A hack impacting Discord’s age verification process shows in stark terms the risk of tech companies collecting users’ ID documents. Now the hackers are posting peoples’ IDs and other sensitive information online.

From Discord’s age verification page, under “Privacy and Data Security”:

Q: Is my data stored when I use Face Scan or Scan ID verification?

A: Discord and k-ID do not permanently store personal identity documents or your video selfies. The image of your identity document and the ID face match selfie are deleted directly after your age group is confirmed, and the video selfie used for facial age estimation never leaves your device.

https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord

https://archive.is/FBqo5

So is that a lie?

scytale
link
fedilink
16
edit-2
10d

Technically no, but they leave out the tiny detail that the 3rd party vendor they use (who had the breach) stores the data.

marud
link
fedilink
1510d

A fucking lie from a shitty company

Should be sued to death.

Can’t because couple months ago they opted everybody into forced arbitration

(Fucking paywall article)

Summary

A catastrophic data breach at Discord’s third-party vendor Zendesk has exposed sensitive user information, including ID documents and selfies uploaded for age verification[1][2]. At least 70,000 people were impacted by the breach, with hackers leaking users’ driver’s licenses, approximate locations, real names, and emails[2:1].

The hackers are attempting to extort Discord and have already shared leaked selfies of users posing with their IDs in a Telegram group, along with a spreadsheet containing detailed information on a thousand users[2:2].

This breach validates critics’ concerns about tech companies collecting sensitive identity documents, particularly in light of recent age verification requirements in countries like the UK[2:3]. As one security expert notes in Gadgeteer, “a password is easy to change, but an ID document is often a nightmare to change, and the ID number anyway stays the same”[3].

Discord says it is working with affected users and authorities but won’t give in to the hackers’ demands[2:4].


  1. 404 Media - The Discord Hack is Every User’s Worst Nightmare ↩︎

  2. The Flagship Eclipse - Discord Suffers Major Hack Making Users’ Worst Nightmare Come True ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  3. Gadgeteer - The Discord Hack is Every User’s Worst Nightmare — Why Uploaded IDs are a Problem ↩︎

every user worst nightmare is joining discord with non-temp email, like a rube.

yeehaw
link
fedilink
41
edit-2
10d

"A catastrophic breach has impacted Discord user data including selfies and identity documents uploaded as part of the app’s verification process, email addresses, phone numbers, approximately where the user lives, and much more. "

Discord requires selfies now? Lol.

I tried again recently to make a fake Facebook account since nobody uses other places to buy and sell used shit. Logged in then they asked for a 360 degree video of my head.

Nope.

Who are the idiots that do this anyways?

Facebook wants a 360 of your head? Wtf??

Tenderizer78
link
fedilink
5
edit-2
9d

Shouldn’t your face be enough for Facebook?

How else are they going to train their AI to make stupid images of yourself?

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 113 users / day
  • 519 users / week
  • 1.44K users / month
  • 4.49K users / 6 months
  • 1 subscriber
  • 4.32K Posts
  • 109K Comments
  • Modlog