Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

281–290 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#281
post #154

Earlier quoted context omitted.

You don't have to use ML models for this.

Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…

Do you understand how image hashing works? You don't need machine learning just to check if two images are potentially identical.

Re: Discord says 70k users may have had their government IDs leaked in breach

#283
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

I don't think you have become jaded. It's just the truth of the internet.

If you upload anything to the internet, it's public. Even the passwords you type are potentially public.

Re: Discord says 70k users may have had their government IDs leaked in breach

#284
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

The wording Discord used leaves open the possibility that a ZenDesk account was compromised through no fault of ZenDesk.

Kinda feels like Discord is lying by omission.

Edit: Actually my bet is their support staff just sold them out.

Re: Discord says 70k users may have had their government IDs leaked in breach

#286
post #272

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.

Heck, i would like a fake name, social security number, and birthdate as well while I am at it

Re: Discord says 70k users may have had their government IDs leaked in breach

#287

Earlier quoted context omitted.

“Linkability is especially problematic because untrusted entities, such as attribute providers and relying parties acting together, can correlate and link auxiliary information to the same user, thereby breaching privacy and enabling tracking, profiling, or de-anonymisation.” [1] That’s assuming EUDI never gets breached — but if Google and every major tech company has been, it’s only a matter of time, but this will h…

For sure, but with the EU system you'd just give discord an expiring certificate that proves you're over 18. They can leak that all they want, it's worthless otherwise. Right now you have to upload your actual ID which is obviously extremely dangerous if leaked. So yes, even though there are obvious problems that you mentioned, the EU implementation is better.

EUDI requires Google or Apple, I hope it is DOA. It is even bloated before anyone adopted it.

Re: Discord says 70k users may have had their government IDs leaked in breach

#288

I kinda hope and root for EU's spec ( https://ageverification.dev/Technical%20Specification/archit... ) with "Zero Knowledge Proof" that wouldn't require passing actual ID to the service…

My preference would be just requiring site operators to add the RTA header [1] for anything that could potentially be adult in nature or user contributed content and let parents decide if devices should have parental controls. Not perfect, nothing is but would protect most small children. Teens will easily bypass any method as many today watch porn together in rated-g/pg video games that allow setting up a streaming player in-game.

[1] - https://www.rtalabel.org/index.php?content=howtofaq#single

Re: Discord says 70k users may have had their government IDs leaked in breach

#289
post #155

Earlier quoted context omitted.

> just like in the physical world it provides the id card/passport/etc used for checking this. In Sweden it wasn't the government that provided id cards, but the post office and banks. It became the government's job sometime after Sweden joined the EU, after the introduction of the common EUID standard. And even then online identification is handled by a private company owned by banks: https://en.wikipedia.org/wiki/B…

We have BankID in Norway, run by DNB (I think). A single service that uses my personnummer (like a social security number but actually unique) as my user name and logs me in to almost all government services, banks, insurance companies, etc.

And unfortunately it's also used in some places outside the ones you're mentioning, e.g. private persons renting out their camper (I've seen this). Which opens the doors to fraud, as has happened too many times (the fraudsters make it look like a normal bank-id lookup, gets you to do it twice, and then they have enough to open your bank account and withdraw money. If they can get you do to it three times they also have enough to remove the limit on withdrawal, and empty your account).

The system is highly convenient and pretty safe, but it does still need vigilance from the user. Which is tricky, re all those phishing attempts and click-scams which people fall for again and again and again.

Re: Discord says 70k users may have had their government IDs leaked in breach

#290

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their information or at least took some protective measures like partial redaction and use-case watermarking, this breach would be less of an issue and/or such breaches would be less common.

We need to make sure nobody is surprised. Everyone should rewrite every "upload" button in their head to say "publish".

Post reply on HN