Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

331–340 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#331

This is the end result of forcing private companies enforce ID verification.

No, this is the result that companies dngaf about your private data. Sue them to oblivion.

Hard disagree. Companies could care about your data and still be subject to rbeach. ID verification is the source of the issue.

Re: Discord says 70k users may have had their government IDs leaked in breach

#332

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

The Discord message (in Australia at least) specifically says: The information you provide is only used to confirm your age group, then it's deleted Refer screenshot: https://www.reddit.com/r/discordapp/comments/1nkrxcp/discord... I can still swipe the message away, so I haven't done it yet. I'm going to work out how I can fake the face scan. I ain't sending Government ID to some chat app (no matter how big or small)…

That is not the system that was compromised.

It was Discord's helpdesk software (reported to be Zendesk).

If you have problems with that system, you can log a support ticket with the Discord helpdesk, attaching your ID, and they can override it for you.

Re: Discord says 70k users may have had their government IDs leaked in breach

#333

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

Discord is a fed honeypot so why would they.

Re: Discord says 70k users may have had their government IDs leaked in breach

#334

Earlier quoted context omitted.

Might that be a business model for an enterprising Secretary of State? They carefully verify your real ID, the fake ID's trivially tie back to that if the cops ask (not so useful for committing crimes), there are upcharges for multiple fake ID's, or tweaked ages / weights / photos. More upcharges for "vanity" names... "Really, your honor, it's hardly different from an author getting a DBA or LLC for his pen name."

So many were issuing IDs for illegal immigrants. I was like, why can't I have one? I'd love to erase my past arbitrarily and be unidentifiable. I decided that it was for the same reason that I couldn't get a civil union for a heterosexual partnership; politics and control. Don't we still have states and countries issuing new IDs for trans people that don't link to their old identities? Do I have to threaten to kill m…

I'm aware of the culture war battles around ID cards for illegal, trans, etc. people. A reasonable, business-like SoS - trying to boost revenue while protecting people from data breaches and other such hazards - would stay far away from those minefields.

Also, it'd only be a DBA/LLC depth of "identity". Those do not give you a citizenship, nor clean police record, nor new gender, nor legal adult status, nor marriage, nor SSN/EIN, nor voting rights, nor ...

Re: Discord says 70k users may have had their government IDs leaked in breach

#335

Earlier quoted context omitted.

From the previous[1] statement: The unauthorized party also accessed a “small number” of images of government IDs from “users who had appealed an age determination.” It makes sense they have to hang on to the ID in case of processing an appeal, which probably doesn't have the highest priority and hence stretches out in time. [1]: https://www.theverge.com/news/792032/discord-customer-servic...

The funny thing about this is that it kinda makes it OK for Discord to still have the records. But... 1. Discord still got hacked despite being a company that must have passed some level of authorised audit in order to be able to store government ID cards. (who audits the auditors? Is there an independent rating of security audit companies? What was the vulnerability? Was there any Government due diligence?) 2. This…

> passed some level of authorised audit in order to be able to store government ID cards.

In a perfect world, maybe. Not in this one.

Re: Discord says 70k users may have had their government IDs leaked in breach

#336

Pieces of shit. Do they need to look at them on a daily basis or isn't is enough to use them to confirm identity when received and then encrypt them and move them to an offline storage?

It's just a standard helpdesk application.

You submit a ticket to Discord with the ID attached when the automated ID verification didn't work for you.

Once the ticket is dealt with, Discord could have a policy of deleting the IDs, but they don't.

Re: Discord says 70k users may have had their government IDs leaked in breach

#337
post #242

Earlier quoted context omitted.

> User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID. This is the part where the user has to take at least partial blame. You have to be utterly stupid (or at the very least way too sheltered) to believe a statement like this from a company, especially when ther…

Pure victim blaming.

Calling "victim blaming" is not a retort.

There is nothing wrong with dividing up blame among both people who offer a risky choice and people who make the risky decision to accept that choice, just because one of them suffered the downside of that risk. There are a lot of other examples where if you screw something up you might get hurt, and the victim is definitely at fault. It's a spectrum, as someone else put it.

Sending your government ID over the Internet is a very risky decision, given the number and frequency of data breaches. The people who got burned here are not totally at fault but they share at least a little responsibility.

Re: Discord says 70k users may have had their government IDs leaked in breach

#338

Earlier quoted context omitted.

It might give momentum to age-verification schemes like Apple Wallet [0]. Apple gets the state ID in wallet and exposes an age verification API to apps like Discord; Discord queries the API and relies on Apple's age verification without ever getting access to the personally-identifying information. [0] https://medium.com/@drewsmith_6943/apple-wallet-id-is-the-so...

Maybe not wallets but regular "sign in with X" SSO. If all the X's can agree that one of the claims in the SSO is "is_adult", then at least you limit the exposure of your government ID to X getting breached, while all the "sign in with X" sites won't have access to the ID itself, just the claim. Of course, pretty much every X gets breached anyway, and the walled garden shenanigans are not attractive, but it's better…

This makes me hate the Twitter rebrand even more. I'm reading your use of "X" as generic name to be filled in as needed vs the poorly rebranded Musk owned platform. Then again, I could see that platform actually promoting its services to do this very thing.

Re: Discord says 70k users may have had their government IDs leaked in breach

#339

Why haven't zero knowledge proofs shined in this area? Can anyone explain?

Aren't ZKPs useless for their paranoid 'children will die if they see boobies' crap because then they'd allow for a single common token to be shared willy nilly? Not to mention that surveillance is the clear government actual goal.

No, Discord would create a new challenge for every user by creating a random nonce.

Re: Discord says 70k users may have had their government IDs leaked in breach

#340

Earlier quoted context omitted.

> I assume if I run out into the middle of the motorway, I'm likely to get hit by a car. That's why I don't do that. The problem with this is that governments are now requiring you to cross the motorway if you wish to continue having the friends you have already made, but promise that the motorways are now safe for you to cross and they will hold to account anyone who makes crossing motorways unsafe, and the DoT have…

I find it interesting where society draws the line in victim blaming. Because it is absolutely a spectrum, and there isn’t really a pattern. Personally, I don’t victim blame in this case, except for the people that explicitly voted for these short sighted “think of the children” politicians, but of course there’s no way to single them out here.

There's definitely a spectrum. Plenty of examples of people getting hurt through no fault of their own, and I would never assign blame to them. You're out walking your dog and get mugged--you did nothing risky, so you get no blame. But when you decide to do something risky, like skydiving or running in traffic or sending your government ID over the Internet (!!), and you suffer the known and anticipated downside risk, you need to at least share some of the blame. On the other side of the spectrum, if someone buys a penny stock and it loses all its value, that guy gets most of the blame.

Some other reply posted "Victim blaming!" as if that shuts down the discussion. It shouldn't.

Post reply on HN