There’s a bigger question here, „Why were the images of ID cards being held for one second longer than was necessary to confirm age?“ secondly „Why were these images stored without being encrypted?“.
I know what the answer partially is. It’s because they decided to use a generic ticketing platform not designed for PII for their PII sensitive processes.
blogabegonija on
This is eventually the future humanity is not ready for.
Amen.
edparadox on
> Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted
Thank the UK for showing how stupid these laws are.
Goatmannequin on
So if I hoarded 2 million government IDs and then lost control of them as a private citizen, you know what would happen to me? Why aren’t these people in jail?
Haunting_Meal296 on
No one will be held responsible for this
Uhu0451 on
This is a good reminder not to blindly follow what the government suggests. It’s not safe at all.
lantz83 on
Why would anyone share their actual id with discord?
r3dm0nk on
Somewhere in that leak there’s a ticket with my discord nick
That ticket is me snitching on one person breaking discord TOS because they were annoying a-hole
I regret nothing
Fun-Needleworker-794 on
How many of those images will be used for ID fraud and AI models? Will the government care?
LitmusPitmus on
The fraud fallout of this is going to be bad. And the world has changed, banks are are on the hook for a lot more than they should be tbh. I would be furious at the government for this nonsense
ShowBoobsPls on
Can’t wait for the EU version of OSA to kick in…
I hope I can avoid most of the verification stuff with a VPN
SaraHHHBK on
I see protecting the kids is working out great.
Companies need to be made responsible and people put in jail.
TriggeredMemeLord on
*surprised pikachu face*
Diggalumbolo on
Company Leaders have to be accountable for every Action of their fucking Company!
New-Ranger-8960 on
The UK should be held responsible as well.
coccosoids on
No prob‘, chat control will solve it! /s
kagalibros on
This is what I have been warning everyone about and have advised against as a cyber security analyst and expert consultant but no, never listen to me because the consultant grifter crypto finance bro is always right…
I hope the EU squeezes them dry.
Odd_Adhesiveness8705 on
Dsgvo lawsuit incoming.
minobi on
UK Parliament members proved their IQ not that high
LibrarianOk8905 on
Whoever could have seen this coming!
T0ysWAr on
My take is that we need to work on an open standard for government ID that protects privacy.
This was well done for Covid app in UK
Trying to simplify it:
– you generate a private key in your phone’s Secure Enclave
– you register the public keep with the government in a government ID service
– the government ID service provide a derived public key service that merchants can reach to get a unique instance of a derived public key for your id
Merchant don’t need any personal info
You can auth to their service with your gov ID (no more passwords, local 2FA on your phone).
You have a different public key for each merchant (no tracking)
LibrarianOk8905 on
Protecting the children by doxing them.
corruptedpatata on
Is my child safe?
Butterbackfisch on
Make TeamSpeak 6 without the mandatory account and I will never use discord again.
smh_username_taken on
Even without evil intent, keeping data secure is hard work, and if they don’t have to do it, they won’t, in the interest of cost control. Beyond actual tech giants like google, meta, apple that both have huge budgets and actual oversight from EU, and maybe some heavily regulated financial companies, anything customer facing is cowboy territory, if discord can’t keep it safe, you can forget about everyone else who is smaller. Usually these platforms have no alternatives so you can’t even „choose the more secure alternative“
tortorototo on
Isn’t the case that by gdpr companies are required to minimise the storage personal information to only operationally necessary amounts?
Oh right, I guess US „regulations“ apply.
PuddingtonBear on
In today’s episode of „everyone who was opposed to discord having photo id to confirm age could see this coming from a mile away“
SjokoladeIsHare on
Why isn’t ID confirmation solved via a zero knowledge proof?
Cultural_Thing1712 on
Oh so you mean to tell me the „destroy privacy completely“ law completely destroyed privacy?
Who would’ve thought?????
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
29 Kommentare
There’s a bigger question here, „Why were the images of ID cards being held for one second longer than was necessary to confirm age?“ secondly „Why were these images stored without being encrypted?“.
I know what the answer partially is. It’s because they decided to use a generic ticketing platform not designed for PII for their PII sensitive processes.
This is eventually the future humanity is not ready for.
Amen.
> Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted
Thank the UK for showing how stupid these laws are.
So if I hoarded 2 million government IDs and then lost control of them as a private citizen, you know what would happen to me? Why aren’t these people in jail?
No one will be held responsible for this
This is a good reminder not to blindly follow what the government suggests. It’s not safe at all.
Why would anyone share their actual id with discord?
Somewhere in that leak there’s a ticket with my discord nick
That ticket is me snitching on one person breaking discord TOS because they were annoying a-hole
I regret nothing
How many of those images will be used for ID fraud and AI models? Will the government care?
The fraud fallout of this is going to be bad. And the world has changed, banks are are on the hook for a lot more than they should be tbh. I would be furious at the government for this nonsense
Can’t wait for the EU version of OSA to kick in…
I hope I can avoid most of the verification stuff with a VPN
I see protecting the kids is working out great.
Companies need to be made responsible and people put in jail.
*surprised pikachu face*
Company Leaders have to be accountable for every Action of their fucking Company!
The UK should be held responsible as well.
No prob‘, chat control will solve it! /s
This is what I have been warning everyone about and have advised against as a cyber security analyst and expert consultant but no, never listen to me because the consultant grifter crypto finance bro is always right…
I hope the EU squeezes them dry.
Dsgvo lawsuit incoming.
UK Parliament members proved their IQ not that high
Whoever could have seen this coming!
My take is that we need to work on an open standard for government ID that protects privacy.
This was well done for Covid app in UK
Trying to simplify it:
– you generate a private key in your phone’s Secure Enclave
– you register the public keep with the government in a government ID service
– the government ID service provide a derived public key service that merchants can reach to get a unique instance of a derived public key for your id
Merchant don’t need any personal info
You can auth to their service with your gov ID (no more passwords, local 2FA on your phone).
You have a different public key for each merchant (no tracking)
Protecting the children by doxing them.
Is my child safe?
Make TeamSpeak 6 without the mandatory account and I will never use discord again.
Even without evil intent, keeping data secure is hard work, and if they don’t have to do it, they won’t, in the interest of cost control. Beyond actual tech giants like google, meta, apple that both have huge budgets and actual oversight from EU, and maybe some heavily regulated financial companies, anything customer facing is cowboy territory, if discord can’t keep it safe, you can forget about everyone else who is smaller. Usually these platforms have no alternatives so you can’t even „choose the more secure alternative“
Isn’t the case that by gdpr companies are required to minimise the storage personal information to only operationally necessary amounts?
Oh right, I guess US „regulations“ apply.
In today’s episode of „everyone who was opposed to discord having photo id to confirm age could see this coming from a mile away“
Why isn’t ID confirmation solved via a zero knowledge proof?
Oh so you mean to tell me the „destroy privacy completely“ law completely destroyed privacy?
Who would’ve thought?????