Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

171–180 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#171
One important problem that's mostly ignored is the lack of transparency about the third-party providers handling such sensitive ID documents. When a breach occurs, public statements rarely name the exact vendor responsible, making it difficult for affected users to understand who actually had access and who might still have their data. This opacity delays accountability and creates ongoing risks, since users have no meaningful way to audit or assess the practices of these shadow providers. Unless this layer of the data-handling ecosystem is discussed and regulated, future breaches will remain inevitable and largely untraceable.

Re: Discord says 70k users may have had their government IDs leaked in breach

#172
I think it is nice that the GDPR forces companies to not keep too much data about people. And you can only have data that you need for the stated purpose (of course this leaves loopholes but it is good data hygiene to always consider).

For example, if you state you want to verify age, you only need the ID for a couple of seconds. So why didn't they think about the risk of a hack before? They could have done the age verification and then immediately deleted the document. The cynical take is af course they did think about it but would take the fine if it came to that...

Maybe it is good to make an example out of Discord? Don't keep stuff around if you don't need it should be common sense.

Re: Discord says 70k users may have had their government IDs leaked in breach

#173
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

For years, I resisted TSA Pre check on principle, even though I was a frequent traveler. I finally relented when I realized there were places like Thailand that force you to give your biometrics, and almost certainly sell them back to shadowy US agencies.

> places like Thailand that force you to give your biometrics

You're being returned the favor! Anyone that's ever entered the US has had to do the same, and our prints are being stored in a DHS database.

Out of curiosity, did you not need to provide prints to get a passport in the first place? I can't image a single developed country without biometric passports.

Re: Discord says 70k users may have had their government IDs leaked in breach

#174

Earlier quoted context omitted.

Because it's free training data and great for building profiles on users so you can make money showing them targeted ads

Discord isn't really monetized through 'traditional' targeted advertising, though.

Discord no, but my credit card from Advanzia bank actually changed their TOS to allow AI training with your submitted documents for their anti-fraud model.

I complained to the CNPD of Luxembourg and sent a GDPR request, as they defaulted to doing this WITHOUT asking for consent (super illegal as doing AI training with your data is definitely not the minimum required to offer the service)

Re: Discord says 70k users may have had their government IDs leaked in breach

#175

Earlier quoted context omitted.

On the contrary, third parties will only get to know the age of the users, not their identities.

“Linkability is especially problematic because untrusted entities, such as attribute providers and relying parties acting together, can correlate and link auxiliary information to the same user, thereby breaching privacy and enabling tracking, profiling, or de-anonymisation.” [1] That’s assuming EUDI never gets breached — but if Google and every major tech company has been, it’s only a matter of time, but this will h…

For sure, but with the EU system you'd just give discord an expiring certificate that proves you're over 18. They can leak that all they want, it's worthless otherwise. Right now you have to upload your actual ID which is obviously extremely dangerous if leaked. So yes, even though there are obvious problems that you mentioned, the EU implementation is better.

Re: Discord says 70k users may have had their government IDs leaked in breach

#176

Earlier quoted context omitted.

It is specifically because you got banned for "being under 13" it comes from someone asking a question like "How many candles in this photo?" then you reply "7" then they edit the message to say "How old are you" and voila, underage ban. What you are overlooking is that Discord is the new MSN Messenger, YIM, etc your friends are not backed up in a meaningful way, nor the servers you're in, if you lose your account, y…

You can come up with all kinds of excuses, but Discord is not, and NEVER WAS a trustworthy company. > You've got to be a complete moron uploading your gov ID to discord ^ Still stands.

I'm not making excuses for companies retaining PII longer than they should. I'm simply stating why someone might give their ID. Another reason is to verify yourself as a bot developer, though supposedly that is usually done via an entirely different third party.

Re: Discord says 70k users may have had their government IDs leaked in breach

#177

Earlier quoted context omitted.

The issue is if you don't enforce the phone number requirement on your server you get all the trolls who don't use phone numbered accounts. I wish Discord would allow you to restrict known VPNs instead of requiring phone numbers. It would solve so many issues. I know a LOT of VPNs wont be caught, but if you block MOST non-residential IP blocks, you'll capture a lot of them.

Phone numbers may be required to bring order to a vast international user base, but a few dozen devs and a small user community can function without invasive moderation tactics.

[deleted]

Re: Discord says 70k users may have had their government IDs leaked in breach

#179
post #55

Earlier quoted context omitted.

It is specifically because you got banned for "being under 13" it comes from someone asking a question like "How many candles in this photo?" then you reply "7" then they edit the message to say "How old are you" and voila, underage ban. What you are overlooking is that Discord is the new MSN Messenger, YIM, etc your friends are not backed up in a meaningful way, nor the servers you're in, if you lose your account, y…

This hits the nail on the head. The big issue here is that the submitted photos were not deleted and that is quite concerning to me.

This should be a warning to anyone providing function in any way similar to what Discord is doing. Do not keep PII longer than you legally have to. Don't have to keep it at all? Delete it. Leave a redacted record such as "Image verified by x, removed on x after unban" or something simple if you must. Remove PII from ticketing systems especially on a platform like Discord where users want to be private by design.

Re: Discord says 70k users may have had their government IDs leaked in breach

#180
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

I very much do blame the corporations and governments that push for these kinds of policies in some way or another.

We see things like this, which happen about as often as fucking rainfall in a mountain forest, and then also see the ever increasing push towards ID verification by corporations and government organizations that pinkie-promise to secure or not retain any of the personal data you were wrist-burned into handing over to them.

What a toxic mix of garbage that becomes. The result is crap like the above, making the internet ever worse and basic personal data security (to not even speak of lofty things like digital privacy and using the internet anonymously) pretty much null and void even if you really do try to take the right steps.

Post reply on HN