9 ms·
I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for a
by tifik 1y ago
I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'.
Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system.
To make it clear - I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures. I just completely dropped the expectation of my information being private, and for the very few bits that I do actually want to stay private, I just don't, or allow anyone to, digitalize or reproduce them at all in any way.
- L-four 1y agoDeveloper time is more valuable than user data. The market is being efficient.
- hulitu 1y agoNo.Just greedy.
- kalaksi 1y agoI think you're assuming an ideal world where there's no information asymmetry, all the market participants receive and understand all the information and the risks, and clients could realistically move to an alternative platform that provably handles things better.
- baobabKoodaa 1y agoExternalized costs aren't weighed in that calculation
- Gigachad 1y agoIt’s surprising that it happened to a big name like Discord in this day and age. Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better.
- tacticus 1y agoi mean it's only every other week we see orgs like TCS handing out admin
- eviks 1y agoIt's getting better, but never reaching good, so still no surprise
- hulitu 1y ago> Huge data breaches of large tech companies are becoming increasingly rare as security in general is getting better. Citation needed. /s cough Microsoft cough
- Suzuran 1y agoPenetrations of this sort happen differently. If I want the ID of a bunch of Discord users, I don't go after Discord directly, I find some bot that the targeted users have on their discord servers, or third party service that Discord uses themselves. Then I find some individual person with access to those things, and I harass and/or threaten that person until they give me what I want to make me go away. If I think they might be crooked, I might just offer them a cut of the take. I'm probably not paying them though, not unless I think I can leverage them against other targets and need to keep them around. Either way, an individual person isn't going to be able to hold off a coordinated attack for very long, and law enforcement generally doesn't give a shit about internet randoms attacking individual people.
- codedokode 1y agoAlso this is an issue with people willing to send important documents to some company with which they do not even have a written agreement.
- fourside 1y agoA big problem is that the Silicon Valley playbook drives companies like Discord to be winner take all. It’s hard to avoid using them, but then they require that give up sensitive documents. I shouldn’t have to choose between keeping sensitive documents private and being able to participate in most gaming communities. Some open source projects have also starting adopting Discord to manage their communities.
- robinsonb5 1y ago> Some open source projects have also starting adopting Discord to manage their communities. And I've chosen not to engage with more than one such community because I'm not perpared even to give Discord my phone number, let alone any kind of ID document. Luckily there's nothing on Discord I care about that much, so I'm not having to make too difficult a choice. I totally get why most people won't take such a stand.
- 01HNNWZ0MV43FF 1y agoI'm not willing, I just don't have a choice. The US should regulate it from the top down like Europe does
- deleted 1y ago[deleted]
- SamDc73 1y agoNot sure what you mean by "like europe" because in Europe they are trying to implement `European Digital Identity (EUDI)` for age verification, which will make stuff like this even worse ....
- 1y ago
- bsimpson 1y agoFor years, I resisted TSA Pre check on principle, even though I was a frequent traveler. I finally relented when I realized there were places like Thailand that force you to give your biometrics, and almost certainly sell them back to shadowy US agencies.
- weird-eye-issue 1y agoThey might not be competent enough https://www.scmp.com/week-asia/politics/article/3300568/thailand-failed-collect-biometric-data-17-million-arrivals-due-limited-storage https://www.scmp.com/week-asia/politics/article/3300568/thai...
- safety1st 1y agoThailand has a big problem with identity theft, and another big problem with Chinese criminal syndicates committing various kinds of scams and fraud. So while they might share that biometric data with US government agencies, it seems more likely to me that at least one identity theft racket has acquired some of it.
- jonasdegendt 1y ago> places like Thailand that force you to give your biometrics You're being returned the favor! Anyone that's ever entered the US has had to do the same, and our prints are being stored in a DHS database. Out of curiosity, did you not need to provide prints to get a passport in the first place? I can't image a single developed country without biometric passports.
- Forgeties79 1y agoI told the 2 servers I hang in about a month ago that if I randomly disappear it’s because I can’t login without an ID and I’m simply not doing it/that they should consider the post my preemptive “goodbye.” I included where to contact me for those who want to. Frankly I think anyone on discord should do the same
- yibg 1y agoI blame companies (including discord) for collecting as much information as they can instead of as little as possible. More data collected -> more data that will eventually get sold / leaked / hacked.
- petre 1y agoDon't governments require them to chech people's IDs to make sure they aren't kids?
- throwaway473825 1y agoIt depends on the implementation. The EU's European Digital Identity Wallet will allow users to prove that they are over 18 without sharing any other personal information.
