The Discord Breach Might Be Worse Than We Thought, As The Hacker Is Said To Have Two Million Age Verification Photos
https://www.thegamer.com/discord-data-breach-2-million-photos-1-5tb-age-verification-zendesk/
https://www.thegamer.com/discord-data-breach-2-million-photos-1-5tb-age-verification-zendesk/
124 Comments
Darkcoffee@sh.itjust.works · 312 pts · 304d
Anyone still defending age verification online is an idiot.
CosmoNova@lemmy.world · 82 pts · 304d
I don‘t think I‘ve ever seen someone defend it online but there were a few people laughing it off which is not much better.
explodicle@sh.itjust.works · 4 pts · 303d
To be fair, they were before this incident too.
HexesofVexes@lemmy.world · 218 pts · 304d
So, I looked at age verification - it was made clear photos were on device only and never transmitted.
If this turns out to be false, then the legal fallout would be apocalyptic.
(Edit: or not, see the comment by ambitiousprocess below)
AmbitiousProcess@piefed.social · 125 pts · 304d
These were photos submitted via the compromised support provider (Zendesk) via the Discord support portal.
Automated age verification via their partner (k-ID, which has its own issues) is a separate system, which was only available to some users. Other users had to contact Discord support manually and submit photo ID, which went through Zendesk, which was then compromised in this breach.
https://support.discord.com/hc/en-us/articles/360041820932-Help-I-m-old-enough-to-use-Discord-in-my-country-but-I-got-locked-out
Additionally, for the automated process, it's the video selfie that's on-device and never transmitted, but photos of your ID and selfie photo are transmitted, just supposedly deleted afterwards. Those ones are *not included in this breach, as far as we're aware, as it's an entirely different third-party with wholly separate infrastructure.
NuXCOM_90Percent@lemmy.zip · 57 pts · 304d
Which is why you farm off stuff like this to third parties whenever possible
DiscordCorp will get a slap on the wrist and give people an offer of a free six months of discord turbo (so long as you provide payment info so it can auto-renew on month seven).
But ANY meaningful consequences will go toward Zendesk Corp for not doing what they were supposed to. And... then everyone will just use ZZendesk instead
Warl0k3@lemmy.world · 26 pts · 304d
Well, yeah. Discord isn't exactly at fault here, they're operating as best they can within the boundaries of a piece of legislation that could be best described as gods gift to the "I-told-you-so" crowd. This breach is exactly what everyone was warning would happen with the UK ID laws, and discord got stung first as they're one of the few companies trying to adhere to the law in good faith (which, yes, why in hell they're trying to do this is good faith is a very good question)
Axolotl_cpp@lemmy.ml · 9 pts · 304d
Literally days ago i was accessing a nsfw channel and i got "well, you should send to us your ID and things so i can verificate you" and i thought "no way! I don't want to give my infos, if they have a data breach we are all doomed" and i ignore, well i don't want to say "i told you so" but...
AmbitiousProcess@piefed.social · 2 pts · 303d
In my opinion, they're still somewhat at fault, because this was them failing to find and configure their software to work with a third-party identity provider who's infrastructure was built to handle the security of sensitive information, and just choosing to use email through Zendesk because it was easier in the meantime. A platform that I should note has been routinely accessed again and again by attackers, not just for Discord, but for all sorts of other companies.
The main problem is that legislation like the Online Safety Act require some privacy protections, like not collecting or storing certain data unless necessary, but they don't require any particular security measures to be in place. This means that, theoretically, nothing stops a company from passing your ID to their servers in cleartext, for example.
Now compare this to industries like the credit card industry, where they created PCI DSS, which mandates specific security practices. This is why you don't often see breaches of any card networks or issuers themselves, and why most fraud is external to the systems that actually process payments through these cards. (e.g. phishing attacks that get your card info, or a store that has your card info already getting hacked)
This is a HUGE oversight, and one that will lead to things like this happening over and over unless it becomes unprofitable for companies to not care.
Warl0k3@lemmy.world · 3 pts · 303d
While there's plenty of merit to what you're saying, I'm too sick to have a coherent thought beyond maybe pointing out that the main issue with legislation like this isn't that it doesn't specify security requirements, but that it's forcing people who do not have infrastructure established to collect and manage sensitive info of this nature in the first place.
