Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

231–240 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#231

It's great news. Introducing totalitarian laws and rushing companies to implement them, who would've thought something would go wrong? I hope this incident and future data breaches will finally raise awareness of which direction many regimes are going.

Don't worry, the only thing governments will learn from this is that they need to exert even more control. They'll use this as a convenient excuse to centralize the age verification in the interest of security, which conveniently gives the government the final say over which web services you're allowed to use.

The stricter the dictatorship is, the more likely people will resist the regime.

That's why many of the traditional totalitarian regimes are populistic, they do what their people want them to do or what they can convince them is good for them. New Western hybrid regimes still didn't realize they can't rule against their own people forever.

Re: Discord says 70k users may have had their government IDs leaked in breach

#232
post #230

Earlier quoted context omitted.

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

In the context of age limits, that is wrong. The German eID has a zero knowledge method of proving that your age is above a certain number without revealing anything else. That method has been around for like 15 years and these days, thanks to smartphones with NFC readers, is quite user-friendly. In practice it's basically not used anywhere except for cigarette vending machines because it's much simpler to hire some…

I won't use the eID because I don't believe in its promises. I don't need a third party, which would be completely dependent on government, to put a signature on my net access.

I would even prefer the dubious service because of the relationship dynamics I mentioned. Best case is that age limits for the net should be enforced on device by parents. Problem solved, no unnecessary infrastructure needed.

Re: Discord says 70k users may have had their government IDs leaked in breach

#233

Earlier quoted context omitted.

From the previous[1] statement: The unauthorized party also accessed a “small number” of images of government IDs from “users who had appealed an age determination.” It makes sense they have to hang on to the ID in case of processing an appeal, which probably doesn't have the highest priority and hence stretches out in time. [1]: https://www.theverge.com/news/792032/discord-customer-servic...

The funny thing about this is that it kinda makes it OK for Discord to still have the records. But... 1. Discord still got hacked despite being a company that must have passed some level of authorised audit in order to be able to store government ID cards. (who audits the auditors? Is there an independent rating of security audit companies? What was the vulnerability? Was there any Government due diligence?) 2. This…

There is no reason for a company like Discord to ever see the ID. The owner of each relevant form of ID — usually a government agency/department — should provide an attestation service, such that users prove their identity to the agency and the agency tells the company "yes, this user is who they say they are".

It's not that hard. Legislators around the world are consistently dropping the ball on this.

Re: Discord says 70k users may have had their government IDs leaked in breach

#234

Earlier quoted context omitted.

I'd have much more sympathy if this was the first instance ever of a corporation being negligent with people's data, and nobody was expecting it. We have to expect it, now. Corporations have a horrible track record of irresponsibility, and governments have a horrible track record of not punishing them. Data breaches are absolutely routine. Knowing this, it's very foolish to hand over ID through the Internet to someon…

> I assume if I run out into the middle of the motorway, I'm likely to get hit by a car. That's why I don't do that. The problem with this is that governments are now requiring you to cross the motorway if you wish to continue having the friends you have already made, but promise that the motorways are now safe for you to cross and they will hold to account anyone who makes crossing motorways unsafe, and the DoT have…

I find it interesting where society draws the line in victim blaming. Because it is absolutely a spectrum, and there isn’t really a pattern. Personally, I don’t victim blame in this case, except for the people that explicitly voted for these short sighted “think of the children” politicians, but of course there’s no way to single them out here.

Re: Discord says 70k users may have had their government IDs leaked in breach

#235

Why haven't zero knowledge proofs shined in this area? Can anyone explain?

Aren't ZKPs useless for their paranoid 'children will die if they see boobies' crap because then they'd allow for a single common token to be shared willy nilly? Not to mention that surveillance is the clear government actual goal.

Re: Discord says 70k users may have had their government IDs leaked in breach

#236

Earlier quoted context omitted.

The funny thing about this is that it kinda makes it OK for Discord to still have the records. But... 1. Discord still got hacked despite being a company that must have passed some level of authorised audit in order to be able to store government ID cards. (who audits the auditors? Is there an independent rating of security audit companies? What was the vulnerability? Was there any Government due diligence?) 2. This…

There is no reason for a company like Discord to ever see the ID. The owner of each relevant form of ID — usually a government agency/department — should provide an attestation service, such that users prove their identity to the agency and the agency tells the company "yes, this user is who they say they are". It's not that hard. Legislators around the world are consistently dropping the ball on this.

Doesn't seem like they did. From the original article I referenced earlier:

One of Discord’s third-party customer service providers was compromised by an “unauthorized party,” the company says. [...] The unauthorized party “did not gain access to Discord directly.”

Re: Discord says 70k users may have had their government IDs leaked in breach

#237

Earlier quoted context omitted.

There is no reason for a company like Discord to ever see the ID. The owner of each relevant form of ID — usually a government agency/department — should provide an attestation service, such that users prove their identity to the agency and the agency tells the company "yes, this user is who they say they are". It's not that hard. Legislators around the world are consistently dropping the ball on this.

Doesn't seem like they did. From the original article I referenced earlier: One of Discord’s third-party customer service providers was compromised by an “unauthorized party,” the company says. [...] The unauthorized party “did not gain access to Discord directly.”

The third party company shouldn't ever need to see the IDs, either. Same issue.

Re: Discord says 70k users may have had their government IDs leaked in breach

#238

Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?

I guess they are required to store everything for years for "compliance". How else are they are going to save their butts when someone manages to fake their identity through them?

Re: Discord says 70k users may have had their government IDs leaked in breach

#239
post #207

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

In the example you give there is no needed provision to store the id or all information in the document. Only extracting the date of birth, name and document number is sufficient. Yes I know this a utopia and it won't happen. Edit: afaik storing the photo is only needed in medical cases to alternatively asses having the correct person. Bit much for something simple as age verification.

This breach is them being irresponsible with customer support software. In the case of automated age verification, the providers say that nothing identifiable gets stored and they might be lying but it’s feasible that you could run that service the way they say they do.

This breach is about the manual alternative to that, where you can appeal to Discord customer support if the automated thing says you’re not the right age. They seem to do that in part by having you send a picture of your ID.

I’m sure in their database they’re then just storing the date of birth etc, but then they obviously just don’t bother deleting the private image from the customer service software.

Re: Discord says 70k users may have had their government IDs leaked in breach

#240
post #136

Earlier quoted context omitted.

I refuse to use their “create a server” language. It is not a server by any definition of the word server. You can set up a community on their servers. I’m not sure why they chose to use misleading language, but it is misleading.

Fun fact: Discord called them guilds before realising that they could compete with paid services that set up actual (e.g. Mumble) servers for you by pretending this is equivalent and free I also have trouble going along with the doublespeak. If a supermarket called their beer apple juice, I'd also not be offering my friends "apple juice", I'd call it what it is Guild is innocuous enough and since the API docs still c…

This seems like a distinction without a difference. If you used a paid service offering Mumble servers that used some custom software that allowed them to offer multiple ... "servers" on different ports/IP addresses from a single daemon, would you really care?

Focusing on the fact that it's not really a "server" because they aren't running as separate processes seems like utterly silly pedantry, and we probably don't even know if that's actually true regarding Discord or not.

Post reply on HN