Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

271–280 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#271
post #230

Earlier quoted context omitted.

In the context of age limits, that is wrong. The German eID has a zero knowledge method of proving that your age is above a certain number without revealing anything else. That method has been around for like 15 years and these days, thanks to smartphones with NFC readers, is quite user-friendly. In practice it's basically not used anywhere except for cigarette vending machines because it's much simpler to hire some…

I won't use the eID because I don't believe in its promises. I don't need a third party, which would be completely dependent on government, to put a signature on my net access. I would even prefer the dubious service because of the relationship dynamics I mentioned. Best case is that age limits for the net should be enforced on device by parents. Problem solved, no unnecessary infrastructure needed.

Theoretically you could have anyone sign and attest to your age at any time. So maybe the government gives you an attestation of 0 at birth, with timestamp (allowing age to be calculated at any time), as part of the normal new-human bureaucracy. And/or maybe you can separately hire an accredited (co-signed?) lab to perform carbon dating on you later on :)

Re: Discord says 70k users may have had their government IDs leaked in breach

#272
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.

Re: Discord says 70k users may have had their government IDs leaked in breach

#273

Earlier quoted context omitted.

No need to blame the user for the companies actions. Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!). User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice…

> User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID. This is the part where the user has to take at least partial blame. You have to be utterly stupid (or at the very least way too sheltered) to believe a statement like this from a company, especially when ther…

Nobody believes the policy or even cares about the policy. They need to use the service, because everyone else is using the service, and they don't have a choice. Plain and simple.

Re: Discord says 70k users may have had their government IDs leaked in breach

#274

I work at a company where we also store government IDs in Zendesk. I've alerted management multiple times but no one seems to care. It's a disaster waiting to happen…

Leave paper trails (emails most likely) and keep hard copies.

Re: Discord says 70k users may have had their government IDs leaked in breach

#275
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

[deleted]

Re: Discord says 70k users may have had their government IDs leaked in breach

#276

I understand I grew up in a different era but it is beyond absurd to me that a chat application requires government ID from it's users. I understand the rationale but I do not find it convincing in the least, especially with the way that security is treated at basically any entity that has this kind of info on file. I do not like this world that we have created and I would like to apply for a full refund

Rationale is likely the requirements of age verification rules by UK, some US states, etc.

We could likely see a bit more of these data leaks in the future I guess, due to how there are more and more countries/states adopting this.

Re: Discord says 70k users may have had their government IDs leaked in breach

#277
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

I don't understand how we allow these companies to protect each other even in the face of egregious malpractice.

This might even be a PR move. They fucked up and can merely say "a third party" did it. Who's gonna verify this?

Unless we have whistleblowers we will never know. What a disgrace.

Re: Discord says 70k users may have had their government IDs leaked in breach

#278
post #207

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

In the example you give there is no needed provision to store the id or all information in the document. Only extracting the date of birth, name and document number is sufficient. Yes I know this a utopia and it won't happen. Edit: afaik storing the photo is only needed in medical cases to alternatively asses having the correct person. Bit much for something simple as age verification.

Even then, for age verification, just verify the ID, record + sign the verification, and DESTROY THE DATA! Don't retain the original document "just in case", or even the birthday or name.

Re: Discord says 70k users may have had their government IDs leaked in breach

#280
post #154

Earlier quoted context omitted.

You don't have to use ML models for this.

Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…

If they can't handle that many users then they should close signups.

The product scales, but sfaely using users' data doesn't? Hardly an excuse.

Post reply on HN