Earlier quoted context omitted.
fraud is not legal. There's a difference between lying on the playground and fraud in a business setting.
Again: fraud is de facto legal. It is ubiquitous in every part of the business world, both internal and consumer-facing.
Discord says 70k users may have had their government IDs leaked in breach
121–130 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#122You've got to be a complete moron uploading your gov ID to discord
A bunch of UK users are blocked from the more "free speech" (over 13) channels unless they prove their identity to Discord, to comply with the Online Safety Act.
Re: Discord says 70k users may have had their government IDs leaked in breach
#123Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?
The Discord message (in Australia at least) specifically says: The information you provide is only used to confirm your age group, then it's deleted Refer screenshot: https://www.reddit.com/r/discordapp/comments/1nkrxcp/discord... I can still swipe the message away, so I haven't done it yet. I'm going to work out how I can fake the face scan. I ain't sending Government ID to some chat app (no matter how big or small)…
Re: Discord says 70k users may have had their government IDs leaked in breach
#124Earlier quoted context omitted.
ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.
That does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where th…
The trusted machine would test your ID (or sometimes accept cash) and dispense single-use tokens to help prove stuff. For example, to prove (A) you are a Real Human, or (B) Real and Over Age X, or (C) you Donated $Y On Some Charity To Show Skin In The Game.
That ATM-esque platform would be open-source and audited to try to limit what data the government could collect, using the same TPM that would make it secure in other ways. For example, perhaps it only exposes the sum total of times each ID was used at machine, but for the previous month only.
The black-market in resold tokens would be impaired (not wholly prevented, that's impossible) by factors like:
1. The difficulty of scaling the physical portion of the work of acquiring the tokens.
2. Suspicion, if someone is using the machine dozens of times per month—who needs that many social-media signups or whatever?
3. There's no way to test if a token has already been used, except to spend it. By making reseller fraud easy, it makes the black-market harder, unless a seller also creates a durable (investigate-able) reputation. I suppose people could watch the vending-machine being used, but that adds another hard-to-scale physical requirement.
Re: Discord says 70k users may have had their government IDs leaked in breach
#125Re: Discord says 70k users may have had their government IDs leaked in breach
#126What is the use case for uploading your government ID to Discord?
Re: Discord says 70k users may have had their government IDs leaked in breach
#127What is the use case for uploading your government ID to Discord?
Re: Discord says 70k users may have had their government IDs leaked in breach
#128Earlier quoted context omitted.
In the UK we have the ICO ( https://ico.org.uk/ ) who have the ability to fine companies who fail to live up to their data retention polices and/or fail to take adequate security measures to prevent or contain a serious personal data breaches. If the UK Government are determined to enforce companies having to validate user ID's to use the company's services, then the government better well be determined to enforce ou…
I'd have much more sympathy if this was the first instance ever of a corporation being negligent with people's data, and nobody was expecting it. We have to expect it, now. Corporations have a horrible track record of irresponsibility, and governments have a horrible track record of not punishing them. Data breaches are absolutely routine. Knowing this, it's very foolish to hand over ID through the Internet to someon…
The problem with this is that governments are now requiring you to cross the motorway if you wish to continue having the friends you have already made, but promise that the motorways are now safe for you to cross and they will hold to account anyone who makes crossing motorways unsafe, and the DoT have said "Its fine, we have put in crossings on the motorway to allow you to do so safely!"
Your avg joe is going to take those reassurances made by multiple parties and assume the activity that would otherwise be risky is safe under these circumstances.
When people go on thrill rides at amusement parks and get injured because the operator or manufacturer fucked up, we don't blame the rider "saying they should know better, look at all of those ride failures in the news!", as they expected the ride to be built to a high standard, it be maintained, operated corrected, and have safety watchdogs keeping an eye on everything.
Re: Discord says 70k users may have had their government IDs leaked in breach
#129Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?
From the previous[1] statement: The unauthorized party also accessed a “small number” of images of government IDs from “users who had appealed an age determination.” It makes sense they have to hang on to the ID in case of processing an appeal, which probably doesn't have the highest priority and hence stretches out in time. [1]: https://www.theverge.com/news/792032/discord-customer-servic...
1. Discord still got hacked despite being a company that must have passed some level of authorised audit in order to be able to store government ID cards. (who audits the auditors? Is there an independent rating of security audit companies? What was the vulnerability? Was there any Government due diligence?)
2. This is a great example of why "something else" is needed for proof of identity transactions over the wire, and this "something else" should exist, and have existed for long enough to develop a level of trust, before Governments start mandating that private companies audited by other private companies must undertake actions that require the storage of Government ID documents. Banking level security and regulation should be required for any aggregator of such sensitive data. That fucking Discord had Government ID docs at all is beyond ridiculous. More-so for Governments of countries other than where Discord was incorporated. A state-sponsored Russian / Chinese / North Korean / Iranian / Discord-alternative would have been an interesting situation. The implicit trust in Discord, and any other "app publisher" requiring ID confirmation is just peculiar.
Re: Discord says 70k users may have had their government IDs leaked in breach
#130What is the use case for uploading your government ID to Discord?
Joining "NSFW channels", which usually means porn. But some normal channel are also tagged NSFW to opt out of Discord's forced content filter on public servers, which has occasional baffling false positives.
Wow.