Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

311–320 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#312

Pieces of shit. Do they need to look at them on a daily basis or isn't is enough to use them to confirm identity when received and then encrypt them and move them to an offline storage?

So many companies do not understand this simple principle. Blast radius reduction. But no, they need to have everything online, and instantly accessible all the time. Because they can't possibly be inconvenienced with a short delay in case they ever want to look at that piece of data that they will never want to look at anyway.

It is going to take a long time before companies realize that data they don't need is a liability, not an asset.

Re: Discord says 70k users may have had their government IDs leaked in breach

#313
post #154

Earlier quoted context omitted.

Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…

0.01% of 65M is 6,500. Also apparently only 70K people uploaded their IDs. That being said, you can still hash faces and metadata (such as ID numbers) instead of storing the whole ID as a scanned photo, if the information is only used for duplicate checking. Hashing does not increase the racial bias. If your model has a bias it will always have a margin of error.

neat, but how do users appeal a false positive? Do companies just trust the users or should the company retain the original information so they can manually verify?

Re: Discord says 70k users may have had their government IDs leaked in breach

#314

Earlier quoted context omitted.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

It's a valid question, which speaks to the frequency with which these things happen. That's isn't trivialising the problem.

No, it's very much used to express the sentiment "I don't care about this, and wish people would stop talking about it."

Re: Discord says 70k users may have had their government IDs leaked in breach

#315

ID checks, driven by prudishness, are an absolute gift to the big social media companies. They're the only entities whom (a) already know the check's answers, and (b) have the resources to keep hackers largely at bay. I am not surprised these laws are landing with such little resistence.

Its as if the big social media companies lobbied for extra redtape, eh?

Surprisingly they've generally lobbied against it for ideological reasons despite their economic incentives.

Re: Discord says 70k users may have had their government IDs leaked in breach

#316
post #154

Earlier quoted context omitted.

Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…

Do you understand how image hashing works? You don't need machine learning just to check if two images are potentially identical.

yes, I've worked on face recognition databases with 150m and 40m faces for banking and safety.

The models are not perfect. Humans should still be in the loop to verify, especially when the consequences of being wrong really suck for the user: losing access to their bank account, getting fired from their job.

If you're referring to algorithms like phash (Where they are using the same core image, but just add a filter), they wont work well, because everyone's ID card mostly looks the same. There will be too many FPs.

Re: Discord says 70k users may have had their government IDs leaked in breach

#317
post #272

Earlier quoted context omitted.

Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.

It might give momentum to age-verification schemes like Apple Wallet [0]. Apple gets the state ID in wallet and exposes an age verification API to apps like Discord; Discord queries the API and relies on Apple's age verification without ever getting access to the personally-identifying information. [0] https://medium.com/@drewsmith_6943/apple-wallet-id-is-the-so...

Maybe not wallets but regular "sign in with X" SSO.

If all the X's can agree that one of the claims in the SSO is "is_adult", then at least you limit the exposure of your government ID to X getting breached, while all the "sign in with X" sites won't have access to the ID itself, just the claim.

Of course, pretty much every X gets breached anyway, and the walled garden shenanigans are not attractive, but it's better than ever site getting your ID.

Re: Discord says 70k users may have had their government IDs leaked in breach

#318

Earlier quoted context omitted.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their…

> "Is anyone surprised" is an important question to ask

It definitely is not, unless you are doing some sort of survey.

Re: Discord says 70k users may have had their government IDs leaked in breach

#320
post #272

Earlier quoted context omitted.

Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.

Might that be a business model for an enterprising Secretary of State? They carefully verify your real ID, the fake ID's trivially tie back to that if the cops ask (not so useful for committing crimes), there are upcharges for multiple fake ID's, or tweaked ages / weights / photos. More upcharges for "vanity" names... "Really, your honor, it's hardly different from an author getting a DBA or LLC for his pen name."

So many were issuing IDs for illegal immigrants. I was like, why can't I have one? I'd love to erase my past arbitrarily and be unidentifiable. I decided that it was for the same reason that I couldn't get a civil union for a heterosexual partnership; politics and control.

Don't we still have states and countries issuing new IDs for trans people that don't link to their old identities? Do I have to threaten to kill myself because people won't treat me like a pretty girl in order to get one; or should erasing your past, anonymity, or at least pseudoanonymity be a right that we all get?

> "Really, your honor, it's hardly different from an author getting a DBA or LLC for his pen name."

This is the worst, really. The only way to be truly anonymous is to open corporations, because corruption relies on laundering money through corporations.

Post reply on HN