Discord never set out to collect this much PII, and as far as I'm aware there's never been a breach of their payment information processing. Like you say, it's an established thing to handle payments and is fairly routine to implement. There is no routine method of handling ID verification yet, and the solutions that exist were forced to be developed rapidly and with no standards.
The legislation is at fault for putting people in this situation - that they used Zendesk was a boneheaded move (I haven't seen details of the breach, was that really the vector that got attacked?) and sure, they're at some degree of fault for letting this happen. But the vast majority of the blame lies at the feet of the asinine legislation that all but explicitly mandated that this situation arise.
AmbitiousProcess@piefed.social · 2 pts · 303d
Oh, of course the legislation is to blame for a lot of this in the end. I'm just saying that Discord could have already partnered with a number of identity verification services that do already have this infrastructure up and running, with standardized and documented ways to call their APIs to both verify and check the verification of a user.
At the end of the day, Discord chose to implement a convoluted process of having users email Discord, upload IDs, then have Discord pull the IDs back down from Zendesk and verify them, rather than implementing a system where users could have simply gone to a third-party verification website, done all the steps there, had their data processed much more securely, then have the site just send Discord a message saying "they're cool, let 'em in"
HexesofVexes@lemmy.world · 2 pts · 303d
Neat summary and cleanup - editing original post to point at this.
lemmyout@lemmy.zip · 31 pts · 304d
What legal fallout? Discord made users agree to new terms just a week ago that involves forced arbitration.
Azzu@lemmy.dbzer0.com · 17 pts · 303d
Forced arbitration clauses are not legal in many European jurisdictions, so "agreeing" to them didn't actually do anything.
amju_wolf@pawb.social · 5 pts · 303d
Are they legal in any EU jurisdictions? I'd hope not.
Not to mention half of their TOS being illegal/unenforceable in the first place.
Azzu@lemmy.dbzer0.com · 2 pts · 303d
Dunno, just didn't want to make a statement I'm not sure of.
ms_lane@lemmy.world · 4 pts · 303d
Sounds like Discord is about to have 2 million cases of arbitration to sort out.
One person takes them to arbitration, it's short work for their legal team, if 1000 do it's harder, if 100,000 do, you still have to respond in a timely manner. The costs would be astronomical.
Valve and a few others removed it for that reason, it's a bomb waiting to blow.
Holytimes@sh.itjust.works · 3 pts · 303d
Forced arbitration tends to backfire massively when you have something of this scale because of everyone starts doing it. The cost of that forced arbitration is more than what the lawsuits would have been without it. It's a big reason why like steam got rid of it. If you get too many people trying to go after you, it's just not worth it and costs too much.
socialsecurity@piefed.social · 1 pts · 303d
And US courts allow companies to reverse force abortion if it no longer suits the company!
REDACTED@infosec.pub · 1 pts · 304d
I'm not sure if Discord's ToS apply to zendesk
Assassassin@lemmy.dbzer0.com · 23 pts · 304d
Here's the information directly from the FAQ as of right now:
LyD@lemmy.ca · 11 pts · 304d
That sounds like the video stays on your device but the photos do not.
oplkill@lemmy.world · 7 pts · 304d
Ganbat@lemmy.dbzer0.com · 2 pts · 304d
Yeah, but those methods of verification weren't the subject of this breach, this was some manual bullshit done through Zendesk.
floofloof@lemmy.ca · 15 pts · 304d
Where is that small print? It should be archived before Discord tries to change it.
HexesofVexes@lemmy.world · 20 pts · 304d
https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord
Check down on data security ;)
LibertyLizard@slrpnk.net · 16 pts · 304d
Looks like it’s already been archived: https://web.archive.org/web/20250930051220/https://support.discord.com/hc/en-us/articles/30326565624343-How-to-Complete-Age-Verification-on-Discord
floofloof@lemmy.ca · 15 pts · 304d
It's also here:
https://archive.is/FBqo5
renegadespork@lemmy.jelliefrontier.net · 11 pts · 304d
Idk it doesn't seem like there are any legal consequences for tech companies anymore.
ipkpjersi@lemmy.ml · 4 pts · 304d
Definitely not, laws are only for the poors.
