• AmbitiousProcess (they/them)@piefed.social
    link
    fedilink
    English
    arrow-up
    100
    ·
    14 hours ago

    These were photos submitted via the compromised support provider (Zendesk) via the Discord support portal.

    Automated age verification via their partner (k-ID, which has its own issues) is a separate system, which was only available to some users. Other users had to contact Discord support manually and submit photo ID, which went through Zendesk, which was then compromised in this breach.

    https://support.discord.com/hc/en-us/articles/360041820932-Help-I-m-old-enough-to-use-Discord-in-my-country-but-I-got-locked-out

    Additionally, for the automated process, it’s the video selfie that’s on-device and never transmitted, but photos of your ID and selfie photo are transmitted, just supposedly deleted afterwards. Those ones are *not included in this breach, as far as we’re aware, as it’s an entirely different third-party with wholly separate infrastructure.

    • NuXCOM_90Percent@lemmy.zip
      link
      fedilink
      English
      arrow-up
      45
      ·
      14 hours ago

      Which is why you farm off stuff like this to third parties whenever possible

      DiscordCorp will get a slap on the wrist and give people an offer of a free six months of discord turbo (so long as you provide payment info so it can auto-renew on month seven).

      But ANY meaningful consequences will go toward Zendesk Corp for not doing what they were supposed to. And… then everyone will just use ZZendesk instead

      • Warl0k3@lemmy.world
        link
        fedilink
        English
        arrow-up
        19
        arrow-down
        1
        ·
        13 hours ago

        Well, yeah. Discord isn’t exactly at fault here, they’re operating as best they can within the boundaries of a piece of legislation that could be best described as gods gift to the “I-told-you-so” crowd. This breach is exactly what everyone was warning would happen with the UK ID laws, and discord got stung first as they’re one of the few companies trying to adhere to the law in good faith (which, yes, why in hell they’re trying to do this is good faith is a very good question)

        • Axolotl_cpp@lemmy.ml
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          edit-2
          8 hours ago

          Literally days ago i was accessing a nsfw channel and i got “well, you should send to us your ID and things so i can verificate you” and i thought “no way! I don’t want to give my infos, if they have a data breach we are all doomed” and i ignore, well i don’t want to say “i told you so” but…