Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

41–50 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#41

I didn't feel comfortable giving discord my phone number when they demanded it, so I lost access to the open source communities that insist on collaborating there. I wish breaches like this would cause people to reconsider their choices but sadly, it's unlikely most users will move.

Discord doesn’t require a phone number. It’s individual community owners who opt to require it. You can create a server that doesn’t require one but it effectively means you can’t ban people since they can just sign up again on a new account.

I refuse to use their “create a server” language. It is not a server by any definition of the word server.

You can set up a community on their servers.

I’m not sure why they chose to use misleading language, but it is misleading.

Re: Discord says 70k users may have had their government IDs leaked in breach

#42

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

I’m in a different industry, but when I’ve had to collect identification for reasons we extracted metadata at the time of presentation, validated it, and discarded the image.

We would never get clearance from counsel to store that in most scenarios, and I can’t think of a reason to justify it for a age or name verification.

Re: Discord says 70k users may have had their government IDs leaked in breach

#43

When can people start going to jail for this kind of thing

Yes, good question: When can we start jailing CEOs and their employees for these blatant violations of the CPRA and GDPR?

Was thinking the same exact thing!!

Re: Discord says 70k users may have had their government IDs leaked in breach

#45
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

Also this is an issue with people willing to send important documents to some company with which they do not even have a written agreement.

Re: Discord says 70k users may have had their government IDs leaked in breach

#47
post #19
post #5

Earlier quoted context omitted.

Just a guess, but they may store the original ID card to audit duplicate accounts. If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

There are image processing methods for hashing people's faces. They don't have to store the actual photo to do that.

Models have racial biases, can't support aged faces, or look-alike faces.

Re: Discord says 70k users may have had their government IDs leaked in breach

#48
post #5

Earlier quoted context omitted.

Just a guess, but they may store the original ID card to audit duplicate accounts. If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

Just store the name and the fact that it was verified and delete the photo. You get what you need without holding on to a massive liability.

How does this help you identify duplicate accounts? If the original photo is deleted, do you just trust the model to be correct 100% of the time when it rejects the newly created account? Or do you keep the original photo and allow a human to make a final decision?

Re: Discord says 70k users may have had their government IDs leaked in breach

#49
post #33
post #6

This is not OK, and the reporting is not OK. Opening with: > Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge. Then a big PR quote, letting a potential wrongdoer further spin it. Then closing with: > In its announcement last week, Discord said that information lik…

> Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses. Credit card numbers are not SSNs, and I can't fathom why Discord would have the latter (I certainly never gave them any government ID either). Not to mention, "last 4 digits" of a credit card number will com…

Age verification is "scan your government ID or give us a detailed video of your face from various angles, open and close your mouth" etc. Not sure which is better to give out in a breach

Re: Discord says 70k users may have had their government IDs leaked in breach

#50
post #37
post #34

Earlier quoted context omitted.

I am in dozens of servers and have not encountered this demand for a phone number. I have been in servers that required it for moderators as part of 2FA, and I just declined to moderate there. It had no effect on my use of any other server.

Just because something hasn't happened to you, doesn't mean it doesn't happen to other people

It never happened to him, so it's never happened

Makes this huge data leak a real head scratcher

Post reply on HN