Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

31–40 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#31

I didn't feel comfortable giving discord my phone number when they demanded it, so I lost access to the open source communities that insist on collaborating there. I wish breaches like this would cause people to reconsider their choices but sadly, it's unlikely most users will move.

The issue is if you don't enforce the phone number requirement on your server you get all the trolls who don't use phone numbered accounts. I wish Discord would allow you to restrict known VPNs instead of requiring phone numbers. It would solve so many issues. I know a LOT of VPNs wont be caught, but if you block MOST non-residential IP blocks, you'll capture a lot of them.

[dead]

Re: Discord says 70k users may have had their government IDs leaked in breach

#32
post #5

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Just a guess, but they may store the original ID card to audit duplicate accounts. If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

IMHO this is a pretty dump approach to the problem

while there probably are some countries with terrible designed passport for most they are designed to be machine readable even with very old style (like >10year old tech) OCR systems

so even if you want to do something like that you can extract all relevant information and just store that, maybe als extract the image

this seems initially pointless, but isn't, if you store a copy of a photo of a people can use that to impersonate someone, if you only steel the information on it it's harder

outside of impersonation issues another problem is that it's not uncommon that technically ids/passports count as property of the state and you might not be allowed to store full photo copies of it and the person they are for can't give you permission for it either (as they don't own the passport technically speaking). Most times that doesn't matter but if a country wants to screw with you holding images of ids/passports is a terrible idea.

but then you also should ask yourself what degree of "duplicate" protection you actually need wich isn't a perfect one. If someone can circumvent it by spending multiple thousands to endup with a new full name + fudged id image this isn't something a company like discord really needs to care about. Or in other word storing a subset of the information on a passport, potentially hashed, is sufficient for like way over 90% of all companies needs for secondary account prevention.

in the end the reason a company might store a whole photo is because it's convenient and you can retrospectively apply whatever better model you want to use and in many places the penalties for a data breach aren't too big. So you might even start out with "it's bad but we only do so for a short time while building a better system" situation, and then due to the not so threatening consequence of not fixing it (or awareness) it is constantly de-prioritized and never happens...

Re: Discord says 70k users may have had their government IDs leaked in breach

#33
post #6

This is not OK, and the reporting is not OK. Opening with: > Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge. Then a big PR quote, letting a potential wrongdoer further spin it. Then closing with: > In its announcement last week, Discord said that information lik…

> Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses.

Credit card numbers are not SSNs, and I can't fathom why Discord would have the latter (I certainly never gave them any government ID either). Not to mention, "last 4 digits" of a credit card number will commonly appear on, for example, store receipts that people commonly just leave behind. Usernames can hardly be called sensitive information, either. The point is all the other stuff being tied to the username.

Re: Discord says 70k users may have had their government IDs leaked in breach

#34

Earlier quoted context omitted.

Discord doesn’t require a phone number. It’s individual community owners who opt to require it. You can create a server that doesn’t require one but it effectively means you can’t ban people since they can just sign up again on a new account.

Discord has an account flag that triggers a mandatory phone number verification. It happens if you do things like send messages too quickly over the span of about a minute, or send multiple friend requests, or join too many servers, or start too many DMs, or indeed, join any server that is set to require phone number verification.

I am in dozens of servers and have not encountered this demand for a phone number. I have been in servers that required it for moderators as part of 2FA, and I just declined to moderate there. It had no effect on my use of any other server.

Re: Discord says 70k users may have had their government IDs leaked in breach

#36
post #33
post #6

This is not OK, and the reporting is not OK. Opening with: > Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge. Then a big PR quote, letting a potential wrongdoer further spin it. Then closing with: > In its announcement last week, Discord said that information lik…

> Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses. Credit card numbers are not SSNs, and I can't fathom why Discord would have the latter (I certainly never gave them any government ID either). Not to mention, "last 4 digits" of a credit card number will com…

I think discord is one of the services that requires age verification in some countries.

Re: Discord says 70k users may have had their government IDs leaked in breach

#37
post #34

Earlier quoted context omitted.

Discord has an account flag that triggers a mandatory phone number verification. It happens if you do things like send messages too quickly over the span of about a minute, or send multiple friend requests, or join too many servers, or start too many DMs, or indeed, join any server that is set to require phone number verification.

I am in dozens of servers and have not encountered this demand for a phone number. I have been in servers that required it for moderators as part of 2FA, and I just declined to moderate there. It had no effect on my use of any other server.

Just because something hasn't happened to you, doesn't mean it doesn't happen to other people

Re: Discord says 70k users may have had their government IDs leaked in breach

#38

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

That is the bonkers thing about this story. Why take on the liability? Get what you need and toss the responsibility. If you must store it (which seems unlikely) put that extra-bad-if-leaked information behind a separate append only service for which read is heavily restricted.

Because there is no liability.

If they were fined $10k per leaked ID, then there is a serious liability there.

Right now, they publish a press release, go 'oopsie poopsie', maybe have to pay for some anit-fraud things from equifax if someone asks, and call it day.

Re: Discord says 70k users may have had their government IDs leaked in breach

#39
post #33
post #6

This is not OK, and the reporting is not OK. Opening with: > Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge. Then a big PR quote, letting a potential wrongdoer further spin it. Then closing with: > In its announcement last week, Discord said that information lik…

> Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses. Credit card numbers are not SSNs, and I can't fathom why Discord would have the latter (I certainly never gave them any government ID either). Not to mention, "last 4 digits" of a credit card number will com…

It’s an escalation path. When you store and image of an ID unnecessarily, then associate it with those last four digits, you’ve created a way to link other data sources to individuals.

Most scenarios I’ve worked with, you toss the ID image once you validate it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#40

You've got to be a complete moron uploading your gov ID to discord

No need to blame the user for the companies actions.

Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!).

User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice before it finally worked) so does what is recommended and make a support ticket. [0]

User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID.

Discord then fail to honour their end of the deal by deleting their users documents after use, and then get breached.

Full blame is on Discord for poorly handling their users data by their 3rd parties, and on the Governments forcing such practices. Discord should have their asses handed to them by the UK's ICO.

Sure, us geeks can and will use self hosted systems and find ways to avoid doing ID checks, but your avg joe isn't going to do that.

Hopefully cases like this will help with the push back on governments mandating these kind of checks, but I see the UK government just falling back to "think of the children" and laying all the blame on Discord, (who are not without fault in this case).

[0] https://support.discord.com/hc/en-us/articles/30326565624343...

[1] https://support.discord.com/hc/en-us/articles/30326565624343...

Post reply on HN