Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

341–350 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#341
post #4

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

in case of the EU it's more the opposite GDPR requires data minimalism and ~use case binding so if you submit data for age verification there is no technical reason to keep it after knowing your age so you _have to_ delete it.

I've come a long way down for somebody to have finally said this!

The GDPR is your friend. It makes retailing unnecessary personal data a liability. As it should be.

Discord is idiotic for operating in the UK and Europe without complying.

No excuses.

Re: Discord says 70k users may have had their government IDs leaked in breach

#343

Earlier quoted context omitted.

There’s no unbreakable secure tooling, none. It might be unbreakable against script-kiddies level of hacking, even though I have my doubts even about that, but Snowden and the general atmosphere during the last decade or so have proved that State actors can put their hands on almost any piece of data out there, either through genuine hacking or other means involving their monopoly on violence.

It’s absolutely possible to verify something anonymously. Here was an interesting example recently https://help.kagi.com/kagi/privacy/privacy-pass.html

You missed my part about State actors and their monopoly on violence. I think it used to be called the “hammer metaphor” or some such, a not very technical solution, if at all, but more than efficient nonetheless.

Re: Discord says 70k users may have had their government IDs leaked in breach

#344

Earlier quoted context omitted.

Anonymous means you can pay someone $2 to use theirs.

Surely that's solved easily by ensuring a 1:1 association between the proof of age and account?

Grandpa isn't interested in Discord, so you can open a second account using his Proof of Age. Maybe a third account, using Uncle Ned's. And a fourth account, using...

Re: Discord says 70k users may have had their government IDs leaked in breach

#345

The whole "it wasn't us, it was our third-party vendor" line is getting way too common. If you're collecting government IDs for age verification, the security bar should be extremely high... no matter who's handling the data

But our subcontractor made a contractual promise to use only sub-subcontractors who use only sub-sub-subcontractors who promise to be secure!

Ahh I see you've done work for the government.

Re: Discord says 70k users may have had their government IDs leaked in breach

#346

Earlier quoted context omitted.

> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now…

The companies in question could have a flag in every user data to confirm they are over the age limit. At worse keep the birth date, since various aspect of a service can be available depending on age (and user can change locality / country, and therefore be subject to different law). If you keep on top of it, you have at most 3 days of user's "ongoing verification" sensible data available for theft. Keeping more tha…

Let's say Discord is sued for letting children access the service without verification or whatever.

If they only store a boolean or a birthday then they can't show how they verified the data.

Re: Discord says 70k users may have had their government IDs leaked in breach

#347

Earlier quoted context omitted.

No, this is the result that companies dngaf about your private data. Sue them to oblivion.

Hard disagree. Companies could care about your data and still be subject to rbeach. ID verification is the source of the issue.

Everyone, please, don't fight.

It's both.

The companies wouldn't have this specific data if it wasn't for the age verification laws. Companies also work to amass as much private data as possible about their users without any influence from government and are often not good stewards of it.

Let's also not forget that companies like Discord often support and work with governments on these kind of laws because they prefer a consolidated regulatory structure and it has the added benefit of making life more difficult for smaller competitors that may enter the space.

Re: Discord says 70k users may have had their government IDs leaked in breach

#348
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"

Re: Discord says 70k users may have had their government IDs leaked in breach

#349
post #195

Earlier quoted context omitted.

Yeah, introducing real world friction is seemingly one of the only ways of actually solving the problems of frictionless digital systems (apart from computational disenfranchisement, of course). It might be a better idea to frame your idea in terms of online interactive proofs rather than offline bearer tokens. It's of course a lot less private/convenient to have to bring a phone or other cell-modem enabled device to…

My concern with some "bring your phone and use it immediately" scheme is that someone could pierce the privacy by looking at a correlation between the time an account was mode or a pattern of network-traffic occurred, versus the time someone was using/near the vending machine. Adding large and unpredictable amounts of latency makes that kind of correlation weaker and hopefully impractical.

That's what I meant by "high latency". Workflow would be something like go to sign up to a site, site issues a challenge which is stored in your browser, then sometime in the next week/month/year you stop by the vending machine which generates a proof for the challenge, then you can finish the signup flow for the site in the next week/month/year.

Of course, this would require people to exercise some restraint with regards to their timing.

But the real problem is that nobody actually wants these types of systems, so there is no organic demand. The motivation only comes as directives from governments, so it's not about the technically best system but rather whatever corporate lobbyists can manage to get mandated.

Re: Discord says 70k users may have had their government IDs leaked in breach

#350
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

I very much do blame the corporations and governments that push for these kinds of policies in some way or another. We see things like this, which happen about as often as fucking rainfall in a mountain forest, and then also see the ever increasing push towards ID verification by corporations and government organizations that pinkie-promise to secure or not retain any of the personal data you were wrist-burned into h…

>I very much do blame the corporations and governments that push for these kinds of policies in some way or another

71% want age verification

https://www.pewresearch.org/short-reads/2023/10/31/81-of-us-...

How that's done is the issue but you can't blame the government and corporations from making it happen.

Post reply on HN