Earlier quoted context omitted.
You don't have to use ML models for this.
Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…
Discord says 70k users may have had their government IDs leaked in breach
281–290 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#282The hackers claim they have data of 5.5 million, discord is saying 70k. Hmmmm
Re: Discord says 70k users may have had their government IDs leaked in breach
#283I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…
If you upload anything to the internet, it's public. Even the passwords you type are potentially public.
Re: Discord says 70k users may have had their government IDs leaked in breach
#284Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/
Kinda feels like Discord is lying by omission.
Edit: Actually my bet is their support staff just sold them out.
Re: Discord says 70k users may have had their government IDs leaked in breach
#285Re: Discord says 70k users may have had their government IDs leaked in breach
#286Earlier quoted context omitted.
It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.
Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.
Re: Discord says 70k users may have had their government IDs leaked in breach
#287Earlier quoted context omitted.
“Linkability is especially problematic because untrusted entities, such as attribute providers and relying parties acting together, can correlate and link auxiliary information to the same user, thereby breaching privacy and enabling tracking, profiling, or de-anonymisation.” [1] That’s assuming EUDI never gets breached — but if Google and every major tech company has been, it’s only a matter of time, but this will h…
For sure, but with the EU system you'd just give discord an expiring certificate that proves you're over 18. They can leak that all they want, it's worthless otherwise. Right now you have to upload your actual ID which is obviously extremely dangerous if leaked. So yes, even though there are obvious problems that you mentioned, the EU implementation is better.
Re: Discord says 70k users may have had their government IDs leaked in breach
#288I kinda hope and root for EU's spec ( https://ageverification.dev/Technical%20Specification/archit... ) with "Zero Knowledge Proof" that wouldn't require passing actual ID to the service…
[1] - https://www.rtalabel.org/index.php?content=howtofaq#single
Re: Discord says 70k users may have had their government IDs leaked in breach
#289Earlier quoted context omitted.
> just like in the physical world it provides the id card/passport/etc used for checking this. In Sweden it wasn't the government that provided id cards, but the post office and banks. It became the government's job sometime after Sweden joined the EU, after the introduction of the common EUID standard. And even then online identification is handled by a private company owned by banks: https://en.wikipedia.org/wiki/B…
We have BankID in Norway, run by DNB (I think). A single service that uses my personnummer (like a social security number but actually unique) as my user name and logs me in to almost all government services, banks, insurance companies, etc.
The system is highly convenient and pretty safe, but it does still need vigilance from the user. Which is tricky, re all those phishing attempts and click-scams which people fall for again and again and again.
Re: Discord says 70k users may have had their government IDs leaked in breach
#290Earlier quoted context omitted.
It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.
This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.
We need to make sure nobody is surprised. Everyone should rewrite every "upload" button in their head to say "publish".