mr_pip@discuss.tchncs.de · 1 pts · 303d
you agree to legal mediation other than a court in their terms of service, so... not really
explodicle@sh.itjust.works · 2 pts · 303d
Those don't always hold up, especially when the shit is really hitting the fan.
mr_pip@discuss.tchncs.de · 1 pts · 303d
"dont always... when it hits the fan" is a little too elusive compared to a legal document you agreed to online imho so i will not necessarily hold to that
explodicle@sh.itjust.works · 1 pts · 303d
Yep that's a lot of stuff, it's a money spending contest.
plz1@lemmy.world · 124 pts · 304d
The fact that these photos and PII (personally identifiable information) were not destroyed after the verification process was certified is absolutely atrocious OpSec. I don't even care which of the two companies is ultimately responsible, because they are both responsible.
I work in IT, and treat PII like it's dangerously radioactive, because in the digital world, it really is.
TomArrr@lemmy.world · 15 pts · 304d
"Apparently" only those who were challenging the verification results and uploaded awaiting reverification are affected.
Not that that isn't bad enough
Kissaki@feddit.org · 12 pts · 304d
That's even worse, in my eyes. Maybe not in scale, but when appeal process is more vulnerable, that seems very questionable.
TomArrr@lemmy.world · 1 pts · 302d
Yea, pretty sure most of the evidence is no longer ther
prole@lemmy.blahaj.zone · 10 pts · 303d
That's because you have ethics
luciferofastora@feddit.org · 6 pts · 304d
Me when I get a request for PII pertaining to a suspected corruption case: Have one of our corporate lawyers give me a written and explicit statement of what data I'm supposed to send to whom or get bent. I'm not touching that with a ten foot pole and gloves unless I have a legally solid affirmation that what I'm doing won't come back to bite me, and that our workers' council knows about it and will back me up.
I'm reluctant to even confirm that I can get that information in the first place. I mean, I'm the one with full access to the audit tool, so I probably do, but I'd have to access that data in the first place to check. I don't think that anyone would notice or care so long as I don't share that information, but as you said: dangerously radioactive; don't touch if I can help it.
Zen_Shinobi@lemmy.world · 5 pts · 304d
Right. It blows me away the required training we have to do for physical files more secured than Fort Knox! Tech world? Eh just throw it in the recycle bin
aidan@lemmy.world · 1 pts · 303d
I agree completely its moronic, but I do imagine the law requires it
kylian0087@lemmy.dbzer0.com · 54 pts · 303d
Proofs the UK is a shithole as well funnily enough.
Nothing against the Brits but their government oh damn that's bad.
Blackmist@feddit.uk · 14 pts · 303d
Wait til you see the next one.
:(
Fraction9170@infosec.pub · 13 pts · 303d
Yep. This is just the first. As long as individuals submit to these ID verifications, services which provide them will be highly targeted. I find it ridiculous that 1.5 million people actually submitted their info to access discord instead of finding a workaround or alternative. I can only imagine how many are gullible enough to verify on porn sites.
KelvarCherry@lemmy.blahaj.zone · 2 pts · 303d
Well before the UK online ID laws, I saw some memes about people getting asked for ID as proof of age for NSFW servers, just to send to server admins. I figured it was a ID fraud scheme of some sort, but now I'd chalk it up to manic "protect the children" believers.
Reginald_T_Biter@lemmy.world · 6 pts · 303d
We'll be reminiscing about good old boring Starmer once Lord Gobshite inevitably gets voted in by a load of gammons
TankovayaDiviziya@lemmy.world · 2 pts · 303d
The Labour under Starmer is closet Tory. I wish that the popular Manchester Labour mayor (whose name I forgot) takes his place as PM, which actual leftist politicians try to make him to be. Although this will be a Sysiphean task under the ruthless politicking in British politics and Labour Party's own strict rule on who could become PM.
this_is_phil@sh.itjust.works · 1 pts · 303d
Andy Burnham!
chatokun@lemmy.dbzer0.com · 51 pts · 304d
Hmm, I don't recall ever doing age verification for Discord. Were older accounts grandfather'd in, or is it currently limited by region or something?
