Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

141–150 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#141
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> this is a systemic issue of governments not having/not enforcing serious security measures. To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII. Not tractable.

The systemic solution wouldn’t be to do that. It would be to both remove their own requirements that organisations collect this data, and to penalise organisations for collecting it outside of a handful of already heavily regulated industries like banking.

Re: Discord says 70k users may have had their government IDs leaked in breach

#142
post #65
post #37

Earlier quoted context omitted.

Just because something hasn't happened to you, doesn't mean it doesn't happen to other people

[dead]

If it doesn't rain one day, that's not evidence there exists no rain

That's about the level of evidence that your specific user account offers to you about whether phone verification is a thing their anti-spam algorithms can trigger...

Re: Discord says 70k users may have had their government IDs leaked in breach

#143
post #137

Earlier quoted context omitted.

> this is a systemic issue of governments not having/not enforcing serious security measures. To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII. Not tractable.

The enforcement could be done by incentives, making sure the penalty for such breaches is large.

Sure, but they would still happen is my point.

Re: Discord says 70k users may have had their government IDs leaked in breach

#144
Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service.

What other third party was Discord using if not Zendesk? Who's reputation are they protecting?

[1] https://www.zendesk.fr/customer/discord/

Re: Discord says 70k users may have had their government IDs leaked in breach

#145
post #87

Earlier quoted context omitted.

Not sure what you mean by "like europe" because in Europe they are trying to implement `European Digital Identity (EUDI)` for age verification, which will make stuff like this even worse ....

On the contrary, third parties will only get to know the age of the users, not their identities.

You must be new here. /s

Re: Discord says 70k users may have had their government IDs leaked in breach

#146
post #119
post #107

Earlier quoted context omitted.

Don't governments require them to chech people's IDs to make sure they aren't kids?

Do they also require permanently storing the document instead of just the check result?

Oficially, no, unoficially, yes.

Re: Discord says 70k users may have had their government IDs leaked in breach

#147

Earlier quoted context omitted.

For years, I resisted TSA Pre check on principle, even though I was a frequent traveler. I finally relented when I realized there were places like Thailand that force you to give your biometrics, and almost certainly sell them back to shadowy US agencies.

They might not be competent enough https://www.scmp.com/week-asia/politics/article/3300568/thai...

Thailand has a big problem with identity theft, and another big problem with Chinese criminal syndicates committing various kinds of scams and fraud. So while they might share that biometric data with US government agencies, it seems more likely to me that at least one identity theft racket has acquired some of it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#148
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It’s surprising that it happened to a big name like Discord in this day and age. Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better.

> Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better.

Citation needed. /s

cough Microsoft cough

Re: Discord says 70k users may have had their government IDs leaked in breach

#149

I once accidentally set an incorrect birth year on Twitter. They locked me out of my account and insisted that I upload a government ID to unlock my account.

Did they accept the edited ID with a DoB matching the account data or how did you solve that?

Re: Discord says 70k users may have had their government IDs leaked in breach

#150
post #124

Earlier quoted context omitted.

That does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where th…

If I had my 'druthers, there would be a kind of physical vending machine installed at local city hall or whatever, which leverages physical controls and (dis-)economies of scale. The trusted machine would test your ID (or sometimes accept cash) and dispense single-use tokens to help prove stuff. For example, to prove (A) you are a Real Human, or (B) Real and Over Age X, or (C) you Donated $Y On Some Charity To Show S…

Yeah, introducing real world friction is seemingly one of the only ways of actually solving the problems of frictionless digital systems (apart from computational disenfranchisement, of course).

It might be a better idea to frame your idea in terms of online interactive proofs rather than offline bearer tokens. It's of course a lot less private/convenient to have to bring a phone or other cell-modem enabled device to the vending machine, especially for the average person who won't exercise good digital hygiene. Still, some sort of high-latency challenge-proof protocol is likely the way to go, because bearer tokens still seem too frictionless.

For example (3) could be mitigated with an intermediary marketplace that facilitated transactions with escrow. If tokens were worth say $2, then even just getting 10 at a time to sell could be worth it for the right kind of person. And personally I'd just get 10 tokens myself simply to avoid having to go back to the machine as much. In fact the optimal strategy for regular power users might be to get as many tokens as you think you might need to use (even if you have to pay for them), and then when they near expiration time you sell them to recoup your time/cost/whatever.

Post reply on HN