frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Discord says 70k users may have had their government IDs leaked in breach

https://www.theverge.com/news/797051/discord-government-ids-leaked-data-breach
60•PaulKeeble•2h ago

Comments

lschueller•2h ago
Asking this out of curiosity: is it a requirement, that such data is being stored once the verification process is completed?
StanislavPetrov•1h ago
Requirement by who? Discord isn't required to demand your ID, let alone store it.
nomel•14m ago
It's required in the UK to access non-child friendly content: https://support.discord.com/hc/en-us/articles/33362401287959...
dathinab•44m ago
in case of the EU it's more the opposite

GDPR requires data minimalism and ~use case binding so if you submit data for age verification there is no technical reason to keep it after knowing your age so you _have to_ delete it.

itake•44m ago
Just a guess, but they may store the original ID card to audit duplicate accounts.

If their machine learning models, think that two people are the exact same, having the original image, especially a photo of the same ID card could confirm that.

fuzzfactor•23m ago
The best years online were when it was universally recognized that government ID's are completely unsuitable for interaction with the internet in any way.

Like it was since the beginning when government ID's first became a thing.

selcuka•6m ago
There are image processing methods for hashing people's faces. They don't have to store the actual photo to do that.
3eb7988a1663•36m ago
That is the bonkers thing about this story. Why take on the liability? Get what you need and toss the responsibility. If you must store it (which seems unlikely) put that extra-bad-if-leaked information behind a separate append only service for which read is heavily restricted.
neilv•38m ago
This is not OK, and the reporting is not OK.

Opening with:

> Discord has identified approximately 70,000 users that may have had their government ID photos exposed as part of a customer service data breach announced last week, spokesperson Nu Wexler tells The Verge.

Then a big PR quote, letting a potential wrongdoer further spin it.

Then closing with:

> In its announcement last week, Discord said that information like names, usernames, emails, the last four digits of credit cards, and IP addresses also may have been impacted by the breach.

This is awful corporate PR language, not journalism, on a big story about probable corporate negligence resulting in harm to tens of thousands people.

Here's the bare minimum kind of lede I expect on this reporting:

Discord may have leaked sensitive personal information about 70,000 users -- including (but not necessarily limited to) government IDs, names, usernames, email addresses, last 4 digits of SSN, and IP addresses.

I'm ready to block both Discord and The Verge.

PaulKeeble•31m ago
The hackers claim they have data of 5.5 million, discord is saying 70k. Hmmmm
selcuka•5m ago
Probably 5.5 million emails/names, 70k photos.
tifik•26m ago
I don't know if I just became cynical and jaded, but is this really surprising to anyone in any way? Any time I give out my personal information to anyone for any reason, I basically treat it as 'any member of public can now access it'.

Even if a service doesn't have it in their TOS that they sell it to 3rd parties, they might do it anyway, or there will, sooner or later, be a breach of their poorly secured system.

To make it clear - I don't particularly blame any one corporation, this is a systemic issue of governments not having/not enforcing serious security measures. I just completely dropped the expectation of my information being private, and for the very few bits that I do actually want to stay private, I just don't, or allow anyone to, digitalize or reproduce them at all in any way.

fishmicrowaver•20m ago
You've got to be a complete moron uploading your gov ID to discord
giancarlostoro•9m ago
It is specifically because you got banned for "being under 13" it comes from someone asking a question like "How many candles in this photo?" then you reply "7" then they edit the message to say "How old are you" and voila, underage ban.

What you are overlooking is that Discord is the new MSN Messenger, YIM, etc your friends are not backed up in a meaningful way, nor the servers you're in, if you lose your account, you lose contact with basically your entire internet life and friends.

Discord should not keep those IDs longer than a month at a time once the user is unbanned it should be deleted a week later, or removed from that panel altogether.

mikert89•13m ago
When can people start going to jail for this kind of thing
elevation•13m ago
I didn't feel comfortable giving discord my phone number when they demanded it, so I lost access to the open source communities that insist on collaborating there.

I wish breaches like this would cause people to reconsider their choices but sadly, it's unlikely most users will move.

giancarlostoro•11m ago
The issue is if you don't enforce the phone number requirement on your server you get all the trolls who don't use phone numbered accounts. I wish Discord would allow you to restrict known VPNs instead of requiring phone numbers. It would solve so many issues. I know a LOT of VPNs wont be caught, but if you block MOST non-residential IP blocks, you'll capture a lot of them.
ChrisArchitect•7m ago
Source: https://discord.com/press-releases/update-on-security-incide...

