It's tussle between two counter-acting forces at play. This get's worse when the overarching authority that supervises both departments, has no clue about how to hit a balanced prioritization. For example, security teams rule the financial companies, like mafia bosses. No one, including CEO, can dare to question why so many layer of security is needed.
You're missing the systemic problem the parent is talking about.
And if even if they did, which of these two is easier?
1. Typing your 16 char password with the current moon phase once an hour, and remembering the new one every time a comet passes
2. Pressing your password manager keyboard shortcut (or tapping your yubikey) once an hour, the exact same action that never changes for the rest of your life
True.
> And if even if they did, which of these two is easier?
You didn't understand their point. The password manager itself locks and tapping doesn't work until you put in the master password again.
> According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
It really doesn't have to be, and setting things up as adversarial is counter-productive. Pretending that you're "balancing" two competing alternatives when they may not even be opposed is a problem, it gets you C++ std::span, a type which was standardized to be pointlessly dangerous because hey, surely if it's less safe that will make it faster right? [Morgan Freeman's Voice: But it was not faster]
For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
If you can just create a world for that simple case, then I will rest my case.
Another easy thing (unless they did it already and I didn't notice) would be Microsoft Entra could default enable Security Keys for authentication. Less friction than remembering passwords or one of those apps on your Phone, but better security.
So you are still making a trade-off
No, that is not arguable for anyone who takes more than a few seconds to think about it. Signing in has nothing to do with authentication, it's about things like "I want to have my own preferences set for showdead/noprocrast/etc. I want to maintain my own lists of favorites." Authentication & security are about making sure others don't access/alter your account or use your property or the like without permission, not about there being infinite resources and everyone being perfectly identical.
>So you are still making a trade-off
Nope.
My local all-eggs basket vendor agrees 100%.
You're not convincing a normal person to memorize 20 high quality passwords, and multiple physical devices are going to be put on the same keyring.
So in short, yes.
Well, it's this one? Or at least for a wide array of practices. To take a trivial example, can you explain how switching encryption from DES to AES (a clear improvement to security) is counteractive to productivity? Of course not, whether it's AES or ChaCha20-Poly1305 or ROT13 the choice of underlying cipher is transparent to the higher level user/application. Or how about reducing memory overflow bugs? That improves security, while also reducing a certain class of crashes. How is reducing software crashes counteractive to productivity?
Even if we take your silly example you clearly intend as a gotcha:
>For a start, most people would certainly be more productive if they hadn't had to authenticate themselves.
People have to identify themselves though in a multi-user environment anyway. Even completely putting aside any sort of security, we all of course have our own preferences for work environment, our own collections of data, etc etc etc. Duh. When we access a system (be it via GUI or CLI or web site) we need to say "I want to use xyz account" anyway. So the marginal cost to auth well can be zero. Using a password manager means "entering user name" and "entering user name and password at the same time" both have the exact same cost: 1 click of a button. Or if using a smartcard/USB PIV token or the like instead, it again can be the same effort: insert it, tap something.
Certainly it's true that sometimes there are unavoidable tradeoffs. But there's a lot of low hanging fruit where things can be made more convenient/productive and more secure at the same time.
The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.
No, I'm honestly engaging with the topic and your post, vs tossing around insults.
>The premise was not to enhance security, but to design a world where security and productivity are not tradeoffs.
And I gave you examples, including engaging with your own example/question. You claimed that "most people would certainly be more productive if they hadn't had to authenticate themselves". But IDing and authenticating are different operations, people would need to ID regardless even in a world where no security was necessary. So if the marginal cost of auth over ID is zero, then by definition that means there is no tradeoff between security and productivity. Something like a security key/card is an example of accomplishing that. Plugging that in and typing 6 numbers or touching it is not merely no extra effort vs typing my user name alone, it's literally faster.
And again to other examples, anything transparent to the user is, again, by definition not an impact on productivity. For another not merely "common" but "near universal" example, see full disk encryption (which is now often the default even with no authentication at all). FDE definitely addresses a few classes of threat scenario. What do you argue is the tradeoff in productivity?
... right up to the moment when they aren't.
I like to think of a law of conservation of productivity.
Before: yours 100%, hacker's 0%.
After: yours 0%, hacker's 100%.
Nonsense, of course. Hacker's boost is nearer 100,000%.
Fact is, modern computer power is inherently far more productive for bad than good. And the economic incentive follows.
Not is it probable that people will take over our system. But is it possible.
I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.
And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.
