Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

161–170 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#162

Earlier quoted context omitted.

That is the bonkers thing about this story. Why take on the liability? Get what you need and toss the responsibility. If you must store it (which seems unlikely) put that extra-bad-if-leaked information behind a separate append only service for which read is heavily restricted.

Because it's free training data and great for building profiles on users so you can make money showing them targeted ads

Discord isn't really monetized through 'traditional' targeted advertising, though.

Re: Discord says 70k users may have had their government IDs leaked in breach

#163

Earlier quoted context omitted.

I just looked up "Openfeint". It took me a while to find the connection to Discord. Not sure if I did because it seems like some mobile app for people who play mobile games with some connection to some Japanese network and hosted in China or something?

OpenFeint was founded by the same guy who founded Discord. From the Wikipedia page: "In 2011, OpenFeint was party to a class action suit with allegations including computer fraud, invasion of privacy, breach of contract, bad faith and seven other statutory violations. According to a news report "OpenFeint's business plan included accessing and disclosing personal information without authorization to mobile-device app…

Oh wow ok.

Now I understand :D

Re: Discord says 70k users may have had their government IDs leaked in breach

#164
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It's not surprising because there's never been a significant penalty for it, I guess because everybody just got completely used to massive breaches without much reaction. But then again it's very hard to get legislation passed that's not in the interests of big business.

[dead]

Re: Discord says 70k users may have had their government IDs leaked in breach

#165

What is the use case for uploading your government ID to Discord?

Two of the other replies are wrong. This isn't actually about the new 18+ age verification stuff that countries seem to be ramming through right now - as far as I know, Discord uses third parties for that service. The link from Discord's statement in the article mentions that this is about appealing account bans of users who were suspected to be under the legal age to use Discord at all (<13 in most places). This is an older thing, which also explains the amount of data that was leaked.

Re: Discord says 70k users may have had their government IDs leaked in breach

#166
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Re: Discord says 70k users may have had their government IDs leaked in breach

#167
post #160
post #155

Earlier quoted context omitted.

> just like in the physical world it provides the id card/passport/etc used for checking this. In Sweden it wasn't the government that provided id cards, but the post office and banks. It became the government's job sometime after Sweden joined the EU, after the introduction of the common EUID standard. And even then online identification is handled by a private company owned by banks: https://en.wikipedia.org/wiki/B…

Yeah we have something similar here in Finland with banks doing most of the (strong) identification. This also makes things difficult for immigrants for the first month or two in the country as a lot of services (like making a phone or internet contract) require this identification to use but it is also a bit of a hassle to get a bank account (but getting a new bank account in a different bank once you have a bank ac…

These systems likely could be extended to just provide age information. If there truly was a wish for it. The suomi.fi systems can be configured. To pass or not pass address for example. So I see no need to pass personal identity number.

Re: Discord says 70k users may have had their government IDs leaked in breach

#168
post #167
post #160

Earlier quoted context omitted.

Yeah we have something similar here in Finland with banks doing most of the (strong) identification. This also makes things difficult for immigrants for the first month or two in the country as a lot of services (like making a phone or internet contract) require this identification to use but it is also a bit of a hassle to get a bank account (but getting a new bank account in a different bank once you have a bank ac…

These systems likely could be extended to just provide age information. If there truly was a wish for it. The suomi.fi systems can be configured. To pass or not pass address for example. So I see no need to pass personal identity number.

Yes and the "backend" (what provides the certificate to the app) for the age verification app for Finland will most likely be suomi.fi (or some dvv.fi thing directly) systems.

But we can't realistically expect every service that needs age check to work with 27 (eu countries) different systems but instead we need to unify it into a single api contract which is what this age verification app basically does.

Re: Discord says 70k users may have had their government IDs leaked in breach

#169

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Why are people assuming they did store it after the process was completed? With the relatively low number leaked here it could have been information collected actively during an ongoing breach, not a dump of some permanent database.

There are only a handful of countries where you are legally mandated to dox yourself and it's a recent change.

You'd expect the numbers to be "low" either way.

Re: Discord says 70k users may have had their government IDs leaked in breach

#170
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

Honestly I don't understand why so many things are tied to one secret _that you have to share with others_ all the time. Why is there no rotation possible? Why is there no API to issue a new secret and mark the previous one as leaked? Why is there no way to have a temporary validation code for travels, which gets auto revoked once the citizens are back in their home country? It's like governments don't understand wha…

Governments don't get a damn thing about the internet. They just want to govern, and justify the spending.

Their goal is not to build resilient systems — it iss to preserve control. The internet was born decentralised, while governments operate through centralised hierarchies. Every system they design ends up reflecting that mindset: central authority, rigid bureaucracy, zero trust in the user.

So instead of adopting key rotation, temporary credentials, or privacy-first mechanisms, they recreate 1950s paperwork in digital form and call it innovation.

Post reply on HN