SoftestSapphic@lemmy.world · 69 pts · 304d
I think it's a UK thing
They have been passing legislation to basically dox their citizens for them to gain access to the internet
REDACTED@infosec.pub · 34 pts · 304d
The Russia thanks UK for this valuable information
echodot@feddit.uk · 9 pts · 304d
Yeah it's like the government want to get sued. They are better than the previous administration but that's a pretty low bar
themachinestops@lemmy.dbzer0.com · 15 pts · 304d
It was obvious things like this will happen, unlike banks and government sites social media sites don't have strict cyber security requirements and they want these sites to have a government ID. It was a bad idea from the start.
TomArrr@lemmy.world · 12 pts · 304d
Also currently being rolled out in Australia too 😔
newcool1230@lemmy.ml · 12 pts · 304d
I believe people from
EUUK and people who say they were under 13 and got reported. They needed to send in a pic of them holding their ID to get unbanned.edit: UK people not EU
aeternum@lemmy.blahaj.zone · 3 pts · 304d
JackbyDev@programming.dev · 6 pts · 304d
You're much too young for the Internet. Please submit your SSN and parents' credit card information.
Crashumbc@lemmy.world · 1 pts · 304d
Foot print
SaharaMaleikuhm@feddit.org · 2 pts · 304d
Am from EU. Two accounts, but no ID confirmation required for either.
seraphine@lemmy.blahaj.zone · 1 pts · 303d
as some pointed out, eu folks didnt have to verify anything. afaik, its the uk folks that are affected
schnokobaer@feddit.org · 1 pts · 304d
From EU, got nothing
Electricd@lemmybefree.net · 1 pts · 304d
Well, did you get reported and did you ever say you were under 13?
schnokobaer@feddit.org · 1 pts · 303d
I don't know and I don't remember. I was replying to the 'people from the EU' bit, as it does not seem correct to me.
Holytimes@sh.itjust.works · 11 pts · 303d
Any time your account gets locked for age reason it requires it. So if you have never had an age lock it's unlikely you had to do it.
It's as easy as someone reporting you for being underage with no proof or even just saying "I'm 14 and what is this" as a meme to get locked tho.
Hell the auto flag system can hit you if you just talk like a kid sometimes.
Electricd@lemmybefree.net · 6 pts · 304d
You often get age verification if your account got blocked because someone reported you to be underage
Octagon9561@lemmy.ml · 49 pts · 303d
And this is why this provide xyz private information for verification bs should be illegal
ILikeBoobies@lemmy.ca · 16 pts · 303d
And why any service asking it should be moved on from.
Pretty sure these people could have found a teamspeak, matrix, or mumble server without the requirement.
Garbagio@lemmy.zip · 8 pts · 303d
KelvarCherry@lemmy.blahaj.zone · 3 pts · 303d
What happened to "Don't share your real identity online"? Oh.. Social Media.
frezik@lemmy.blahaj.zone · 2 pts · 303d
In this case, it's the opposite for people in the UK. It's illegal to not verify age.
PissingIntoTheWind@lemmy.world · 46 pts · 304d
Thank god I never gave them an image.
TommySoda@lemmy.world · 36 pts · 304d
Oh no it's that thing everyone would say would happen!
ms_lane@lemmy.world · 4 pts · 303d
Why shouldn't I make the Torment Nexus!?
supersquirrel@sopuli.xyz · 31 pts · 304d
Fuck Discord
theherk@lemmy.world · 15 pts · 304d
I agree, but fuck this dumb law first and foremost.
seraphine@lemmy.blahaj.zone · -6 pts · 303d
discord isn't at fault here. I don't say they do good stuff either, i just want to stick to the facts. It's the UK government who forced them in the first place
viking@infosec.pub · 7 pts · 303d
They enforced the verification, but discord was supposed to delete the images right after.
socialsecurity@piefed.social · 1 pts · 303d
Are you really defending somebody else's income generating business?
Discord is a threat actor
seraphine@lemmy.blahaj.zone · 3 pts · 303d
nvm i wanted to say the complete opposite, my brain wanted to say two sentences at the same time and mixed up the words. corrected it now
cupcakezealot@piefed.blahaj.zone · 25 pts · 303d
congrats everyone on your two free months of credit monitoring
avidamoeba@lemmy.ca · 25 pts · 304d
To the surprise of no one here. This is the first thing I think of when a system wants me to upload an ID.
TankovayaDiviziya@lemmy.world · 24 pts · 303d
Politicians: That's the point.