Passwords are just a worse, hacky version of passkeys.
*They are private/public keys, so they can’t be MITM.
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
If you start thinking more about this, more and more problems pop up.
The CPR alone is used for casual identification.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
Which does remind me of my game theory class in college... the professor would show movie scenes that demonstrated the game model we would be studying that week. It was quite effective, and certainly helped keep me engaged.
Fingers crossed this late sequel parody somehow duplicates the original's charm. It would be embarrassing for Disney if it's better written/received than their own attempt with the source material.
Having a unique number that is needed for identifying individuals, but also often used for authentication and thus meant to be kept secret, is bound to go wrong. There are too many situations where these use cases are in conflict, and considering Denmark has MitID - a actual national authentication solution - the CPR number should have been considered public information a long time ago, and shouldn’t ever be usable for obtaining credit or the like on its own. A system keeps insisting this is sensitive information is really the main responsible here.
That's also not how they are used. They're maybe the username, but never the password, and absolutely not supposed to be secret. They are supposed to be extremely public.
I doubt the CPR number alone will give you access to obtain credit and the like today, but you can absolutely go into a pharmacy and buy someone’s prescription medicine with just their CPR number, and you for sure can get access to a lot of data by calling various entities and providing your CPR number as proof of identity (but at least fewer now than used to be the case in the past).
If the CPR number was truly made public information, those cases would be much more obviously wrong. The fact that CPR numbers are de facto considered pseudo-secret makes things much worse.
In Norway I have to show photographic ID and my fødselsnummer.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.
So the password could have been 32 alphanumerics with special characters and there still would have been a breach.
The password was not the problem here.
The problem with the compromised platform is that it had no MFA. If they had just had something like OAuth via google workspace or something, this most likely could have been avoided. But it seems like they just had completely vanilla email/password auth with zero additional security measures.
If we technically restrict the minimum length to, let's say, 12 chars, the default passwords will be smth like `123456789012`. If we add the requirement to have 1 letter, at least, the passwords will be `12345678901a`. If we require a special character, we'll get smth like `1234567890a!`.
I believe the issue is not technical, and it's not about the one particular guy. It is about accountability and understanding the impact and responsibility of the "I don't care"/"whatever"/"ship fast" mindsets.
We need a proper social agreement for that, as this goes far beyond the passwords, especially these days when the quantity and speed are valued over quality.
Because from the sound of that, it feels that it would patch the `123456` problem, but opens up a new vulnerability - the password is known / being sent through / printed, so it can be leaked from that source.
On the other hand, how would we make "lazy" people use those? And ensure that won't reuse the same password on some vibe coded forum that will store them in the plain text and get hacked in a few weeks =)
That's why I mentioned that mindset shift as the prerequisite.
When I get an internal mail with multitude of acronyms I know that the people that wrote it does not care if anyone is going to read/understand it or not. It goes directly into the trash.
The information about the leaked password is from the guy claiming to be the hacker who anonymously talked to the media.
Oops, can I delete my comment, it was a copy paste mistake!
> Oops, can I delete my comment, it was a copy paste mistake!
What do you mean? You can safely post your passwords on the internet.
Equivalent to social security information in the US I guess.
Here in Argentina, the DNI is assumed to be public, it appears in a lot of public documents next to your name, and on election day there is a list of all the local voters with name and DNI at the door of the pooling site. To pay a sweater in two installments you may need to present the phisical DNI card and a water or electricity bill and they photocopy all of them.
There's only 500 numbers it could be, assuming someone knows those other things about you.
In any case, there are alternative systems for authorisation.
It's the same in Sweden: YYYY-MM-DD-XXXX is the format for a personnummer, double the population of Denmark and there are no collisions.
edit: I was wrong. Wikipedia says, “The first digit of the sequence number encodes the century of birth (so that centenarians are distinguished from infants)”.
It also says “the last digit of the sequence number is odd for males and even for females”. What a strange system. Essentially the last three digits are two different sequences made to look like one.
Targeted and real looking spam mails come to mind. Hey <NAME> with <Address> and <CPR>, you have to log in <fake government website> to verify X Y Z.
Apparently some pay day loans or similar with just CPR + name is or was a thing. But lets hope that will change now. Bonkers as CPR should be be treaded as a secret.
Like the recent ransomware attack on a Swedish Svedala municipality, still no root cause published on that?
When things like this happen in Asian countries, you always see a lot of people here comment about how “the culture” contributed to it.
So I’m wondering if there are any experts here who can explain if this is cultural too?
