news.volyx.in

Discord says 70k users may have had their government IDs leaked in breach (theverge.com)

780 points by PaulKeeble · 290 days ago · 429 comments on HN

Article summary

Discord has announced that approximately 70,000 users may have had their government ID photos exposed due to a breach of a third-party customer service provider. The breach may have also impacted other information such as names, usernames, emails, and IP addresses. Discord claims that the attackers are circulating inaccurate information about the breach as part of an extortion attempt. The company has contacted all affected users and is working with law enforcement and security experts to investigate the incident.

Main themes

  • Data Breach
  • Government ID Security
  • Age Verification
  • Data Storage Liability
  • Extortion Attempt

What commenters say

  • Storing government ID photos after verification is unnecessary and creates a liability for the company.
  • Discord should not have stored the ID photos in the first place and should have only extracted relevant metadata.
  • The company's decision to store ID photos may be motivated by a desire to use the data for targeted advertising or training AI models.
  • The breach highlights the risks of requiring age verification through government ID scans, and alternative methods should be considered.
  • The low number of leaked IDs suggests that the breach may have been limited to information collected during an ongoing breach, rather than a dump of a permanent database.
  • Discord's handling of the breach and communication with affected users has been inadequate and overly focused on corporate PR spin.
  • The incident raises concerns about the security of sensitive personal information and the need for companies to prioritize data protection and transparency.