Offline, Private AI Agent for Local Files

https://hyperlink.nexa.ai/
1•jinqueeny•1m ago•0 comments

Show HN: 64Careers – Build a pro career page and ATS in 5 minutes for $25/mo

https://www.64careers.com/
1•SaulGallegos•2m ago•0 comments

Self-Correction Bench: Revealing and Addressing LLM Self-Correction Blind Spot

https://arxiv.org/abs/2507.02778
1•yubblegum•3m ago•1 comments

Anthropic’s ‘anti-China’ stance triggers exit of star AI researcher

https://www.scmp.com/tech/tech-trends/article/3328222/anthropics-anti-china-stance-triggers-exit-...
1•nothrowaways•3m ago•0 comments

My Friend Is Giving Me a Kidney

https://nathandyer.me/2025/03/13/micah.html
1•mtlynch•5m ago•0 comments

First Brands Creditor Seeks Investigation of 'Vanished' Cash

https://www.bloomberg.com/news/articles/2025-10-09/first-brands-creditor-seeks-investigation-of-v...
1•zerosizedweasle•12m ago•0 comments

Did not upd@te my S23U for a year and still got a green line today

https://old.reddit.com/r/GalaxyS23Ultra/comments/1nv1bsv/did_not_updte_my_s23u_for_a_year_and_sti...
1•sipofwater•13m ago•0 comments

Musk's Cheap Teslas Are the Wrong Kind of Cheap

https://www.bloomberg.com/opinion/articles/2025-10-07/musk-s-cheap-teslas-are-the-wrong-kind-of-c...
2•teleforce•15m ago•0 comments

Designing a Low Latency 10G Ethernet Core

https://ttchisholm.github.io/ethernet/2023/05/01/designing-10g-eth-1.html
1•picture•22m ago•0 comments

When your website makes you smile

https://jamesg.blog/2025/10/02/when-your-website-makes-you-smile
2•freediver•27m ago•0 comments

My Claude Code Setup

https://www.justindfuller.com/programming/my-claude-code-setup
1•iamjfu•34m ago•0 comments

An open-source, free client-side playground for the Sora 2 API

https://www.sora2playground.com/
1•amirzak•34m ago•1 comments

Anthropic pushing $200/mo MAX users to use Sonnet instead of Opus

https://github.com/anthropics/claude-code/issues/8449
1•moomoo11•36m ago•2 comments

In-Party Love, Out-Party Hate, and Affective Polarization in Twelve Democracies

https://academic.oup.com/poq/article/89/2/459/8152104?login=false
1•PaulHoule•37m ago•0 comments

Frozen internet, not dead internet

https://www.lomondlabs.com/the-web-is-freezing-over
1•isomierism•38m ago•0 comments

Polymarket Founder Is Youngest Self-Made Billionaire After Deal with NYSE Owner

https://finance.yahoo.com/news/polymarket-founder-youngest-self-made-140118244.html
2•jnord•39m ago•2 comments

In thirsty Reno, a crucial vote could usher in more water-guzzling data centers

https://www.nbcnews.com/news/us-news/reno-nevada-data-centers-water-drought-rcna235966
1•petethomas•44m ago•0 comments

First device based on 'optical thermodynamics' can route light without switches

https://phys.org/news/2025-10-device-based-optical-thermodynamics-route.html
1•rbanffy•45m ago•0 comments

With its latest acqui-hire, OpenAI is doubling down on personalized consumer AI

https://techcrunch.com/2025/10/03/with-its-latest-acqui-hire-openai-is-doubling-down-on-personali...
1•gmays•45m ago•0 comments

Bending the Curve

https://thezvi.substack.com/p/bending-the-curve
1•paulpauper•47m ago•0 comments

Four ways learning Econ makes people dumber re: future AI

https://www.lesswrong.com/posts/xJWBofhLQjf3KmRgg/four-ways-learning-econ-makes-people-dumber-re-...
2•paulpauper•47m ago•0 comments

Why DoorDash built its own delivery robot

https://www.restaurantdive.com/news/doordash-dot-smart-scales-autonomous-delivery-platform/761494/
1•jonbaer•54m ago•0 comments

A brain-network renders subjective experience from multiple predictive modules

https://www.nature.com/articles/s41467-025-63522-y
2•Saladin7•1h ago•1 comments

What the Xbox Game Pass price hike says about the rising cost of playing games

https://www.theguardian.com/games/2025/oct/08/pushing-buttons-xbox-game-pass-price
1•c420•1h ago•2 comments

From Passwords to Passkeys

https://ssg.dev/from-passwords-to-passkeys/
3•sedatk•1h ago•3 comments

Show HN: Puter.js Docs

https://github.com/HeyPuter/docs
1•ent101•1h ago•0 comments

The Parasocial Power of AI

https://www.christiancentury.org/features/parasocial-power-ai
1•zdw•1h ago•0 comments

Against "The Pedagogy of the Oppressed" by Paulo Freire

https://zaira.blog/notes/freire/
2•cosmicecho•1h ago•0 comments

Give me a single reason why Sora2 should exist [video]

https://www.youtube.com/watch?v=Vz0oQ0v0W10
1•JumpCrisscross•1h ago•0 comments

Ask HN: What problem would you solve with unlimited resources? (October 2025)

2•hedayet•1h ago•0 comments