Discord says 70k users may have had their government IDs leaked in breach
311–320 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#312Pieces of shit. Do they need to look at them on a daily basis or isn't is enough to use them to confirm identity when received and then encrypt them and move them to an offline storage?
It is going to take a long time before companies realize that data they don't need is a liability, not an asset.
Re: Discord says 70k users may have had their government IDs leaked in breach
#313Earlier quoted context omitted.
Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…
0.01% of 65M is 6,500. Also apparently only 70K people uploaded their IDs. That being said, you can still hash faces and metadata (such as ID numbers) instead of storing the whole ID as a scanned photo, if the information is only used for duplicate checking. Hashing does not increase the racial bias. If your model has a bias it will always have a margin of error.
Re: Discord says 70k users may have had their government IDs leaked in breach
#314Earlier quoted context omitted.
This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.
It's a valid question, which speaks to the frequency with which these things happen. That's isn't trivialising the problem.
Re: Discord says 70k users may have had their government IDs leaked in breach
#315ID checks, driven by prudishness, are an absolute gift to the big social media companies. They're the only entities whom (a) already know the check's answers, and (b) have the resources to keep hackers largely at bay. I am not surprised these laws are landing with such little resistence.
Its as if the big social media companies lobbied for extra redtape, eh?
Re: Discord says 70k users may have had their government IDs leaked in breach
#316Earlier quoted context omitted.
Can you elaborate more? Discord has 656m users. if 10% upload their ID, they'd have 65m ID photos to search through. There are 2 use-cases here: 1/ Safety Bans (lets pretend 0.01% of ID card users have been banned for safety reasons: 650k accounts) If a user submits their selfie/ID card, Discord needs to compare the new image with one of the 650k banned (but deleted?) images. I can't possible think how a human could…
Do you understand how image hashing works? You don't need machine learning just to check if two images are potentially identical.
The models are not perfect. Humans should still be in the loop to verify, especially when the consequences of being wrong really suck for the user: losing access to their bank account, getting fired from their job.
If you're referring to algorithms like phash (Where they are using the same core image, but just add a filter), they wont work well, because everyone's ID card mostly looks the same. There will be too many FPs.
Re: Discord says 70k users may have had their government IDs leaked in breach
#317Earlier quoted context omitted.
Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.
It might give momentum to age-verification schemes like Apple Wallet [0]. Apple gets the state ID in wallet and exposes an age verification API to apps like Discord; Discord queries the API and relies on Apple's age verification without ever getting access to the personally-identifying information. [0] https://medium.com/@drewsmith_6943/apple-wallet-id-is-the-so...
If all the X's can agree that one of the claims in the SSO is "is_adult", then at least you limit the exposure of your government ID to X getting breached, while all the "sign in with X" sites won't have access to the ID itself, just the claim.
Of course, pretty much every X gets breached anyway, and the walled garden shenanigans are not attractive, but it's better than ever site getting your ID.
Re: Discord says 70k users may have had their government IDs leaked in breach
#318Earlier quoted context omitted.
This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.
"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their…
It definitely is not, unless you are doing some sort of survey.
Re: Discord says 70k users may have had their government IDs leaked in breach
#319Re: Discord says 70k users may have had their government IDs leaked in breach
#320Earlier quoted context omitted.
Wonder if this will cause a surge in demand for fake IDs that are sufficient for age-verification but harmless if leaked.
Might that be a business model for an enterprising Secretary of State? They carefully verify your real ID, the fake ID's trivially tie back to that if the cops ask (not so useful for committing crimes), there are upcharges for multiple fake ID's, or tweaked ages / weights / photos. More upcharges for "vanity" names... "Really, your honor, it's hardly different from an author getting a DBA or LLC for his pen name."
Don't we still have states and countries issuing new IDs for trans people that don't link to their old identities? Do I have to threaten to kill myself because people won't treat me like a pretty girl in order to get one; or should erasing your past, anonymity, or at least pseudoanonymity be a right that we all get?
> "Really, your honor, it's hardly different from an author getting a DBA or LLC for his pen name."
This is the worst, really. The only way to be truly anonymous is to open corporations, because corruption relies on laundering money through corporations.