Joking aside, now that I think about it, what difference does does it make if companies are stealing infos and spying on you with government mandated age verification checks, and hackers stealing your government mandated age verification info? This just reinforces my view that governments (and companies) are nothing but glorified gangsters.
dogs0n@sh.itjust.works · 3 pts · 303d
A hacker stealing your id can do way more malicious stuff like more expertly crafted phishing and identity fraud just to name two.
No one involved in this from the government to the companies is innocent in this chain though in my opinion. A breach is always bound to happen.
LifeInMultipleChoice@lemmy.world · 4 pts · 303d
To me giving a company or government permission to create the databases allowed for mass facial recognition is the same thing as giving the facial recognition data to criminals. It will be leaked/hacked/sold, etc. It is only a matter of time.
How many Social security numbers in the U.S. have been leaked/hacked/sold/illegally transferred? ~340 million.
Facial recognition will be a near useless tool for security in 10 years, and 100% for population monitoring at the rate we are going.
Brkdncr@lemmy.world · -1 pts · 303d
Option 3: companies that you pay to provide authentication service. Regulated so that they clearly tell you if they are subsidizing service outside of your payments.
We nearly already do this with certificate services and they would probably be in a good position to offer an id service.
gian@lemmy.grys.it · 1 pts · 303d
Then you just need to hack this company instead of Discord, you only change target.
MyNameIsIgglePiggle@sh.itjust.works · 23 pts · 303d
More than half of them turn out to be AI
prole@lemmy.blahaj.zone · 18 pts · 303d
They're all screenshots from Detroit: Become Human
aliser@lemmy.world · 22 pts · 303d
so instead of creating some kind of authorization system that would not require sending your private information to everyone the govt did nothing and instead put that responsibility on EVERY company. begs the question why rushing so much?
spicehoarder@lemmy.zip · 8 pts · 303d
The department of Social security could have created some sort of public/private key pair to very age and DOB. But that's too much to ask for isn't it?
KelvarCherry@lemmy.blahaj.zone · 8 pts · 303d
Have you seen the USA? UK? Russia? China? I really don't want the government making any system to tie internet to any identity. I really don't want any government having any role in the internet.
gian@lemmy.grys.it · 1 pts · 303d
I would suppose that this is because there is not a single way valid for every govt. For example, in Italy we have SPID, which is different from what Germany, France and every EU state have.
If Discord wanted to use it, they had to implement a numbers of way to do it, which can be not that easy.
frenchfryenjoyer@lemmings.world · 19 pts · 303d
A certain subset of people: "B-but at least it stops kids seeing photos of dental decay!!!1111"
meliaesc@lemmy.world · 3 pts · 303d
...what?
frenchfryenjoyer@lemmings.world · 17 pts · 303d
my friend who also lives in the uk was unable to view a Reddit post that had a picture of dental decay because it was marked as nsfw and Reddit requires you to verify age using ID/selfie to be in compliance with the uk's Online Safety Act to see anything marked as nsfw.
my comment was a play on the people who think this is all worth it because it might prevent kids from seeing porn
beejboytyson@lemmy.world · 1 pts · 303d
More people got It then didn't. I clearly didn't.
DoPeopleLookHere@sh.itjust.works · 1 pts · 302d
Im sorry but I need a verb there.
beejboytyson@lemmy.world · 1 pts · 302d
First off to get "it" is the verb. Secondly you needed a noun. See herr lookhere your English is not as good as you think it is.
Mwa@thelemmy.club · 19 pts · 303d
this is why i dont give my ID to any service(obv including Discord) anymore.
frezik@lemmy.blahaj.zone · 9 pts · 303d
The issue here is that age verification is mandatory in the UK, and not just for Discord.
Mwa@thelemmy.club · 4 pts · 303d
yeah thats bad.
TheObviousSolution@lemmy.ca · 15 pts · 303d
I've criticized the sort of personal information that is allowed to be managed by banking entities in the cases of Accidental Americans, where people who have nothing to do with America except that they were born in the US have their data handled by private entities to be passed onto governments they've never been in. Public entities that should handle and be responsible for it in their actual home countries want to wash their hands off from them and there's too much money against too small of a minority for anyone to care about their rights. It doesn't matter how banks have consistently proven that they or their staff can act criminally, either.
