WTF were they thinking about?
Discord says 70k users may have had their government IDs leaked in breach
301–310 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#302I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…
It’s surprising that it happened to a big name like Discord in this day and age. Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better.
If I want the ID of a bunch of Discord users, I don't go after Discord directly, I find some bot that the targeted users have on their discord servers, or third party service that Discord uses themselves. Then I find some individual person with access to those things, and I harass and/or threaten that person until they give me what I want to make me go away. If I think they might be crooked, I might just offer them a cut of the take. I'm probably not paying them though, not unless I think I can leverage them against other targets and need to keep them around.
Either way, an individual person isn't going to be able to hold off a coordinated attack for very long, and law enforcement generally doesn't give a shit about internet randoms attacking individual people.
Re: Discord says 70k users may have had their government IDs leaked in breach
#303Earlier quoted context omitted.
Again: fraud is de facto legal. It is ubiquitous in every part of the business world, both internal and consumer-facing.
De facto is the opposite of de jure, so no, non-enforcement doesn't make it legal
Re: Discord says 70k users may have had their government IDs leaked in breach
#304I kinda hope and root for EU's spec ( https://ageverification.dev/Technical%20Specification/archit... ) with "Zero Knowledge Proof" that wouldn't require passing actual ID to the service…
We're talking about a solved problem here.
Similar to storing passwords as unhashed/plaintext.
Re: Discord says 70k users may have had their government IDs leaked in breach
#305Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/
The wording Discord used leaves open the possibility that a ZenDesk account was compromised through no fault of ZenDesk. Kinda feels like Discord is lying by omission. Edit: Actually my bet is their support staff just sold them out.
> they were able to compromise Discord Zendesk by compromising a "BPO Agent" (outsourced support).
> Of course, as is tradition, it is also entirely possible they're lying
Re: Discord says 70k users may have had their government IDs leaked in breach
#306Discord uses Zendesk (1). However in the press release they don't name the third party that was compromised, and Zendesk denies that it was their service. What other third party was Discord using if not Zendesk? Who's reputation are they protecting? [1] https://www.zendesk.fr/customer/discord/
Re: Discord says 70k users may have had their government IDs leaked in breach
#307Earlier quoted context omitted.
No, governments caused the issue by demanding customers to ID themselves, while failing to provide the necessary tooling for doing so in a secure manor. There's really only a few countries in the world who can provide the services needed to make this work. On top of my head, Estonia, Sweden and Denmark (there's probably others).
There’s no unbreakable secure tooling, none. It might be unbreakable against script-kiddies level of hacking, even though I have my doubts even about that, but Snowden and the general atmosphere during the last decade or so have proved that State actors can put their hands on almost any piece of data out there, either through genuine hacking or other means involving their monopoly on violence.
Here was an interesting example recently https://help.kagi.com/kagi/privacy/privacy-pass.html
Re: Discord says 70k users may have had their government IDs leaked in breach
#308Earlier quoted context omitted.
It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.
Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.
[0] https://medium.com/@drewsmith_6943/apple-wallet-id-is-the-so...
Re: Discord says 70k users may have had their government IDs leaked in breach
#309Re: Discord says 70k users may have had their government IDs leaked in breach
#310Every time I see a data breach caused by a third party vendor, I can't help but wonder why are these big companies so deeply reliant on outsourcing, yet so lax when it comes to controlling security?