Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

191–200 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#191
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures

Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures.

Unlikely that the data will ever be deleted now, no matter if Discord pays any ransoms or not.

Re: Discord says 70k users may have had their government IDs leaked in breach

#192
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.

You mean not collecting IDs is the real answer. Easy solution is the best solution and it already is mainstream.

This is an example why that was a bad idea in the first place. No damage control for bad solutions will change that.

Re: Discord says 70k users may have had their government IDs leaked in breach

#193

You've got to be a complete moron uploading your gov ID to discord

No need to blame the user for the companies actions. Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!). User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice…

> Discord then fail to honour their end of the deal by deleting their users documents after use, and then get breached.

This wasn't documents uploaded via the automated ID checker, it was users manually sending ID documents to support in order to appeal an automated age decision.

Re: Discord says 70k users may have had their government IDs leaked in breach

#194
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

I very much do blame the corporations and governments that push for these kinds of policies in some way or another. We see things like this, which happen about as often as fucking rainfall in a mountain forest, and then also see the ever increasing push towards ID verification by corporations and government organizations that pinkie-promise to secure or not retain any of the personal data you were wrist-burned into h…

It's really just creating massive honeypots of sensitive data that will eventually leak. And when it does, the consequences are always on us

Re: Discord says 70k users may have had their government IDs leaked in breach

#195
post #124

Earlier quoted context omitted.

If I had my 'druthers, there would be a kind of physical vending machine installed at local city hall or whatever, which leverages physical controls and (dis-)economies of scale. The trusted machine would test your ID (or sometimes accept cash) and dispense single-use tokens to help prove stuff. For example, to prove (A) you are a Real Human, or (B) Real and Over Age X, or (C) you Donated $Y On Some Charity To Show S…

Yeah, introducing real world friction is seemingly one of the only ways of actually solving the problems of frictionless digital systems (apart from computational disenfranchisement, of course). It might be a better idea to frame your idea in terms of online interactive proofs rather than offline bearer tokens. It's of course a lot less private/convenient to have to bring a phone or other cell-modem enabled device to…

My concern with some "bring your phone and use it immediately" scheme is that someone could pierce the privacy by looking at a correlation between the time an account was mode or a pattern of network-traffic occurred, versus the time someone was using/near the vending machine.

Adding large and unpredictable amounts of latency makes that kind of correlation weaker and hopefully impractical.

Re: Discord says 70k users may have had their government IDs leaked in breach

#196

Earlier quoted context omitted.

That does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where th…

>Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where the proof is used. That is not nessisarially true. There are ZK setups where you can tell when a witness is reused, such as in linkable ring signatures. Another simple example is blind sign…

The easy solution is the best one. Just don't collect the info. Any problems resulting from that need to be handled differently.

Proven to work and we wouldn't be dependent on untrustworthy identity providers.

Re: Discord says 70k users may have had their government IDs leaked in breach

#197

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

The regulation lets identity verification companies store identity data for up to three years. The providers typically do it to train machine learning models for fraud detection.

Re: Discord says 70k users may have had their government IDs leaked in breach

#198
post #171

One important problem that's mostly ignored is the lack of transparency about the third-party providers handling such sensitive ID documents. When a breach occurs, public statements rarely name the exact vendor responsible, making it difficult for affected users to understand who actually had access and who might still have their data. This opacity delays accountability and creates ongoing risks, since users have no…

The third-party layer is basically the dark matter of data breaches like invisible to users, barely acknowledged by companies, and completely unaccountable when things go wrong

Re: Discord says 70k users may have had their government IDs leaked in breach

#199
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#200
post #87

Earlier quoted context omitted.

Not sure what you mean by "like europe" because in Europe they are trying to implement `European Digital Identity (EUDI)` for age verification, which will make stuff like this even worse ....

On the contrary, third parties will only get to know the age of the users, not their identities.

That is not true, EUDI is a security problem instead of a solution. It is trivial to correlate the info and there is a critical path where a breach would expose even more.

Best security: Don't collect. Nothing comes close, no even the best ZK setup.

Also, as a European citizen I really don't want it. Ironically governments aren't mature enough for that.

Post reply on HN