Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

241–250 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#242

Earlier quoted context omitted.

No need to blame the user for the companies actions. Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!). User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice…

> User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID. This is the part where the user has to take at least partial blame. You have to be utterly stupid (or at the very least way too sheltered) to believe a statement like this from a company, especially when ther…

Pure victim blaming.

Re: Discord says 70k users may have had their government IDs leaked in breach

#243
post #104
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

Developer time is more valuable than user data. The market is being efficient.

Externalized costs aren't weighed in that calculation

Re: Discord says 70k users may have had their government IDs leaked in breach

#244

The whole "it wasn't us, it was our third-party vendor" line is getting way too common. If you're collecting government IDs for age verification, the security bar should be extremely high... no matter who's handling the data

But our subcontractor made a contractual promise to use only sub-subcontractors who use only sub-sub-subcontractors who promise to be secure!

Re: Discord says 70k users may have had their government IDs leaked in breach

#245
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

Same. I automatically assume that all information I send to any organisation will end up on the Internet sooner or later be it by accident or sold to some shady third party.

Re: Discord says 70k users may have had their government IDs leaked in breach

#248
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

> Facts are reported because they are important.

Without going too much off-topic: In a vacuum, you are right. In reality, facts are reported because they sell.

It is a good day when important facts like this one happen to coincide with what people what to know more about. (the recent UK attempt at stripping the rights of its citizens)

Tomorrow, people will have forgotten all about it, and the government can continue to expand its powers without anyone talking about it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#249

You've got to be a complete moron uploading your gov ID to discord

Are you seriously blaming kids and teenagers (who spend their free time on Discord) because they are not smart enough to know better and form communities elsewhere?

You can do better than victim blame, and instead point the finger at Discord and whoever told the British government that delegating ID control to third-parties was a good idea.

Re: Discord says 70k users may have had their government IDs leaked in breach

#250
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> this is a systemic issue of governments not having/not enforcing serious security measures. To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII. Not tractable.

Audit at random? With severe penalty in case of non compliance.
Post reply on HN