At least here, it affects a lot more people so it will likely bring in the change and reform it needs, even if the sensitivity of this data is significantly less.
Gonna have to say, this guy is definitely gonna be screwed by this:
prole@lemmy.blahaj.zone · 9 pts · 303d
Keep on keeping on 👍
HeyThisIsntTheYMCA@lemmy.world · 5 pts · 303d
hey don't share my discord id photo please
CannonFodder@lemmy.world · 13 pts · 304d
So they have 2 million ai generated or free stock photos of faces?
AmbitiousProcess@piefed.social · 32 pts · 304d
These were images of people's ID's, along with photos of their faces to check for a match, not stock photos or even just real selfies on their own.
Skunk@jlai.lu · 5 pts · 304d
Half of those are Norman Reedus in Death Stranding 2.
Holytimes@sh.itjust.works · 3 pts · 303d
Nah, it gets tricked by the first game just as easily lol
nutsack@lemmy.dbzer0.com · 11 pts · 303d
the only person who's allowed to verify my age is my cat because he won't stop being a dick about it
Brkdncr@lemmy.world · 8 pts · 303d
I’d like to use your cat verification system too.
bhamlin@lemmy.world · 11 pts · 303d
That's why I used a picture of my anus for my age verification photo. The wrinkles are what sold it, I think.
adespoton@lemmy.ca · 9 pts · 304d
Who exactly was required to submit age verification photos? Just US citizens?
Kirp123@lemmy.world · 13 pts · 304d
UK ones too.
Warl0k3@lemmy.world · 16 pts · 304d
Just the UK, as far as I'm able to find. Some US users have to verify by clicking the box, but I do not believe they've been en-masse required to upload ID or use the UK's facial recognition nonsense.
From the discord age verification FAQ:
Kirp123@lemmy.world · 2 pts · 304d
So I guess it was only UK ones. For some reason I thought they were asking pictures in the US too.
Warl0k3@lemmy.world · 5 pts · 304d
You might be confusing it with how several states have attempted to implement identity verification for access to porn sites (which has so far avoided a similar scandal to this one by virtue of rampant, contemptuous noncompliance on the part of the porn sites)
x00z@lemmy.world · 1 pts · 303d
Besides some countries, people that had their account flagged as possible underage also need to verify themselves.
I know a French guy that joked about being 12 in a chat, got reported by a troll that got his account locked, and had to send his ID to unlock it.
AnarchistArtificer@slrpnk.net · 8 pts · 304d
Quelle surprise
LustyArgonianMana@lemmy.world · 5 pts · 303d
Just roll all the class actions into a UBI fund for the people
panda_abyss@lemmy.ca · 5 pts · 304d
Well, now I feel better about using a throwaway email when I made my account.
shads@lemy.lol · 9 pts · 304d
Throw away email! Are you going something illegal online that you would want to bypass the government and big techs absolute right to spy on everything you do! That's it people will henceforth only get one single email address assigned at birth that they will be forced to use for all online interactions henceforth. I hope you feel ashamed of yourself with all the children you put at risk with your thoughtless selfish behaviour. Now upload an image of your face certified by a government official and a copy of your birth certificate just to be sure that
terrorists, uhcriminals, uh child abusers don't win.*Please tell me this is the most superfluous /s of all time. *
WorldsDumbestMan@lemmy.today · 4 pts · 303d
Including mine. Nice job Discord! Thanks for the fake age ban...this was their plan, wasn't it?
ohshit604@sh.itjust.works · 4 pts · 304d
So glad I ditched discord the second they considered going public, converting people to Matrix sucks because Element is terrible for group calls, [Edit] tried setting up a Snikket server via Docker compose yesterday but their documentation sucks for manual setups, I don’t need them handling reverse proxying for me and rather they didn’t bind to the host network and instead bind to a docker network eventually my tweaks broke docker itself and I had to restart the service.
Holytimes@sh.itjust.works · 2 pts · 303d
Should have just gone back to TeamSpeak 3
peoplebeproblems@midwest.social · 3 pts · 304d
Age verification photos?
rageagainstmachines@lemmy.world · 1 pts · 304d
edgarzen@sh.itjust.works · 1 pts · 301d
Don't ever use Tencent apps