Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/
Discord says 70k users may have had their government IDs leaked in breach
221–230 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#222It's great news. Introducing totalitarian laws and rushing companies to implement them, who would've thought something would go wrong? I hope this incident and future data breaches will finally raise awareness of which direction many regimes are going.
Re: Discord says 70k users may have had their government IDs leaked in breach
#223Mandated to be accessible to EU citizens by 2027 when all Member States have developed a Wallet solution.
Not associated but learned through it at work recently, just awesome project and thought I'd share in this context.
[1] https://commission.europa.eu/strategy-and-policy/priorities-...
[2] https://eu-digital-identity-wallet.github.io/eudi-doc-archit...
Re: Discord says 70k users may have had their government IDs leaked in breach
#224Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?
deleted = database column
Re: Discord says 70k users may have had their government IDs leaked in breach
#225One important problem that's mostly ignored is the lack of transparency about the third-party providers handling such sensitive ID documents. When a breach occurs, public statements rarely name the exact vendor responsible, making it difficult for affected users to understand who actually had access and who might still have their data. This opacity delays accountability and creates ongoing risks, since users have no…
Re: Discord says 70k users may have had their government IDs leaked in breach
#226Why are they even storing these? Once they have verified them as old enough, why keep them? These companies should be forced to release a proper account of events - like Google/Cloudflare do when they mess something up
Re: Discord says 70k users may have had their government IDs leaked in breach
#227You've got to be a complete moron uploading your gov ID to discord
Re: Discord says 70k users may have had their government IDs leaked in breach
#228Earlier quoted context omitted.
It depends on the implementation. The EU's European Digital Identity Wallet will allow users to prove that they are over 18 without sharing any other personal information.
Anonymous means you can pay someone $2 to use theirs.
Re: Discord says 70k users may have had their government IDs leaked in breach
#229Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?
I have quite a lot of experience dealing with personal identity information. Unless the latter has to be reported then it's never stored. Along with the fact it's actually deleted to comply with GDPR and friends (when it has to be recorded). In any case if any personal data is to be stored, it's always encrypted with personal keys.
Re: Discord says 70k users may have had their government IDs leaked in breach
#230I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…
> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…
In practice it's basically not used anywhere except for cigarette vending machines because it's much simpler to hire some dubious third party "wave your ID in front of your camera" service
Edit: mandatory age verification is still an atrocious idea for a number of other reasons, just to be clear