Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

131–140 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#131
post #87

Earlier quoted context omitted.

Not sure what you mean by "like europe" because in Europe they are trying to implement `European Digital Identity (EUDI)` for age verification, which will make stuff like this even worse ....

On the contrary, third parties will only get to know the age of the users, not their identities.

“Linkability is especially problematic because untrusted entities, such as attribute providers and relying parties acting together, can correlate and link auxiliary information to the same user, thereby breaching privacy and enabling tracking, profiling, or de-anonymisation.” [1]

That’s assuming EUDI never gets breached — but if Google and every major tech company has been, it’s only a matter of time, but this will have way more personal info ....

I've been using discord for 5 years and never upload my ID … And I don't want discord (or any other company) to know my age, or any other identification ...

[1] https://www.wi.uni-muenster.de/news/5104-new-publication-pri...

Re: Discord says 70k users may have had their government IDs leaked in breach

#132
post #100

Earlier quoted context omitted.

fraud is not legal. There's a difference between lying on the playground and fraud in a business setting.

Again: fraud is de facto legal. It is ubiquitous in every part of the business world, both internal and consumer-facing.

A more useful construct is that civil offenses are only a problem if someone is aware of, motivated, and able to afford to sue you over it. Businesses do a lot of arguably illegal things that are not likely to lead to an actual lawsuit.

Re: Discord says 70k users may have had their government IDs leaked in breach

#133
post #62

I didn't feel comfortable giving discord my phone number when they demanded it, so I lost access to the open source communities that insist on collaborating there. I wish breaches like this would cause people to reconsider their choices but sadly, it's unlikely most users will move.

I also wish open-source communities would move off of Discord for another reason: Users are limited to joining a maximum of 100 servers. I've hit the cap and it's driving me crazy. It's really easy to hit it since each friend group, hobby group, gaming community, and open-source community often all have their own servers.

That limit is per account, right?

Re: Discord says 70k users may have had their government IDs leaked in breach

#134
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> this is a systemic issue of governments not having/not enforcing serious security measures.

To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII.

Not tractable.

Re: Discord says 70k users may have had their government IDs leaked in breach

#135
post #104
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

Developer time is more valuable than user data. The market is being efficient.

No.Just greedy.

Re: Discord says 70k users may have had their government IDs leaked in breach

#136

Earlier quoted context omitted.

Discord doesn’t require a phone number. It’s individual community owners who opt to require it. You can create a server that doesn’t require one but it effectively means you can’t ban people since they can just sign up again on a new account.

I refuse to use their “create a server” language. It is not a server by any definition of the word server. You can set up a community on their servers. I’m not sure why they chose to use misleading language, but it is misleading.

Fun fact: Discord called them guilds before realising that they could compete with paid services that set up actual (e.g. Mumble) servers for you by pretending this is equivalent and free

I also have trouble going along with the doublespeak. If a supermarket called their beer apple juice, I'd also not be offering my friends "apple juice", I'd call it what it is

Guild is innocuous enough and since the API docs still call their communities that, that can be a term to use among those in the know to have common and clear terminology

'Guilds in Discord represent an isolated collection of users and channels, and are often referred to as "servers" in the UI.' —https://discord.com/developers/docs/resources/guild

Re: Discord says 70k users may have had their government IDs leaked in breach

#137
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> this is a systemic issue of governments not having/not enforcing serious security measures. To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII. Not tractable.

The enforcement could be done by incentives, making sure the penalty for such breaches is large.

Re: Discord says 70k users may have had their government IDs leaked in breach

#138

Earlier quoted context omitted.

The Discord message (in Australia at least) specifically says: The information you provide is only used to confirm your age group, then it's deleted Refer screenshot: https://www.reddit.com/r/discordapp/comments/1nkrxcp/discord... I can still swipe the message away, so I haven't done it yet. I'm going to work out how I can fake the face scan. I ain't sending Government ID to some chat app (no matter how big or small)…

When the australia sub reddit was discussing the introduction of id on discord, the top comment was something along the lines of "look up openfeint". That was the day I uninstalled discord. It may not be an easy decision, especially if you are part of important social communities, but we cannot accept this level of disregard for our identities.

I just looked up "Openfeint".

It took me a while to find the connection to Discord. Not sure if I did because it seems like some mobile app for people who play mobile games with some connection to some Japanese network and hosted in China or something?

Re: Discord says 70k users may have had their government IDs leaked in breach

#140
post #53

When can people start going to jail for this kind of thing

You know it'll be the IT pros going to jail not the execs right?

Good, then they can stop the excuses for implementing the most shittiest things that ruined the web and just say no.
Post reply on HN