- immibis 1y agoAnonymous means you can pay someone $2 to use theirs.
- whatevertrevor 1y agoSurely that's solved easily by ensuring a 1:1 association between the proof of age and account?
- bell-cot 1y agoGrandpa isn't interested in Discord, so you can open a second account using his Proof of Age. Maybe a third account, using Uncle Ned's. And a fourth account, using...
- whatevertrevor 1y agoI think I'm fine with that tradeoff between effectiveness of age gating vs privacy gains of not having IDs sent over to corporations. To me, identity theft by targeting large stores of government IDs, is orders of magnitude worse than a teenager accessing NSFW channels every now and then. I'm not defending age verification's existence in the first place btw, I don't think it's a good idea without secure protocols of central attestation for such things. But of course, governments aren't interested in solving the harder more valuable problem, they're interested in shifting the responsibility to corporations while crying foul.
- SeanAnderson 1y agoZK proofs for identity can't go mainstream quick enough. I agree with what you're saying completely. It's frustrating that we have the technology now to verify aspects of someone's identity without revealing it, but that it's going to take forever to become robust enough for mainstream use.
- mindslight 1y agoThat does not work without treacherous locked-down hardware. The marketing by Google et al is leaving out that fact to privacy-wash what is ultimately a push for digital authoritarianism. Think about it - the claim is that those systems can prove aspects of someone's identity (eg age), without the site where the proof is used obtaining any knowledge about the individual and without the proof provider knowing where the proof is used. If all of these things are true while users are running software they can control, then it's trivial for an activist to set up a proxy that takes requests for proofs from other users and generates proofs based on the activist's identity - with no downside for the activist, since this can never be traced back to them. The only thing that could be done is for proof providers to limit the rate of proofs per identity so that multiple activists would be required to say provide access to Discord to all the kids who want it.
- Terr_ 1y agoIf I had my 'druthers, there would be a kind of physical vending machine installed at local city hall or whatever, which leverages physical controls and (dis-)economies of scale. The trusted machine would test your ID (or sometimes accept cash) and dispense single-use tokens to help prove stuff. For example, to prove (A) you are a Real Human, or (B) Real and Over Age X, or (C) you Donated $Y On Some Charity To Show Skin In The Game. That ATM-esque platform would be open-source and audited to try to limit what data the government could collect, using the same TPM that would make it secure in other ways. For example, perhaps it only exposes the sum total of times each ID was used at machine, but for the previous month only. The black-market in resold tokens would be impaired (not wholly prevented, that's impossible) by factors like: 1. The difficulty of scaling the physical portion of the work of acquiring the tokens. 2. Suspicion, if someone is using the machine dozens of times per month—who needs that many social-media signups or whatever? 3. There's no way to test if a token has already been used, except to spend it. By making reseller fraud easy, it makes the black-market harder, unless a seller also creates a durable (investigate-able) reputation. I suppose people could watch the vending-machine being used, but that adds another hard-to-scale physical requirement.
- cookiengineer 1y agoHonestly I don't understand why so many things are tied to one secret _that you have to share with others_ all the time. Why is there no rotation possible? Why is there no API to issue a new secret and mark the previous one as leaked? Why is there no way to have a temporary validation code for travels, which gets auto revoked once the citizens are back in their home country? It's like governments don't understand what identity actually means, and always confuse it with publicity of secrets. I mean, more modern digital passports now have a public and private key. But they put the private key on the card, which essentially is an absolute anti pattern and makes the key infrastructure just as pointless. If you as a government agency have a system in place that does not accommodate for the use case that passports are stolen all the time, you must be utterly out of touch with reality.
- gloosx 1y agoGovernments don't get a damn thing about the internet. They just want to govern, and justify the spending. Their goal is not to build resilient systems — it iss to preserve control. The internet was born decentralised, while governments operate through centralised hierarchies. Every system they design ends up reflecting that mindset: central authority, rigid bureaucracy, zero trust in the user. So instead of adopting key rotation, temporary credentials, or privacy-first mechanisms, they recreate 1950s paperwork in digital form and call it innovation.
- 0xbadcafebee 1y agoIt's not surprising because there's never been a significant penalty for it, I guess because everybody just got completely used to massive breaches without much reaction. But then again it's very hard to get legislation passed that's not in the interests of big business.
- baybal2 1y ago[dead]
- andsoitis 1y ago> this is a systemic issue of governments not having/not enforcing serious security measures. To do so seems impractical. Imagine the government machinery that would be required to audit all companies and organizations and services to which someone can upload PII. Not tractable.
- aydyn 1y agoThe enforcement could be done by incentives, making sure the penalty for such breaches is large.
