Gonzo.Markets
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
return2ozma@lemmy.world to Technology@lemmy.worldEnglish · 3 hours ago

The Discord Breach Might Be Worse Than We Thought, As The Hacker Is Said To Have Two Million Age Verification Photos

www.thegamer.com

external-link
message-square
29
link
fedilink
155
external-link

The Discord Breach Might Be Worse Than We Thought, As The Hacker Is Said To Have Two Million Age Verification Photos

www.thegamer.com

return2ozma@lemmy.world to Technology@lemmy.worldEnglish · 3 hours ago
message-square
29
link
fedilink
It's being claimed that whoever breached Discord now has access to 1.5TB of user data, with more than two million photos.
  • HexesofVexes@lemmy.world
    link
    fedilink
    English
    arrow-up
    75
    ·
    2 hours ago

    So, I looked at age verification - it was made clear photos were on device only and never transmitted.

    If this turns out to be false, then the legal fallout would be apocalyptic.

    • AmbitiousProcess (they/them)@piefed.social
      link
      fedilink
      English
      arrow-up
      35
      ·
      2 hours ago

      These were photos submitted via the compromised support provider (Zendesk) via the Discord support portal.

      Automated age verification via their partner (k-ID, which has its own issues) is a separate system, which was only available to some users. Other users had to contact Discord support manually and submit photo ID, which went through Zendesk, which was then compromised in this breach.

      https://support.discord.com/hc/en-us/articles/360041820932-Help-I-m-old-enough-to-use-Discord-in-my-country-but-I-got-locked-out

      Additionally, for the automated process, it’s the video selfie that’s on-device and never transmitted, but photos of your ID and selfie photo are transmitted, just supposedly deleted afterwards. Those ones are *not included in this breach, as far as we’re aware, as it’s an entirely different third-party with wholly separate infrastructure.

      • NuXCOM_90Percent@lemmy.zip
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 hours ago

        Which is why you farm off stuff like this to third parties whenever possible

        DiscordCorp will get a slap on the wrist and give people an offer of a free six months of discord turbo (so long as you provide payment info so it can auto-renew on month seven).

        But ANY meaningful consequences will go toward Zendesk Corp for not doing what they were supposed to. And… then everyone will just use ZZendesk instead

        • Warl0k3@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          28 minutes ago

          Well, yeah. Discord isn’t exactly at fault here, they’re operating as best they can within the boundaries of a piece of legislation that could be best described as gods gift to the “I-told-you-so” crowd. This breach is exactly what everyone was warning would happen with the UK ID laws, and discord got stung first as they’re one of the few companies trying to adhere to the law in good faith (which, yes, why in hell they’re trying to do this is good faith is a very good question)

    • Assassassin@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      2 hours ago

      Here’s the information directly from the FAQ as of right now:

      Q: Is my data stored when I use Face Scan or Scan ID verification?

      A: Discord and k-ID do not permanently store personal identity documents or your video selfies. The image of your identity document and the ID face match selfie are deleted directly after your age group is confirmed, and the video selfie used for facial age estimation never leaves your device.

      • LyD@lemmy.ca
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 hours ago

        That sounds like the video stays on your device but the photos do not.

      • oplkill@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        2
        ·
        2 hours ago

        Big company lies again what a big surprise

    • floofloof@lemmy.ca
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 hours ago

      Where is that small print? It should be archived before Discord tries to change it.

      • HexesofVexes@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        2 hours ago

        https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord

        Check down on data security ;)

        • LibertyLizard@slrpnk.net
          link
          fedilink
          English
          arrow-up
          13
          ·
          2 hours ago

          Looks like it’s already been archived: https://web.archive.org/web/20250930051220/https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord

          • floofloof@lemmy.ca
            link
            fedilink
            English
            arrow-up
            12
            ·
            2 hours ago

            It’s also here:

            https://archive.is/FBqo5

    • renegadespork@lemmy.jelliefrontier.net
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Idk it doesn’t seem like there are any legal consequences for tech companies anymore.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2.9K users / day
  • 8.07K users / week
  • 14.6K users / month
  • 17.6K users / 6 months
  • 1 local subscriber
  • 75.9K subscribers
  • 1.13K Posts
  • 26.5K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • UI: unknown version
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org