Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

1–10 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#3

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Requirement by who? Discord isn't required to demand your ID, let alone store it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#4

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

in case of the EU it's more the opposite

GDPR requires data minimalism and ~use case binding so if you submit data for age verification there is no technical reason to keep it after knowing your age so you _have to_ delete it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#5

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Just a guess, but they may store the original ID card to audit duplicate accounts.

If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

Re: Discord says 70k users may have had their government IDs leaked in breach

#6
This is not OK, and the reporting is not OK.

Opening with:

> Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge.

Then a big PR quote, letting a potential wrongdoer further spin it.

Then closing with:

> In its announcement last week, Discord said that information like names, usernames, emails, the last four digits of credit cards, and IP addresses also may have been impacted by the breach.

This is awful corporate PR language, not journalism, on a big story about probable corporate negligence resulting in harm to tens of thousands people.

Here's the bare minimum kind of lede I expect on this reporting:

Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses.

I'm ready to block both Discord and The Verge.

Re: Discord says 70k users may have had their government IDs leaked in breach

#7

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

That is the bonkers thing about this story. Why take on the liability? Get what you need and toss the responsibility. If you must store it (which seems unlikely) put that extra-bad-if-leaked information behind a separate append only service for which read is heavily restricted.

Re: Discord says 70k users may have had their government IDs leaked in breach

#9
I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'.

Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system.

To make it clear - I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures. I just completely dropped the expectation of my information being private, and for the very few bits that I do actually want to stay private, I just don't, or allow anyone to, digitalize or reproduce them at all in any way.

Re: Discord says 70k users may have had their government IDs leaked in breach

#10
post #5

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Just a guess, but they may store the original ID card to audit duplicate accounts. If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

The best years online were when it was universally recognized that government ID's are completely unsuitable for interaction with the internet in any way.

Like it was since the beginning when government ID's first became a thing.

Post reply on HN