Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

351–360 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#351
post #242

Earlier quoted context omitted.

Pure victim blaming.

Calling "victim blaming" is not a retort. There is nothing wrong with dividing up blame among both people who offer a risky choice and people who make the risky decision to accept that choice, just because one of them suffered the downside of that risk. There are a lot of other examples where if you screw something up you might get hurt, and the victim is definitely at fault. It's a spectrum, as someone else put it.…

If Discord says they delete the PII they collect and they ultimately fail to do that, whether by malice or negligence Discord owns 100% of the blame.

If I get drunk and drive the wrong way down the highway and cause a wreck, the blame is not shared because the victim was driving a vehicle which is known to be a risky activity. I am culpable, full stop.

Re: Discord says 70k users may have had their government IDs leaked in breach

#352

Earlier quoted context omitted.

I mean leaked from the EUDI side. > the EU implementation is better. It's better than the current implementation, sure, but you can never beat zero identifiers

Again, for sure and I agree with you - but we're talking about institutions that already have our IDs in some form or another, so just asking them to issue a certificate that says "yeah this user is actually over 18" seems like a no brainer functionality on top of an existing system. Like obviously our government office has a copy of my passport and ID card, but if those leak then we have a much bigger problem as a c…

> we're talking about institutions that already have our IDs in some form or another

The issue isn’t who already has our IDs, it’s that EUDI introduces new auxiliary information (public keys, signatures, revocation identifiers) that create globally unique, linkable identifiers.

Even if the same institutions issue the wallet, each transaction generates additional personal data that can be misused for tracking and profiling, far beyond the data already stored in government registries.

Re: Discord says 70k users may have had their government IDs leaked in breach

#354

Earlier quoted context omitted.

Maybe not wallets but regular "sign in with X" SSO. If all the X's can agree that one of the claims in the SSO is "is_adult", then at least you limit the exposure of your government ID to X getting breached, while all the "sign in with X" sites won't have access to the ID itself, just the claim. Of course, pretty much every X gets breached anyway, and the walled garden shenanigans are not attractive, but it's better…

This makes me hate the Twitter rebrand even more. I'm reading your use of "X" as generic name to be filled in as needed vs the poorly rebranded Musk owned platform. Then again, I could see that platform actually promoting its services to do this very thing.

Oof, I didn't even think about x/twitter... that was a poor choice of variable name! I shall try to eXcrete smarter in the future.

Re: Discord says 70k users may have had their government IDs leaked in breach

#355

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"

Hey now, that's not fair. Someone cared enough to murder the journalist that published them with a car bomb.

Re: Discord says 70k users may have had their government IDs leaked in breach

#356

And how will they pay for it? How did we get to this state anyway? Isn't HN supposed to be populated by the people who work at these companies, the fuck are you guys doing??

Whatever stereotypes you've read, about 0.01% of HNer's hold C-level jobs at huge tech companies, to be setting such policies.

And even at modest-sized companies, those are decided by Legal Dept's and senior business managers.

While you might find it cathartic, to angrily curse at some convenient Post Office employee for (say) the Postmaster General's latest postage stamp price increase - that is really not a classy move.

Re: Discord says 70k users may have had their government IDs leaked in breach

#357

Earlier quoted context omitted.

Maybe not wallets but regular "sign in with X" SSO. If all the X's can agree that one of the claims in the SSO is "is_adult", then at least you limit the exposure of your government ID to X getting breached, while all the "sign in with X" sites won't have access to the ID itself, just the claim. Of course, pretty much every X gets breached anyway, and the walled garden shenanigans are not attractive, but it's better…

This makes me hate the Twitter rebrand even more. I'm reading your use of "X" as generic name to be filled in as needed vs the poorly rebranded Musk owned platform. Then again, I could see that platform actually promoting its services to do this very thing.

it's time to bring back metasyntactic variables

https://en.wiktionary.org/wiki/foo

Re: Discord says 70k users may have had their government IDs leaked in breach

#358

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"

Well, in a few notorious cases the tax services cared and the voters cared.

Re: Discord says 70k users may have had their government IDs leaked in breach

#359

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"

I think it's a combination of "everyone knows they're doing this stuff" and "the ones who could do something about it (i.e. charge/prosecute, change laws, etc.) are implicated".

Much like the problem in the US Congress: they are not subject to insider trading laws, so they can make huge sums of money acting on non-public information. The only people that can change that are ... members of the US Congress.

Re: Discord says 70k users may have had their government IDs leaked in breach

#360

Earlier quoted context omitted.

Sure, but making use of that introduces new problems. Fundamentally it limits a person to one account/nym per site. This itself removes privacy. An individual should be able to have multiple Discord nyms, right? Then if someone gets their one-account-per-site taken/used by someone else, now administrative processes are required to undo/override that. Then furthermore it still doesn't prevent someone from selling acce…

>An individual should be able to have multiple Discord nyms, right? Yeah, I think so. I mean this is like my 20th hacker news account. I am using my 5th discord account right now. But at the same time it would be an interesting to see how anonymous yet sybil-proof social media would work out. I get the feeling that it's already pretty easy to buy and sell fake IDs, so I don't think it would pan out in practice. I als…

> interesting to see how anonymous yet sybil-proof social media would work out.

I agree it could be interesting but on the other hand we see plenty of people posting tripe under their public meatspace nym. The real problem with social media is the centralized sites optimizing for engagement, which includes boosting sockpuppets into view of the average user. So focusing on controlling users continues to ignore the puppetmaster elephants in the room.

I think talking about crypto details is a red herring on this topic though. User controlled computing devices mean that any two people can run software that behaves as a single client, using the credentials of the first person to give access to the second person. The only way to stop this is to make the first person have skin in the game, which is directly contrary to all of the privacy goals.

Chewing on this problem a bit more, it's starting to feel like this "use cryptography prove aspects of your identity without revealing your identity" is actually a bit of a longstanding nerd-snipe. It seems like a worthwhile problem because it copies what we do in meatspace for liquor/stripclubs/gambling/etc. But even the meatspace protocols are falling apart with a lot of places using ID scanners that query (ie log) a centralized database, rather than a mere employee who doesn't really care to remember you (and especially catalog your purchases). The straightforward answer to both is actually strong privacy laws that mandate companies cannot unnecessarily request or store data in the first place. Then some very simple digital protocols suffice to avoid this issue of identity being implied by knowing one mostly-public number.

(FWIW the problem of making change always seemed very simple to me - binary denominations of coins/tokens. I've always thought the statement of it as a problem has more to do with the speed of crypto ops during the period of early ecash research)

Post reply on HN