Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

301–310 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#302
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It’s surprising that it happened to a big name like Discord in this day and age. Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better.

Penetrations of this sort happen differently.

If I want the ID of a bunch of Discord users, I don't go after Discord directly, I find some bot that the targeted users have on their discord servers, or third party service that Discord uses themselves. Then I find some individual person with access to those things, and I harass and/or threaten that person until they give me what I want to make me go away. If I think they might be crooked, I might just offer them a cut of the take. I'm probably not paying them though, not unless I think I can leverage them against other targets and need to keep them around.

Either way, an individual person isn't going to be able to hold off a coordinated attack for very long, and law enforcement generally doesn't give a shit about internet randoms attacking individual people.

Re: Discord says 70k users may have had their government IDs leaked in breach

#303
post #121
post #100

Earlier quoted context omitted.

Again: fraud is de facto legal. It is ubiquitous in every part of the business world, both internal and consumer-facing.

De facto is the opposite of de jure, so no, non-enforcement doesn't make it legal

Again, nobody said it was legal. They said de facto legal, which does not mean it's actually legal but just that it's effectively treated as legal.

Re: Discord says 70k users may have had their government IDs leaked in breach

#304

I kinda hope and root for EU's spec ( https://ageverification.dev/Technical%20Specification/archit... ) with "Zero Knowledge Proof" that wouldn't require passing actual ID to the service…

This.

We're talking about a solved problem here.

Similar to storing passwords as unhashed/plaintext.

Re: Discord says 70k users may have had their government IDs leaked in breach

#305
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

The wording Discord used leaves open the possibility that a ZenDesk account was compromised through no fault of ZenDesk. Kinda feels like Discord is lying by omission. Edit: Actually my bet is their support staff just sold them out.

vx-underground claims to have communication with the group, and this post of theirs adds to the support agent theory: https://xcancel.com/vxunderground/status/1976238815665856646

> they were able to compromise Discord Zendesk by compromising a "BPO Agent" (outsourced support).

> Of course, as is tradition, it is also entirely possible they're lying

Re: Discord says 70k users may have had their government IDs leaked in breach

#306
post #144

Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/

Do you happen to have a link to Zendesk's denial?

Re: Discord says 70k users may have had their government IDs leaked in breach

#307

Earlier quoted context omitted.

No, governments caused the issue by demanding customers to ID themselves, while failing to provide the necessary tooling for doing so in a secure manor. There's really only a few countries in the world who can provide the services needed to make this work. On top of my head, Estonia, Sweden and Denmark (there's probably others).

There’s no unbreakable secure tooling, none. It might be unbreakable against script-kiddies level of hacking, even though I have my doubts even about that, but Snowden and the general atmosphere during the last decade or so have proved that State actors can put their hands on almost any piece of data out there, either through genuine hacking or other means involving their monopoly on violence.

It’s absolutely possible to verify something anonymously.

Here was an interesting example recently https://help.kagi.com/kagi/privacy/privacy-pass.html

Re: Discord says 70k users may have had their government IDs leaked in breach

#308
post #272

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.

It might give momentum to age-verification schemes like Apple Wallet [0]. Apple gets the state ID in wallet and exposes an age verification API to apps like Discord; Discord queries the API and relies on Apple's age verification without ever getting access to the personally-identifying information.

[0] https://medium.com/@drewsmith_6943/apple-wallet-id-is-the-so...

Re: Discord says 70k users may have had their government IDs leaked in breach

#310
post #295

Every time I see a data breach caused by a third party vendor, I can't help but wonder why are these big companies so deeply reliant on outsourcing, yet so lax when it comes to controlling security?

Usually some regulation change that the company is not aware off, they have to run to find a fix as soon as possible, some business guy who don't know anything about tech find a vendor who are ready to sell a solution (they probably created their whole business last month on a gamble that the new regulation would be passed and that businesses would be rushing for a solution). Then they simply buy that solution "for compliance" as a top down decision, even when internal employees ring the warning bell.
Post reply on HN