- andsoitis 1y agoSure, but they would still happen is my point.
- austhrow743 1y agoThe systemic solution wouldn’t be to do that. It would be to both remove their own requirements that organisations collect this data, and to penalise organisations for collecting it outside of a handful of already heavily regulated industries like banking.
- stackbutterflow 1y agoAudit at random? With severe penalty in case of non compliance.
- nirui 1y ago> I basically treat it as 'any member of public can now access it'. Still remember the conversation over "mega apps"? Based on my experience with Alipay, which was a Chinese financial focused mega app but now more like a platform of everything plus money, the idea of treating every bit information you uploaded online as public info is laughable. Back when Alipay was really just a financial app, it make sense for it to collect private information, facial data, government issued ID etc. But now as a mega app, the "smaller app" running inside it can also request permission to read these private information if they wanted to, and since most users are idiots don't know how to read, they will just click whatever you want them to click (it really work like this, magic!). Alipay of course pretends to have protection in place, but we all know why it's there: just to make it legally look like it's the user's fault if something went wrong -- it's not even very delicate or complex. Kinda like what the idea "(you should) treat it (things uploaded online) as 'any member of public can now access'" tries to do, blame the user, punch down, easy done. But fundamentally, the information was provided and used in different context, user provided the information without knowing exactly how the information will be used in the future. It's a Bait-and-switch, just that simple. Of course, Discord isn't Alipay, but that's just because they're not a mega app, yet. A much healthier mentality is ask those companies to NOT to collect these data, or refuse to use their products. For example, I've not ever uploaded my government ID photos to Discord, if some feature requires it, I just don't use that feature.
- SequoiaHope 1y agoIt is a common misconception that facts are reported because they are surprising. Facts are reported because they are important. More and more governments are passing age verification laws which put exactly this data in to the hands of even more shady private companies. This breach serves as evidence that those laws are misguided, and spreading news of this event may help build public support for those efforts.
- boriskourt 1y agoThis is the essential point, and why it’s always a bit frustrating seeing ‘is anyone surprised’ take come up so often here. It lowers the quality of the possible discussion by trivialising it.
- franga2000 1y ago"Is anyone surprised" is an important question to ask, although in this case it would be more valuable to ask on a less techy forum. I'm not surprised and many people here are not surprised, but most people are still surprised when they hear something like this, which is why they gladly give their information to anyone that asks. If the majority of Discord users knew breaches are inevitable and refused to give their information or at least took some protective measures like partial redaction and use-case watermarking, this breach would be less of an issue and/or such breaches would be less common. We need to make sure nobody is surprised. Everyone should rewrite every "upload" button in their head to say "publish".
- pessimizer 1y ago> "Is anyone surprised" is an important question to ask It definitely is not, unless you are doing some sort of survey.
- nobodywillobsrv 1y agoIt does feel like it hide the important context often summarized as a meme: a) it doesn't happen b) ok it happens, but it's rare c) ok it's not rare but the impact is minimal d) ok it's not rare and the impact is not minimal but here's why it is necessary and a good thing Of course blanket "not surprised" is perhaps not helpful without linkage to the people who denied the risks at steps a, b, c etc. But this is why we really need decision makes and politicians to be treated like anyone making a bet: we need to have collateral takes and enforcers. The "I am surprised" people who are silent would be forced to show they believe "it does not happen" by backing the bet and the "I'm not surprised" people would be raking it in. With no bets, no collateral (or rather other people's lives), you just get this kind of lying in accounting and a scam. It happens in all kinds of domains with commons risk. This is a particularly good example because it is not so emotionally triggering and divisive (most people presumably don't want their data leaked and can't argue immediately that you are Xist or whatever). Anyway, I love thinking about this stuff. Hopefully HN does not think these meta-discussions are spammy.
- southernplaces7 1y agoI very much do blame the corporations and governments that push for these kinds of policies in some way or another. We see things like this, which happen about as often as fucking rainfall in a mountain forest, and then also see the ever increasing push towards ID verification by corporations and government organizations that pinkie-promise to secure or not retain any of the personal data you were wrist-burned into handing over to them. What a toxic mix of garbage that becomes. The result is crap like the above, making the internet ever worse and basic personal data security (to not even speak of lofty things like digital privacy and using the internet anonymously) pretty much null and void even if you really do try to take the right steps.
