I am not surprised these laws are landing with such little resistence.
Discord says 70k users may have had their government IDs leaked in breach
261–270 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#262Re: Discord says 70k users may have had their government IDs leaked in breach
#263Earlier quoted context omitted.
That is exactly what EU is doing with its age verification law. Basically the service provider just has to accept the certificate and check that it is valid and all the cert says is "is over X years old". https://ageverification.dev/ And the fact that the companies have to implement the system themselves is just crazy. It is very obvious that if the government require such a check it has to provide the proof/way of c…
> And the fact that the companies have to implement the system themselves is just crazy. Isn’t this how most industry regulations work? It’s not like the government provides designs to car companies to reduce emissions or improve crash safety.
Or are you suggesting that anyone should be able to make their own passport?
Or a bit closer example. If there was no official id cards/passports/etc (there currently is no official way of proving your age online) and the government made a law that mandates that one has to be over X to buy alcohol. Who’s job is it to provide the means to prove that you are over X?
For the car a proper analogy would be the goverment requiring drivers license. Who provides the drivers license? Should every manufacturer provide its own?
Re: Discord says 70k users may have had their government IDs leaked in breach
#264Earlier quoted context omitted.
For years, I resisted TSA Pre check on principle, even though I was a frequent traveler. I finally relented when I realized there were places like Thailand that force you to give your biometrics, and almost certainly sell them back to shadowy US agencies.
> places like Thailand that force you to give your biometrics You're being returned the favor! Anyone that's ever entered the US has had to do the same, and our prints are being stored in a DHS database. Out of curiosity, did you not need to provide prints to get a passport in the first place? I can't image a single developed country without biometric passports.
Re: Discord says 70k users may have had their government IDs leaked in breach
#265Re: Discord says 70k users may have had their government IDs leaked in breach
#266Earlier quoted context omitted.
This breach is them being irresponsible with customer support software. In the case of automated age verification, the providers say that nothing identifiable gets stored and they might be lying but it’s feasible that you could run that service the way they say they do. This breach is about the manual alternative to that, where you can appeal to Discord customer support if the automated thing says you’re not the righ…
Sounds like a great use case for an automated ML cleanup/reporting feature. Maybe as a daemon as a bolt-on fix, or integrated as a feature into the support software itself.
Re: Discord says 70k users may have had their government IDs leaked in breach
#267I do not like this world that we have created and I would like to apply for a full refund
Re: Discord says 70k users may have had their government IDs leaked in breach
#268I once accidentally set an incorrect birth year on Twitter. They locked me out of my account and insisted that I upload a government ID to unlock my account.
Did they accept the edited ID with a DoB matching the account data or how did you solve that?
Re: Discord says 70k users may have had their government IDs leaked in breach
#269Earlier quoted context omitted.
I'm not willing, I just don't have a choice. The US should regulate it from the top down like Europe does
Not sure what you mean by "like europe" because in Europe they are trying to implement `European Digital Identity (EUDI)` for age verification, which will make stuff like this even worse ....
EUID is made for working with government agencies, banks, etc where you need proper identification of the person and the age verification for verifying ones age (it doesn't even say how old you are just that you are over X years old)
End goal is to unify them into the same app at some point but the certificates/validation flows are different. Also as the use cases are very different for the proper identification a whilelist is used on who is allowed to request it. With age verification as it is just a certificate that anyone can validate against the public key so no whitelisting possible (or wanted really)
Re: Discord says 70k users may have had their government IDs leaked in breach
#270ID checks, driven by prudishness, are an absolute gift to the big social media companies. They're the only entities whom (a) already know the check's answers, and (b) have the resources to keep hackers largely at bay. I am not surprised these laws are landing with such little resistence.