Earlier quoted context omitted.
Do you understand how image hashing works? You don't need machine learning just to check if two images are potentially identical.
yes, I've worked on face recognition databases with 150m and 40m faces for banking and safety. The models are not perfect. Humans should still be in the loop to verify, especially when the consequences of being wrong really suck for the user: losing access to their bank account, getting fired from their job. If you're referring to algorithms like phash (Where they are using the same core image, but just add a filter)…
Discord says 70k users may have had their government IDs leaked in breach
431–440 of 447 posts
Re: Discord says 70k users may have had their government IDs leaked in breach
#432Earlier quoted context omitted.
I just... sent a scan of my passport. I mean, they promised to delete it right? Nothing could go wrong?
Oh, right, they will just believe whatever the "passport" says no matter what you declared earlier! That could come in handy
Re: Discord says 70k users may have had their government IDs leaked in breach
#433Earlier quoted context omitted.
Again, for sure and I agree with you - but we're talking about institutions that already have our IDs in some form or another, so just asking them to issue a certificate that says "yeah this user is actually over 18" seems like a no brainer functionality on top of an existing system. Like obviously our government office has a copy of my passport and ID card, but if those leak then we have a much bigger problem as a c…
> we're talking about institutions that already have our IDs in some form or another The issue isn’t who already has our IDs, it’s that EUDI introduces new auxiliary information (public keys, signatures, revocation identifiers) that create globally unique, linkable identifiers. Even if the same institutions issue the wallet, each transaction generates additional personal data that can be misused for tracking and prof…
But clearly this isn't the way the internet is going. As much as I hate it, it seems inevitable that globally every government is introducing at least a requirement for websites to check the age of their users.
So right now this can be done(here in the UK anyway) either by scanning your ID with a 3rd party provider who "promises" to delete it straight away, or by linking your bank account(yes, I'm definitely going to do that to go on pornhub, 100%). Both methods have the problems you mentioned + the additional risk of leaking my personal details because they are getting more info than they need to fulfil their legal obligations.
But if the government could just issue me an expiring cert that says "yep, this user is 18", without any of my other data on it.....then that's vastly preferable to having to scan my passport or driving licence to browse reddit or discord or whatever? Like yeah, maybe someone could still track it somehow(don't see how if every certificate has a unique ID and doesn't contain any identifiable info other than "yep this is a valid certificate and yes the user is over 18", but let's just say they can), but at least my IDs are not at risk of being leaked anywhere.
Re: Discord says 70k users may have had their government IDs leaked in breach
#434Earlier quoted context omitted.
This seems like a distinction without a difference. If you used a paid service offering Mumble servers that used some custom software that allowed them to offer multiple ... "servers" on different ports/IP addresses from a single daemon, would you really care? Focusing on the fact that it's not really a "server" because they aren't running as separate processes seems like utterly silly pedantry, and we probably don't…
A server, to me, you have control over if that's the product name of what you rent. Discord servers are as much yours as Hacker News is yours It's like pretending a taxi is the same as owning a vehicle, even if the taxi company was your neighbor and there's always someone available. The result is the same but the distinction couldn't be clearer. To me it's similarly misrepresentative to say you own a car when you liv…
Re: Discord says 70k users may have had their government IDs leaked in breach
#435Earlier quoted context omitted.
So you can only sign up for how many adult services per week before you get banned from signing up for any more? What if I'm checking out all the online casinos and each one wants an age token?
Again, the service host and request id is part of the certification request, so you can easily separate a legitimate signup for multiple different websites from suspicious multi-signups to the same service for the same govt id.
Re: Discord says 70k users may have had their government IDs leaked in breach
#436Earlier quoted context omitted.
Anonymous proofs of age don't work, because (in theory) I could set up a server, plugged into my ID chip, that lets anyone download age proofs from me, and then anyone can be over 18. They don't just need to know someone is over 18 - they also need to know it's the same person using the website.
Make it so that the proofs are not reusable.
Re: Discord says 70k users may have had their government IDs leaked in breach
#437Earlier quoted context omitted.
"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their…
> "Is anyone surprised" is an important question to ask It definitely is not, unless you are doing some sort of survey.
Of course blanket "not surprised" is perhaps not helpful without linkage to the people who denied the risks at steps a, b, c etc. But this is why we really need decision makes and politicians to be treated like anyone making a bet: we need to have collateral takes and enforcers. The "I am surprised" people who are silent would be forced to show they believe "it does not happen" by backing the bet and the "I'm not surprised" people would be raking it in.
With no bets, no collateral (or rather other people's lives), you just get this kind of lying in accounting and a scam. It happens in all kinds of domains with commons risk. This is a particularly good example because it is not so emotionally triggering and divisive (most people presumably don't want their data leaked and can't argue immediately that you are Xist or whatever).
Anyway, I love thinking about this stuff. Hopefully HN does not think these meta-discussions are spammy.
Re: Discord says 70k users may have had their government IDs leaked in breach
#438Earlier quoted context omitted.
Reminds me of the Panama Papers, which exposed a huge international money laundering/tax evasion ring that no one seemed to care about because "everyone knows they're doing this stuff"
I think it's a combination of "everyone knows they're doing this stuff" and "the ones who could do something about it (i.e. charge/prosecute, change laws, etc.) are implicated". Much like the problem in the US Congress: they are not subject to insider trading laws, so they can make huge sums of money acting on non-public information. The only people that can change that are ... members of the US Congress.
Re: Discord says 70k users may have had their government IDs leaked in breach
#439It will keep happening as well.
Their IDs given in the name of "online safety" how safe are they now their IDs are leaked?
Re: Discord says 70k users may have had their government IDs leaked in breach
#440Companies usually promise that the ID would be used only for validation and then immediately deleted. How so many IDs could leak then? They verify millions of IDs per month?
Either the deletion promise is a lie, or the third-party vendor was storing the data anyway