but that's not open source's fault).

[−] corroclaro 64d ago
This keeps happening in Europe with these mega-IT suppliers repeatedly getting exposed using very bad development practices. Sweden most recently had a major breach back in 2024 when the other large IT services supplier TietoEvry had their data centres breached and claimed "not actually an issue of security".

Several government organisations / regional authorities and companies were down. Last I heard several medical journals for whole municipalities were just destroyed.

Unfortunately, the public tender process encourages awarding contracts to these giants that repeatedly fail to deliver on even basic opsec and still believe in security-by-obscurity, are suspicious of things like zero-trust, follow outdated engineering practices. Sigh.

[−] yaris 64d ago
Knowing swedish people's mindset I'm not surprised at all by the breach. What can be mildly surprising is that no major e-gov service has expressed concerns on their websites. Only on skatteverket.se, which is Swedish Tax Service website, there is a vague note on "maintenance work" planned for coming Saturday. Maybe totally unrelated though.
[−] vladde 64d ago
CGI has a lot of consultants in both government and municipal places (i've worked at both), and some of our main tools like time reporting was built as a addon to our personnel system by consultants at CGI. half my team are consultants from CGI, 4 out of 7 people.

also: hi tavro! it's been a few years, how have you been :D

[−] Lliora 64d ago
Worked on a similar platform. The real risk isn't the code - it's the config files. Government deployments have hardcoded staging credentials, VPN endpoints, and encryption keys that don't get rotated when code leaks. Source is whatever. Those env files are the skeleton key.
[−] PeterStuer 64d ago
Misleading title, as my first thought was "why is Sweden's egov not open source to begin with?".

Turns out it's about data.

[−] dspearson 63d ago
It's odd to me, as a Brit, to see that this stuff was not mostly public anyway. (looking at you https://github.com/alphagov)
[−] GuB-42 64d ago
First reaction: How come the source code is not public in the first place, accessible to every Swedish citizen? They paid for it!

But it turns out that more than the source code was leaked.

[−] WhereIsTheTruth 64d ago
As long as cronyism remains the primary qualification for leadership, nothing will ever change, worse, it's only going to get worse

Accountability now, send these people to prison

[−] FpUser 64d ago
Unless they hardcode passwords and other juicy details in their source code what's all the fuzz about? It is a publicly funded thingy anyways.
[−] blin2h 64d ago
What forum is the original screenshot from? It reminds me of cs.rin.ru
[−] butz 64d ago
Most important question: do Swedish e-government services use curl?
[−] olalonde 64d ago
Anyone knows what their tech stack looks like?