Changing a whole societal mentality in the institutional level happens slower than the populace discovering the "naturally" occuring dysfuntionality of everyday life, because the System has never felt the need to ask: Does it work as intended? OR Why would anyone disrupt a functioning system?!
We are having to learn. I have no ideal how. In this instance, the CPR hack, it would be completely IDIOTIC to replace the system with a new propritory system, since the problem is trust in the system rather than informed understanding of the threats to any system.
The second was giving out access to "companies and associations" that might have "legitimate needs".
THEN we get to morons using passwords like that.
Since then I think medical data science is mainly a waste of tax payer's money.
I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
You might think Im being weird, but after living many years in corporate the amount of times you see some major thing go wrong and some random guy get fired for it - often the dude who found/highlighted the problem, is crazy. I mean you simply don't believe it until you witness it. Its just moral/leadership decay.
I wouldn't have made this comment but I see comments with people empathising with certain individuals in cases like this, when the way to be nice is to overhaul the system of checks and people responsible and spread the blame, fixing the domain.
I asked them to do a thing, but didn't intend the obvious consequences* so it's not my fault they occurred.
And now we have the same thing but the bosses 'hire' AI.
Now I realise this is part of how unusual my thinking is.
I'm happy to use phrases like "ChatGPT hacked out of the sandbox, then hacked into HuggingFace"; people often respond to this like I'm suggesting OpenAI isn't at fault, and like, that's not my position at all, so far as I'm concerned the buck still stops with the person who set the task regardless, the thing that changes from incidents like this is now nobody in the future gets to even have the excuse "oh but we didn't know it could even do that" or "we didn't know it might interpret our orders in that kind of way".
The response, both when a human messes up and now when an AI messes up, needs to be defence in depth: someone giving orders needs to be giving clear orders, entities (human or machine) who follow instructions need to have not just an understanding of how to follow them, but also what's so out of scope as to be forbidden - the difference between 'follow orders' and 'follow lawful orders'.
That’d be engineering.
Real world, as you say, not so simple. Everything has to deal with certain degree of forecastable nonsense, e.g. a bridge has to cope not only with traffic and winds, but the possibility that someone will be drunk in charge of a ship and crash into it.
> AI is built on human knowledge so guess what it will keep doing.
Yes, and also brings its own additional mess on top of that. All machine learning takes a huge number of examples to get good, so an LLM isn't just "read all the online courses in how to run a business", but also likely has 50 business versions of the recent demonstration of common sense failure with "I live 100m from a car wash, should I walk or drive?"
> How do we build systems without assuming complete adherence, but tolerating imperfection and failures? Isn't there some discipline teaching us that?
Many such disciplines. Perhaps all except maths and computer science? Or even including maths and computer science, given stats is part of maths and even compsci has to deal with fault tolerance.
> I dont understand why there is not massive reorganisations in systems when things go wrong. Its always , oh yeah so we fired the guy furthest down the ladder.
Of all the things that failed for that leak, we should focus the LEAST on the password being insecure, and the company whom had their account misused, and the most at the other end of the long line of failures.
Why was there no monitoring on a company suddenly looking up 600 people a minute, why was this only discovered when they were making the invoice?? And how was it even possible to have a password that unsafe, no two factor auth etc etc etc.
As for 2FA, it is a nice thing to have, but it comes at a significant support cost. People lose their token, people get annoyed by the friction, people can't figure out setup (especially older folks).
Government services have to work in all these scenarios, simply because that is a right of the citizens.
Our system now heavily reenforces lack of accountability to executives for what happens under their watch.
Investors don't lose money when these breaches happen.
This is why it won't change until those change.
Otherwise shareholders do not care, because they do not have skin in the game.
Same for government staff. Unless they are explicitly fired there are no consequences of abusing the trust of public.
... said every "security" pedlar ever.
Because massive reorganisations can easily lead to even more things going wrong. Also most people are lazy and phlegmatic by default.
This would just replace one insecure system with another.
It is time to recognise there's no such thing as a secure connected computer. And thanks to "AI" there's no such thing even as a significant defence lead over attackers.
I think there's also a big part of the line that Jennifer Lawrence says in the satiric comedy "Don't look up":
"They are not even smart enough to be as evil as you're giving them credit for."
Just as the person who picks 123456 as a password doesn't see where the problem is, I think there are really quite a lot of people dumb enough all along the decision chain to think that firing the person who reported the problem did actually fix the problem.
They are really that dumb.