It wasn't Discord itself that got breached it was their service provider. The article does mention age verification data. So possibly k-ID which I've found on their support site as the provider for age verification. And what do they say about saving those?
Discord and k-ID do not permanently store personal identity documents or your video selfies. Images of your identity documents and ID match selfies are deleted directly after your age group is confirmed, and the video selfie used for facial age estimation never leaves your device.
No you lying politicians, you needed it for surveillance reasons and now you harmed everyone instead.. -.-"
Same for the chat control which keeps getting put on the table in Europe, there aint no thing like a backdoor "only for the good guys", bad actors will find and abuse it eventually.
Hit up your politicians, tell them to start actually caring for your best interests instead of speedrunning towards a surveillance state.
there aint no thing like a backdoor "only for the good guys"
And why are we even thinking of the oppressors as "the good guys" at this point? Draconian acts like these make them very, very bad actors. I'll even call them evil. Yeah, I've lost all faith in our digital future...
So uh, according to this article, and also Mutahar ( not sure what his source was )...
Yeah it was "apparently" ZenDesk that got compromised.
I... think that might actually be worse, as... ZenDesk is used a lot by a lot of B2B and client facing type shit.
Because that would mean ZenDesk are actually the people not deleting photo ids and other PII.
Yeah, Discord itself seems to be fine, in the sense of their own in house systems not being comprimised, but uh yeah, yeah, this is what happens when you leave things to trusted expert vendors who are in fact not experts and probably should not be trusted.
Yeah, this is why... the model of ... requiring your actual identification to do more and more on the net... is very bad.
You are basically just doxxing yourself with a randomly timed fuse, at this rate, everybody, every business gets hacked, all the time, its just normal now.
So anyway yeah, hope you didn't send a support ticket to Discord any time lately.
I wrote a top level comment with more details and a more recent, more fleshed out article as a source.
Basically, the only mistake Discord made ... appears to havr been trusting ZenDesk, it was apparently their systems that got breached, Discord hands support ticket management off to them as a contractor, and ZenDesk appear to be the people where this shit actually got lifted from, ZenDesk's Discord support silo.
Also, the group claiming credit is laspus....they have a number of pretty high profile breaches of corpo systems under their belt already.
10 Comments
ook@discuss.tchncs.de · 43 pts · 309d
Confining@lemmy.dbzer0.com · 41 pts · 309d
It’s almost like we told everyone long ago what was going to happen. But we are the paranoid ones.
bad_news@lemmy.billiam.net · 20 pts · 309d
RickyRigatoni@retrolemmy.com · 5 pts · 309d
Wain't that cassandra
bad_news@lemmy.billiam.net · 1 pts · 309d
cdzero@lemmy.ml · 11 pts · 309d
It wasn't Discord itself that got breached it was their service provider. The article does mention age verification data. So possibly k-ID which I've found on their support site as the provider for age verification. And what do they say about saving those?
Discord and k-ID do not permanently store personal identity documents or your video selfies. Images of your identity documents and ID match selfies are deleted directly after your age group is confirmed, and the video selfie used for facial age estimation never leaves your device.
Source: https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord
Rikj000@discuss.tchncs.de · 39 pts · 309d
"bUt wE nEEdeD iT tO pRoTeCt tHe cHiLdrEn"
No you lying politicians, you needed it for surveillance reasons and now you harmed everyone instead.. -.-"
Same for the chat control which keeps getting put on the table in Europe, there aint no thing like a backdoor "only for the good guys", bad actors will find and abuse it eventually.
Hit up your politicians, tell them to start actually caring for your best interests instead of speedrunning towards a surveillance state.
antipiratgruppen@lemmy.dbzer0.com · 4 pts · 307d
And why are we even thinking of the oppressors as "the good guys" at this point? Draconian acts like these make them very, very bad actors. I'll even call them evil. Yeah, I've lost all faith in our digital future...
goldkiddo@feddit.it · 14 pts · 309d
oh no, unexpected!
sp3ctr4l@lemmy.dbzer0.com · 12 pts · 309d
https://hackread.com/discord-data-breach-hackers-ids-billing-support-chats/
So uh, according to this article, and also Mutahar ( not sure what his source was )...
Yeah it was "apparently" ZenDesk that got compromised.
I... think that might actually be worse, as... ZenDesk is used a lot by a lot of B2B and client facing type shit.
Because that would mean ZenDesk are actually the people not deleting photo ids and other PII.
Yeah, Discord itself seems to be fine, in the sense of their own in house systems not being comprimised, but uh yeah, yeah, this is what happens when you leave things to trusted expert vendors who are in fact not experts and probably should not be trusted.
Yeah, this is why... the model of ... requiring your actual identification to do more and more on the net... is very bad.
You are basically just doxxing yourself with a randomly timed fuse, at this rate, everybody, every business gets hacked, all the time, its just normal now.
So anyway yeah, hope you didn't send a support ticket to Discord any time lately.
paequ2@lemmy.today · 6 pts · 309d
So if you've never interacted with support, you're maybe ok?
sp3ctr4l@lemmy.dbzer0.com · 1 pts · 309d
Probably, as it looks right now.
I wrote a top level comment with more details and a more recent, more fleshed out article as a source.
Basically, the only mistake Discord made ... appears to havr been trusting ZenDesk, it was apparently their systems that got breached, Discord hands support ticket management off to them as a contractor, and ZenDesk appear to be the people where this shit actually got lifted from, ZenDesk's Discord support silo.
Also, the group claiming credit is laspus....they have a number of pretty high profile breaches of corpo systems under their belt already.
altphoto@lemmy.today · 4 pts · 309d
Cornea scans? Ball print? Areola prints? Anal print?
Nah! Face! Sign in to discord with your face! Its totally safe and secure!