Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

441–447 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#441

Earlier quoted context omitted.

Which is kinda sad. Way back in the mid-2000s, I was playing World of Warcraft with a few people I had met in the game itself. Later on, we chipped in to rent a TeamSpeak server from a company that offered ready-made servers and we had a lot of fun. You didn’t even have to do much admin work. :(

You still don't have to do much these services still exist, even for Mumble. Their limitation is scaling. So if you want way more than just a handful of people, you either start charging everyone an entrance fee, or you cap the server.

Discord's limitation is scaling as well, to be honest. It's incredibly hard to follow a server full of tens of thousands of people. Just because something can scale in a technical sense doesn't mean it will scale in a human one.

Re: Discord says 70k users may have had their government IDs leaked in breach

#442
post #288

Earlier quoted context omitted.

My preference would be just requiring site operators to add the RTA header [1] for anything that could potentially be adult in nature or user contributed content and let parents decide if devices should have parental controls. Not perfect, nothing is but would protect most small children. Teens will easily bypass any method as many today watch porn together in rated-g/pg video games that allow setting up a streaming…

That would be also nice, but given we can't make everyone to do the most basic interoperability I don't see it working… As for: > Teens will easily bypass any method as many today watch porn well, they do, but each obstacle discourage them to do that. It's like with chocolate while being on a diet - if you have it within reach next to you you are more likely to eat it; put it on a shelf which would require standing a…

That would be also nice, but given we can't make everyone to do the most basic interoperability I don't see it working…

Many moons ago there were a couple browsers that looked for the ICRA PICS label but the adoption was low due to complexity of the header creation and a lack of laws requiring it. I expect it would take an intern an afternoon to create the code to look for the RTA header and probably a couple weeks to get through the QA/staging process. It only needs to initially get into Chrome, Safari, Edge and Firefox to protect small children on a tablet with kids using a normie account and parents retaining the super-user account. Should a law pass that has a timeline for the check to be mandatory I expect a majority of web agents to recognize and act on the RTA header long before the deadline.

It would be 100% more than what we have today is nothing in the browser and privacy invading third parties that would not be involved in kids going to sites that do not force people into said third party sites which is most of them. To be a fly on the wall when someone tries to force the third party ID checks on 4chan...

Re: Discord says 70k users may have had their government IDs leaked in breach

#443

Earlier quoted context omitted.

The distinction matters. The cost (to my users) of switching from one Mumble server to another is the same, regardless of who hosts the server. The cost of switching from one "Discord server" to another is much lower than the cost of switching between Discord and any Discord clone, keeping people on Discord.

That's not some inherent feature of it being a server or not, that's a feature of Discord offering much more features than Mumble.

No, it's a feature of Discord putting all the "Discord servers" into one program, but not allowing third-party servers to be listed in the same program. A rival system offering exactly the same featureset as Discord is nonetheless not interoperable with Discord, whereas a Mumble rival could easily be interoperable with Mumble clients.

Re: Discord says 70k users may have had their government IDs leaked in breach

#444

Earlier quoted context omitted.

You still don't have to do much these services still exist, even for Mumble. Their limitation is scaling. So if you want way more than just a handful of people, you either start charging everyone an entrance fee, or you cap the server.

Discord's limitation is scaling as well, to be honest. It's incredibly hard to follow a server full of tens of thousands of people. Just because something can scale in a technical sense doesn't mean it will scale in a human one.

I'm in such servers, people pick channels, and also slowmode is a key factor to stop people spamming too quickly.

VC is also drastically quieter on average, but can be fun too.

Re: Discord says 70k users may have had their government IDs leaked in breach

#445
post #105

.... The government ID's they only started asking for as a bullshit requirement after running for like 10 years without needing them? At some point we'll start seeing companies that rotate your passwords automatically and integrate with your autologins, and send immediate reports of breaches / suddenly failing logins. Wait. Why isn't this a thing

haveibeenpwned?

afaik they do not actually handle your logins

Re: Discord says 70k users may have had their government IDs leaked in breach

#446

Earlier quoted context omitted.

Make it so that the proofs are not reusable.

Why does that matter if I can keep generating new ones?

Because non-reusable proofs have a "linkability" property that lets you tell if they come from the same source.

Re: Discord says 70k users may have had their government IDs leaked in breach

#447

ID checks, driven by prudishness, are an absolute gift to the big social media companies. They're the only entities whom (a) already know the check's answers, and (b) have the resources to keep hackers largely at bay. I am not surprised these laws are landing with such little resistence.

Its as if the big social media companies lobbied for extra redtape, eh?

Large companies love regulation and red tape because it usually kills smaller competitors.
Post reply on HN