Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

221–230 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#221
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

[deleted]

Re: Discord says 70k users may have had their government IDs leaked in breach

#222

It's great news. Introducing totalitarian laws and rushing companies to implement them, who would've thought something would go wrong? I hope this incident and future data breaches will finally raise awareness of which direction many regimes are going.

Don't worry, the only thing governments will learn from this is that they need to exert even more control. They'll use this as a convenient excuse to centralize the age verification in the interest of security, which conveniently gives the government the final say over which web services you're allowed to use.

Re: Discord says 70k users may have had their government IDs leaked in breach

#223
This is why I am really looking forward to PIDs in the European Digital Identity ecosystem (EUDI) [1]. This works with the OpenID Verifiable Credentials spec built on top of Oauth2. There are open source solutions in the competition for building the EUDI Wallet and the architecture and reference framework is openly accessible [2]. All credentials are kept with the holder (you) at all times. Basically implementation of the EU eIDAS 2.0 regulation, obviously subject to GDPR.

Mandated to be accessible to EU citizens by 2027 when all Member States have developed a Wallet solution.

Not associated but learned through it at work recently, just awesome project and thought I'd share in this context.

[1] https://commission.europa.eu/strategy-and-policy/priorities-...

[2] https://eu-digital-identity-wallet.github.io/eudi-doc-archit...

[3] https://github.com/openwallet-foundation/credo-ts

Re: Discord says 70k users may have had their government IDs leaked in breach

#224
post #82

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

deleted = database column

Or maybe they define 'delete' as moving data from "production" env to "deleted" env and if someone asked that data to be deleted even from there then the next step is moving from "deleted" to "purged".

Re: Discord says 70k users may have had their government IDs leaked in breach

#225
post #171

One important problem that's mostly ignored is the lack of transparency about the third-party providers handling such sensitive ID documents. When a breach occurs, public statements rarely name the exact vendor responsible, making it difficult for affected users to understand who actually had access and who might still have their data. This opacity delays accountability and creates ongoing risks, since users have no…

The biggest problem is giving data to people in the first place.

Re: Discord says 70k users may have had their government IDs leaked in breach

#227

You've got to be a complete moron uploading your gov ID to discord

What would you say of a lot of FOSS companies/orgs who love to stay on places like Discord? Hell, some entities that pride themselves on "privacy" and "E2EE" shit are specifically on Discord. I think that must go beyond moronity.

Re: Discord says 70k users may have had their government IDs leaked in breach

#228

Earlier quoted context omitted.

It depends on the implementation. The EU's European Digital Identity Wallet will allow users to prove that they are over 18 without sharing any other personal information.

Anonymous means you can pay someone $2 to use theirs.

Surely that's solved easily by ensuring a 1:1 association between the proof of age and account?

Re: Discord says 70k users may have had their government IDs leaked in breach

#229

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

The fact the deletion is at all needed speaks for a pretty terrible design. The data should simply not be permanently stored.

I have quite a lot of experience dealing with personal identity information. Unless the latter has to be reported then it's never stored. Along with the fact it's actually deleted to comply with GDPR and friends (when it has to be recorded). In any case if any personal data is to be stored, it's always encrypted with personal keys.

Re: Discord says 70k users may have had their government IDs leaked in breach

#230
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

In the context of age limits, that is wrong. The German eID has a zero knowledge method of proving that your age is above a certain number without revealing anything else. That method has been around for like 15 years and these days, thanks to smartphones with NFC readers, is quite user-friendly.

In practice it's basically not used anywhere except for cigarette vending machines because it's much simpler to hire some dubious third party "wave your ID in front of your camera" service

Edit: mandatory age verification is still an atrocious idea for a number of other reasons, just to be clear

Post reply on HN