Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

321–330 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#321
post #65

Earlier quoted context omitted.

[dead]

A simple Google search turns up results from years ago that are still valid today: https://old.reddit.com/r/discordapp/comments/ircyh1/locked_o... > You'll be required to register a phone number to your Discord account in order to continue the use of it.

I didn't claim that it didn't happen to you, or that it never happens. You seemed to be implying that it will always happen, or commonly happen; my experience is proof that it doesn't always happen, and at least as strong evidence for it rarely happening as your experience is of it frequently happening.

Re: Discord says 70k users may have had their government IDs leaked in breach

#322
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> "this is a systemic issue of governments not having/not enforcing serious security measures"

Is it this, or is it a "systemic issue of governments not minding their own damn business"???

Re: Discord says 70k users may have had their government IDs leaked in breach

#323

Earlier quoted context omitted.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

It's a valid question, which speaks to the frequency with which these things happen. That's isn't trivialising the problem.

The person might not intend to be trivializing the problem, but that is the common outcome. This was very observable in the wake of the Snowden leaks, where "is anyone actually surprised?" was a key prong in the narrative that argued that you shouldn't actually care about what the NSA was getting up to.

Re: Discord says 70k users may have had their government IDs leaked in breach

#324
post #295

Every time I see a data breach caused by a third party vendor, I can't help but wonder why are these big companies so deeply reliant on outsourcing, yet so lax when it comes to controlling security?

Because the consequences of events like this are minimal so why would they waste time and effort worrying about it?

Re: Discord says 70k users may have had their government IDs leaked in breach

#326

Earlier quoted context omitted.

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

No, governments caused the issue by demanding customers to ID themselves, while failing to provide the necessary tooling for doing so in a secure manor. There's really only a few countries in the world who can provide the services needed to make this work. On top of my head, Estonia, Sweden and Denmark (there's probably others).

No, the problem is in the requirements already, not only in the implementation.

I don't want to ID myself if it isn't necessary. Proven security mechanism to minize data collection. It is a security risk, even with ZKP. It wouldn't even be hard to correlate the data, especially since governments also force ISPs to save connection info.

There is no need to a foul compromise here.

Re: Discord says 70k users may have had their government IDs leaked in breach

#327

Earlier quoted context omitted.

I won't use the eID because I don't believe in its promises. I don't need a third party, which would be completely dependent on government, to put a signature on my net access. I would even prefer the dubious service because of the relationship dynamics I mentioned. Best case is that age limits for the net should be enforced on device by parents. Problem solved, no unnecessary infrastructure needed.

Theoretically you could have anyone sign and attest to your age at any time. So maybe the government gives you an attestation of 0 at birth, with timestamp (allowing age to be calculated at any time), as part of the normal new-human bureaucracy. And/or maybe you can separately hire an accredited (co-signed?) lab to perform carbon dating on you later on :)

I totally would prefer the biopsy to a government Id. So carbon dating here I come.

Re: Discord says 70k users may have had their government IDs leaked in breach

#328

Earlier quoted context omitted.

I just looked up "Openfeint". It took me a while to find the connection to Discord. Not sure if I did because it seems like some mobile app for people who play mobile games with some connection to some Japanese network and hosted in China or something?

OpenFeint was founded by the same guy who founded Discord. From the Wikipedia page: "In 2011, OpenFeint was party to a class action suit with allegations including computer fraud, invasion of privacy, breach of contract, bad faith and seven other statutory violations. According to a news report "OpenFeint's business plan included accessing and disclosing personal information without authorization to mobile-device app…

I was entertaining an offer from Discord and also stumbled upon the founder’s former company debacle. The platform vision pitched to me in the interview seemed similar and seeing as how he started to implement spyware I decided to bail.
Post reply on HN