Live data from Hacker News

Discord says 70k users may have had their government IDs leaked in breach

theverge.com

91–100 of 447 posts

Re: Discord says 70k users may have had their government IDs leaked in breach

#91

Earlier quoted context omitted.

Discord doesn’t require a phone number. It’s individual community owners who opt to require it. You can create a server that doesn’t require one but it effectively means you can’t ban people since they can just sign up again on a new account.

I refuse to use their “create a server” language. It is not a server by any definition of the word server. You can set up a community on their servers. I’m not sure why they chose to use misleading language, but it is misleading.

I'm not sure it matters in this situation ...? Server/instance/VM/shard/... when used in this context is pure corporate naming BS. They'd have called it "setting up a new circle jerk" if they thought it would increase metrics

Re: Discord says 70k users may have had their government IDs leaked in breach

#92

Earlier quoted context omitted.

The issue is if you don't enforce the phone number requirement on your server you get all the trolls who don't use phone numbered accounts. I wish Discord would allow you to restrict known VPNs instead of requiring phone numbers. It would solve so many issues. I know a LOT of VPNs wont be caught, but if you block MOST non-residential IP blocks, you'll capture a lot of them.

Trolls likely have access to phone number farms though. And in some parts of the world it's extra cheap to mass-register phone numbers. Trolls wouldn't be harmed in a data leak, only normal users get hurt.

Most trolls aren't the kind of trolls that run large scale networks, they're the 12 year olds you triggered by saying BLM

Re: Discord says 70k users may have had their government IDs leaked in breach

#93

Earlier quoted context omitted.

Discord doesn’t require a phone number. It’s individual community owners who opt to require it. You can create a server that doesn’t require one but it effectively means you can’t ban people since they can just sign up again on a new account.

I refuse to use their “create a server” language. It is not a server by any definition of the word server. You can set up a community on their servers. I’m not sure why they chose to use misleading language, but it is misleading.

It’s wrong in terms of the technical implementation and right in terms of user experience.

Gamers are well familiar with different communities actually hosting servers and instances for games or voice chat pre discord. Discord offers the same experience but without physically being different servers. Keeping the name guides users in the same way OSs call it a recycling bin despite not actually being a bin.

Re: Discord says 70k users may have had their government IDs leaked in breach

#95

Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?

Why are people assuming they did store it after the process was completed?

With the relatively low number leaked here it could have been information collected actively during an ongoing breach, not a dump of some permanent database.

Re: Discord says 70k users may have had their government IDs leaked in breach

#96
post #48

Earlier quoted context omitted.

Just store the name and the fact that it was verified and delete the photo. You get what you need without holding on to a massive liability.

How does this help you identify duplicate accounts? If the original photo is deleted, do you just trust the model to be correct 100% of the time when it rejects the newly created account? Or do you keep the original photo and allow a human to make a final decision?

There are a million other signals for duplicate accounts anyway. Location, OS, device fingerprints, communities joined, etc. If those match and real name matches that’s enough data.

And if a few people manage to slip through it’s not really an issue. They will either get banned again for the same reasons or not violate the rules anymore so who cares

Re: Discord says 70k users may have had their government IDs leaked in breach

#97

Earlier quoted context omitted.

No need to blame the user for the companies actions. Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!). User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice…

> User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID. This is the part where the user has to take at least partial blame. You have to be utterly stupid (or at the very least way too sheltered) to believe a statement like this from a company, especially when ther…

In the UK we have the ICO (https://ico.org.uk/) who have the ability to fine companies who fail to live up to their data retention polices and/or fail to take adequate security measures to prevent or contain a serious personal data breaches.

If the UK Government are determined to enforce companies having to validate user ID's to use the company's services, then the government better well be determined to enforce our data protection laws too. Governments can not have it both ways (esp as the UK government also want to role out new digital IDs that will need to be checked when getting a new job), demanding users hand over ID to access services but not kick butts when those services fuck things up is just idiotic (Ok its the government, they make being idiots a profession), but that's not the fault of the user.

I'm mad at both Discord (for not securing their customers data inline with their published polices), and at the government (for forcing them into collecting the data in the first place, if Discord didn't have the data to begin with it can not be exposed).

But I can not be mad as users of a service, who though no fault of their own just wished to continue to be in communication with their friends and were faced with the no-win choice of providing ID or being denied access to a communication platform.

(just to be clear, I was not breached in this leak so I'm not being salty about the leak, but I see the point of view of the avg user because I see how the avg person uses the net every day.)

Re: Discord says 70k users may have had their government IDs leaked in breach

#98
post #9

I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'. Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system. T…

I blame companies (including discord) for collecting as much information as they can instead of as little as possible. More data collected -> more data that will eventually get sold / leaked / hacked.

Re: Discord says 70k users may have had their government IDs leaked in breach

#99

Earlier quoted context omitted.

No need to blame the user for the companies actions. Company enacts policy enforced on them by law, for example requiring proof that a user is above the age of 18 to be able to use a channel where other users may use naughty words (The Horror!!!). User struggles to use the automated age check system (I used the "guess age by letting an AI have a look at a selfie" method and it was a pain in the ass which failed twice…

> User, relying on the published policy that Discord will delete ID directly after being used to to the age check [1] decides they wish to remain to have communication with their online friends uploads their ID. This is the part where the user has to take at least partial blame. You have to be utterly stupid (or at the very least way too sheltered) to believe a statement like this from a company, especially when ther…

You don’t remember what it was like to just not think about this stuff too much because all our peers weren’t either.

How many of us freely and gleefully gave our info to Facebook, Google, etc all through the 2010’s? How many continue to?

Re: Discord says 70k users may have had their government IDs leaked in breach

#100
post #75

Earlier quoted context omitted.

Lying is usually legal. And even if lying is illegal in a particular context, it's de-facto legal since nobody ever gets punished for it.

fraud is not legal. There's a difference between lying on the playground and fraud in a business setting.

Again: fraud is de facto legal.

It is ubiquitous in every part of the business world, both internal and consumer-facing.

Post reply on HN