Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

181–190 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#181

Earlier quoted context omitted.

ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.

That does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where th…

>Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where the proof is used.

That is not nessisarially true. There are ZK setups where you can tell when a witness is reused, such as in linkable ring signatures.

Another simple example is blind signatures, you know each unblinded signature corresponds to a unique blind signature without knowing who blinded it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#183
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.

Anonymous proofs of age don't work, because (in theory) I could set up a server, plugged into my ID chip, that lets anyone download age proofs from me, and then anyone can be over 18. They don't just need to know someone is over 18 - they also need to know it's the same person using the website.

Re: Discord says 70k users may have had their government IDs leaked in breach

#185

Earlier quoted context omitted.

ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.

Anonymous proofs of age don't work, because (in theory) I could set up a server, plugged into my ID chip, that lets anyone download age proofs from me, and then anyone can be over 18. They don't just need to know someone is over 18 - they also need to know it's the same person using the website.

Make it so that the proofs are not reusable.

Re: Discord says 70k users may have had their government IDs leaked in breach

#186
post #107

Earlier quoted context omitted.

Don't governments require them to chech people's IDs to make sure they aren't kids?

It depends on the implementation. The EU's European Digital Identity Wallet will allow users to prove that they are over 18 without sharing any other personal information.

Anonymous means you can pay someone $2 to use theirs.

Re: Discord says 70k users may have had their government IDs leaked in breach

#187
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

What's wild is that the burden keeps falling on individuals to be ultra-cautious, while the systems handling the data rarely face meaningful consequences

Re: Discord says 70k users may have had their government IDs leaked in breach

#188
post #154

Earlier quoted context omitted.

You don't have to use ML models for this.

Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…

0.01% of 65M is 6,500. Also apparently only 70K people uploaded their IDs.

That being said, you can still hash faces and metadata (such as ID numbers) instead of storing the whole ID as a scanned photo, if the information is only used for duplicate checking. Hashing does not increase the racial bias. If your model has a bias it will always have a margin of error.

Re: Discord says 70k users may have had their government IDs leaked in breach

#189

More governments should provide a system like the German electronic ID*, which lets you prove your age without revealing other information. * Tragically underused because impractical

not just impractical, but also not easy and free to integrate with your service. Seems designed to push you to use a commercial product.

https://www.ausweisapp.bund.de/so-werden-sie-diensteanbieter

Re: Discord says 70k users may have had their government IDs leaked in breach

#190

Earlier quoted context omitted.

That does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where th…

>Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where the proof is used. That is not nessisarially true. There are ZK setups where you can tell when a witness is reused, such as in linkable ring signatures. Another simple example is blind sign…

Sure, but making use of that introduces new problems.

Fundamentally it limits a person to one account/nym per site. This itself removes privacy. An individual should be able to have multiple Discord nyms, right?

Then if someone gets their one-account-per-site taken/used by someone else, now administrative processes are required to undo/override that.

Then furthermore it still doesn't prevent someone from selling access to all the sites they don't care about. A higher bar than an activist simply giving it away for free, but still.

Post reply on HN