Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

211–220 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#211

Earlier quoted context omitted.

“Linkability is especially problematic because untrusted entities, such as attribute providers and relying parties acting together, can correlate and link auxiliary information to the same user, thereby breaching privacy and enabling tracking, profiling, or de-anonymisation.” [1] That’s assuming EUDI never gets breached — but if Google and every major tech company has been, it’s only a matter of time, but this will h…

For sure, but with the EU system you'd just give discord an expiring certificate that proves you're over 18. They can leak that all they want, it's worthless otherwise. Right now you have to upload your actual ID which is obviously extremely dangerous if leaked. So yes, even though there are obvious problems that you mentioned, the EU implementation is better.

I mean leaked from the EUDI side.

> the EU implementation is better.

It's better than the current implementation, sure, but you can never beat zero identifiers

Re: Discord says 70k users may have had their government IDs leaked in breach

#212
post #6

This is not OK, and the reporting is not OK. Opening with: > Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge. Then a big PR quote, letting a potential wrongdoer further spin it. Then closing with: > In its announcement last week, Discord said that information lik…

This is what most of journalism has been for quite some time. Read some of Noam Chomskys work.

Re: Discord says 70k users may have had their government IDs leaked in breach

#213
post #155
post #151

Earlier quoted context omitted.

That is exactly what EU is doing with its age verification law. Basically the service provider just has to accept the certificate and check that it is valid and all the cert says is "is over X years old". https://ageverification.dev/ And the fact that the companies have to implement the system themselves is just crazy. It is very obvious that if the government require such a check it has to provide the proof/way of c…

> just like in the physical world it provides the id card/passport/etc used for checking this. In Sweden it wasn't the government that provided id cards, but the post office and banks. It became the government's job sometime after Sweden joined the EU, after the introduction of the common EUID standard. And even then online identification is handled by a private company owned by banks: https://en.wikipedia.org/wiki/B…

We have BankID in Norway, run by DNB (I think). A single service that uses my personnummer (like a social security number but actually unique) as my user name and logs me in to almost all government services, banks, insurance companies, etc.

Re: Discord says 70k users may have had their government IDs leaked in breach

#214
It's great news. Introducing totalitarian laws and rushing companies to implement them, who would've thought something would go wrong?

I hope this incident and future data breaches will finally raise awareness of which direction many regimes are going.

Re: Discord says 70k users may have had their government IDs leaked in breach

#215

More governments should provide a system like the German electronic ID*, which lets you prove your age without revealing other information. * Tragically underused because impractical

As far as I have heard zero knowledge proofs have become optional (thus dead) in the EU wallet specification. I expect selective disclosure in all form to be completely axed next.

Re: Discord says 70k users may have had their government IDs leaked in breach

#216

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

Either the deletion promise is a lie, or the third-party vendor was storing the data anyway

Or it's all kosher as per their "internal policy" which translates to "yes, it was deleted on the server where you first uploaded it" but "pre-deletion" it was "transitioned" to "another secure server" for "your convenience" and "everything is as per our T&C that you agreed to and we follow the highest standards of data security and safety. Thank you for your time".

If Kafka were alive today, he'd see the world has outdone itself.

Re: Discord says 70k users may have had their government IDs leaked in breach

#217
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

No, governments caused the issue by demanding customers to ID themselves, while failing to provide the necessary tooling for doing so in a secure manor.

There's really only a few countries in the world who can provide the services needed to make this work. On top of my head, Estonia, Sweden and Denmark (there's probably others).

Re: Discord says 70k users may have had their government IDs leaked in breach

#219
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

The companies in question could have a flag in every user data to confirm they are over the age limit.

At worse keep the birth date, since various aspect of a service can be available depending on age (and user can change locality / country, and therefore be subject to different law).

If you keep on top of it, you have at most 3 days of user's "ongoing verification" sensible data available for theft. Keeping more than that will always be an invitation to bad actors.

Re: Discord says 70k users may have had their government IDs leaked in breach

#220

Earlier quoted context omitted.

For sure, but with the EU system you'd just give discord an expiring certificate that proves you're over 18. They can leak that all they want, it's worthless otherwise. Right now you have to upload your actual ID which is obviously extremely dangerous if leaked. So yes, even though there are obvious problems that you mentioned, the EU implementation is better.

I mean leaked from the EUDI side. > the EU implementation is better. It's better than the current implementation, sure, but you can never beat zero identifiers

Again, for sure and I agree with you - but we're talking about institutions that already have our IDs in some form or another, so just asking them to issue a certificate that says "yeah this user is actually over 18" seems like a no brainer functionality on top of an existing system. Like obviously our government office has a copy of my passport and ID card, but if those leak then we have a much bigger problem as a country.
Post reply on HN