Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

361–370 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#361

Earlier quoted context omitted.

No, this is the result that companies dngaf about your private data. Sue them to oblivion.

Hard disagree. Companies could care about your data and still be subject to rbeach. ID verification is the source of the issue.

Anyone with a semblance of security awareness wouldn't store photo ids in net accessible storage

Re: Discord says 70k users may have had their government IDs leaked in breach

#362
The one approach that has never failed is to use a fake identity when signing up for online services. It is a violation of TOS but not a crime to do so. Only give your real information to the government. If companyX requires hard information but cannot protect this PII, then they don't deserve real data.

Re: Discord says 70k users may have had their government IDs leaked in breach

#363

Earlier quoted context omitted.

ZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.

You mean not collecting IDs is the real answer. Easy solution is the best solution and it already is mainstream. This is an example why that was a bad idea in the first place. No damage control for bad solutions will change that.

Mandated age checks (systemic deanonymization) is the gateway to social credit scores

Re: Discord says 70k users may have had their government IDs leaked in breach

#364
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

> I just completely dropped the expectation of my information being private

There are all the reasons in the world to feel that way. The scary thing (says troyvit as he passes out the tinfoil hats) is that privacy laws are all about an "expectation of privacy." In other words we all expect privacy when we're in our bathrooms, so government surveillance in the bathroom is hard to justify. Now that there are cameras in supermarket checkouts, and we all expect them, legally that's no longer a privacy concern and we can't claim that our privacy is being unreasonably infringed.

And what you're saying is that now we've reached the stage in history where through incompetence and greed we shouldn't expect any privacy anyway, and that opens the door for all kinds of surveillance because our expectations have fallen so low. I'm not a lawyer btw so take it all with a grain of salt.

Re: Discord says 70k users may have had their government IDs leaked in breach

#365

The one approach that has never failed is to use a fake identity when signing up for online services. It is a violation of TOS but not a crime to do so. Only give your real information to the government. If companyX requires hard information but cannot protect this PII, then they don't deserve real data.

The problem is that the government has these leaks too.

Re: Discord says 70k users may have had their government IDs leaked in breach

#366
post #351

Earlier quoted context omitted.

Calling "victim blaming" is not a retort. There is nothing wrong with dividing up blame among both people who offer a risky choice and people who make the risky decision to accept that choice, just because one of them suffered the downside of that risk. There are a lot of other examples where if you screw something up you might get hurt, and the victim is definitely at fault. It's a spectrum, as someone else put it.…

If Discord says they delete the PII they collect and they ultimately fail to do that, whether by malice or negligence Discord owns 100% of the blame. If I get drunk and drive the wrong way down the highway and cause a wreck, the blame is not shared because the victim was driving a vehicle which is known to be a risky activity. I am culpable, full stop.

I hope we agree that there's a spectrum, and sometimes the victim is the one at fault. We just have to disagree about this specific case. I'm OK with that. All the best.

Re: Discord says 70k users may have had their government IDs leaked in breach

#367

Earlier quoted context omitted.

It is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

To me it's an important point. We're all being worn down so much by these idiotic mistakes and intrusions that it's just another Thursday when it happens, like school shootings. I don't know what the great filter looks like on other planets, but here it's because we're smart enough to make all sorts of incredible toys and stupid enough to not know how to use them properly and we're just going to drive ourselves into the ground.

Re: Discord says 70k users may have had their government IDs leaked in breach

#368

Earlier quoted context omitted.

This is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.

"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their…

It should say "publish" because that's what happens after the fact, not what it's "doing" for an amount of time until it stops.

Re: Discord says 70k users may have had their government IDs leaked in breach

#369

Earlier quoted context omitted.

Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"

Hey now, that's not fair. Someone cared enough to murder the journalist that published them with a car bomb.

That allegedly would be Yorgen Fenech, via Alfred and George Degiorgio, Vincent Muscat, and as for the explosives, Robert Agius and Jamie Vella.

Re: Discord says 70k users may have had their government IDs leaked in breach

#370

The one approach that has never failed is to use a fake identity when signing up for online services. It is a violation of TOS but not a crime to do so. Only give your real information to the government. If companyX requires hard information but cannot protect this PII, then they don't deserve real data.

The problem is that the government has these leaks too.

sure, but your reducing the likelihood of your real data getting out there if it's only stored in one place, rather than hundreds.
Post reply on HN