- eleveriven 1y agoIt's really just creating massive honeypots of sensitive data that will eventually leak. And when it does, the consequences are always on us
- Braxton1980 1y ago>I very much do blame the corporations and governments that push for these kinds of policies in some way or another 71% want age verification https://www.pewresearch.org/short-reads/2023/10/31/81-of-us-adults-versus-46-of-teens-favor-parental-consent-for-minors-to-use-social-media/ https://www.pewresearch.org/short-reads/2023/10/31/81-of-us-... How that's done is the issue but you can't blame the government and corporations from making it happen.
- eleveriven 1y agoWhat's wild is that the burden keeps falling on individuals to be ultra-cautious, while the systems handling the data rarely face meaningful consequences
- raxxorraxor 1y ago> I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures Wrong, governments caused the issue because they demand customers to ID themselves. There exists not a single viable security measure aside from not collecting the data. Government is also not able to propose any security measures. Unlikely that the data will ever be deleted now, no matter if Discord pays any ransoms or not.
- mrweasel 1y agoNo, governments caused the issue by demanding customers to ID themselves, while failing to provide the necessary tooling for doing so in a secure manor. There's really only a few countries in the world who can provide the services needed to make this work. On top of my head, Estonia, Sweden and Denmark (there's probably others).
- paganel 1y agoThere’s no unbreakable secure tooling, none. It might be unbreakable against script-kiddies level of hacking, even though I have my doubts even about that, but Snowden and the general atmosphere during the last decade or so have proved that State actors can put their hands on almost any piece of data out there, either through genuine hacking or other means involving their monopoly on violence.
- TingPing 1y agoIt’s absolutely possible to verify something anonymously. Here was an interesting example recently https://help.kagi.com/kagi/privacy/privacy-pass.html https://help.kagi.com/kagi/privacy/privacy-pass.html
- paganel 1y agoYou missed my part about State actors and their monopoly on violence. I think it used to be called the “hammer metaphor” or some such, a not very technical solution, if at all, but more than efficient nonetheless.
- rwky 1y agoSame. I automatically assume that all information I send to any organisation will end up on the Internet sooner or later be it by accident or sold to some shady third party.
- stackbutterflow 1y agoFor us it's too late. But we must push for better laws and build better systems for those that come after us.
- paganel 1y agoIf “serious security measures” involves anything to that 2fa authentication that any normal person hates with a passion then you can forget about it. The real, long term answer to all this consists in having less of our lives in digital presence, that even means less digital government thingies and, yes, less payments and other money-related issues being handled online.
- somenameforme 1y ago> "or there will, sooner or later, be a breach of their poorly secured system." It doesn't even need to be poorly secured. The oldest form of hacking is social engineering. If a company is storing valuable enough information, all one needs to do is compel the lowest common denominator with access to it to intentionally or inadvertently provide access. You can try to create all the sort loopholes and redundancies but in general the reality is that no system is ever going to be truly secure. Another reality is that many of the people with the greatest level of access will not be technical by nature. For instance apparently the DNC hacks were carried out by a textbook phishing email - 'You've like totally been hacked, click on this anonymizer link to leads to Goog1e.com so we can confirm your identity.'
- AlienRobot 1y agoI don't think you have become jaded. It's just the truth of the internet. If you upload anything to the internet, it's public. Even the passwords you type are potentially public.
- johndhi 1y agoYou really think governments could write rules that would help this? The only rule I can imagine is big penalties for data being breached, no matter the cause, but do we actually think it's a multi million dollar problem for 70k photos to be released? Hard problem.
- NoSalt 1y ago> "this is a systemic issue of governments not having/not enforcing serious security measures" Is it this, or is it a "systemic issue of governments not minding their own damn business"???
- troyvit 1y ago> I just completely dropped the expectation of my information being private There are all the reasons in the world to feel that way. The scary thing (says troyvit as he passes out the tinfoil hats) is that privacy laws are all about an "expectation of privacy." In other words we all expect privacy when we're in our bathrooms, so government surveillance in the bathroom is hard to justify. Now that there are cameras in supermarket checkouts, and we all expect them, legally that's no longer a privacy concern and we can't claim that our privacy is being unreasonably infringed. And what you're saying is that now we've reached the stage in history where through incompetence and greed we shouldn't expect any privacy anyway, and that opens the door for all kinds of surveillance because our expectations have fallen so low. I'm not a lawyer btw so take it all with a grain of salt.
- HeavyStorm 1y agoCouldn't agree more, save for your last sentence. How do you avoid that? We need to provide o Digital papers to a number of different people for proper handling
- abustamam 1y agoThere's a surprising amount of people pro-age verification in this thread https://news.ycombinator.com/item?id=45424888 https://news.ycombinator.com/item?id=45424888 (I don't really want to call out specific comments) So I'm sure this article may be surprising to them.