frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Discord cuts ties with Peter Thiel-backed verification software

https://fortune.com/2026/02/24/discord-peter-thiel-backed-persona-identity-verification-breach/
134•robtherobber•3h ago

Comments

embedding-shape•3h ago
Ah man, just tried to submit this with the title "Discord cuts ties with Peter Thiel-backed SaaS once code tied to US spying found" which is slightly better I think, and fits exactly within 80 characters :)

I think the whole "after its code was found tied to U.S. surveillance efforts" part is new and wasn't known before, so feels important to have in the title too. Although most of us probably assumed it was true before too.

blitzar•1h ago
> once code tied to US spying found

New and also should be the big story.

"Butcher cuts ties with supplier when steaks found to be human meat" shouldnt be a story about changing suppliers ...

robtherobber•1h ago
That would have been a better title, I agree.
crimsoneer•39m ago
Is this actually a thing that is true?
jyscao•1h ago
So does this mean Discord is scrapping its new face verification requirement for users, or imply they’re no longer using this 3rd party service (Persona) to do it? The article wasn’t too clear on that.
Macha•1h ago
K-id is the vendor they were proposing which did on device processing. They were trying to downplay the initiative by saying all the k-id data stayed on device.

This was undermined by the fact they were also trialling a switch to Persona (the vendor in the story), which did not uphold that guarantee. It was horrific optics to be reassuring people that it was ok because you didn’t save data but also be trialling a switch to a vendor which did save data, which I guess is a lot of the reason this vendor switch was cancelled. (Though it does call into question discord’s judgment that they thought this was a good idea).

Anyway, Persona was also breached which is how the government links were discovered and also probably a part of this decision. This is not to be confused with the breach in November of 5CA, _another_ vendor they used in the initial UK and Australia roll outs. The fact that two vendors were breached in four months is a good example of why this is a bad idea

Aurornis•45m ago
> So does this mean Discord is scrapping its new face verification requirement for users,

No, they’re outsourcing the verification to an external company. Just not this one.

Side note: The verification is only if you want to remove content filters, join adult-themed servers and a couple other features. If you only want to chat with your friends and use voice then no verification is required.

blibble•41m ago
probably find out the new identity verification firm is just a shell around the Thiel company
giraffe_lady•27m ago
Well, until the upcoming batch of laws goes through classifying discussion of lgbtq people as inherently mature content. This is one half of a two part strategy by the american right to make queer content de facto illegal again without running into first amendment protections. Getting the payment processors banning "mature" content is the other leg of this stool.
ta9000•1h ago
Too fucking late, eat shit Discord. We’re all moving to E2E encrypted platforms.
squeefers•1h ago
where we definitely will not be moaning about the same thing in 18 months time
alphawhisky•1h ago
Joke's on you, once I finish setting up my P2P tin can network I'll be invisible.
dgxyz•1h ago
I just nuked it and didn’t replace it. Bloated piece of shit full of misery.

We decided to just meet up in person twice a month and play board games instead.

encom•47m ago
What's the point of E2E on a chatroom/channel/"""server""" that anyone can join?

Yes, I'm making (another) argument in favour of IRC. IRC has optional client-server encryption, and you can set channel modes to only allow encrypted clients access. So that way you at least prevent eavesdropping.

josefritzishere•1h ago
This does not cure the face scanning nonsense. I deleted and am not going back.
john_strinlai•1h ago
>Nearly 2,500 accessible files were found sitting on a U.S. government-authorized endpoint, researchers pointed out on X. The files showed Persona conducted facial recognition checks against watchlists and screened users against lists of politically exposed persons.

>Persona performs 269 distinct verification checks, including screening for “adverse media”

im sure everyone assumed this, but its good to know it.

>And the information was openly available. “We didn’t even have to write or perform a single exploit, the entire architecture was just on the doorstep,”

it is kind of scary how often these types of situations are only found out because of wild incompetence. you have to imagine that most similar situations dont suffer from the same incompetence (and thus arent known)

>“At Discord, protecting the privacy and security of our users is a top priority.

please, i wish companies would just stop saying this obvious lie. you know that you dont care. we know that you dont care.

>It’s dystopian that we want people to facedox themselves to everyone to be real online.

.... says the ceo of the company that you have to send your face ("facedox", if you will) to

midtake•1h ago
> According to Discord, only a small number of users were part of this test, in which any information submitted could be stored for up to seven days before it would be deleted.

Ah yes, we only store it for 7 days. During those 7 days, we pass it to Persona, and who knows how long they keep it!

AlexandrB•1h ago
Discord's previous statement:

> "Identity documents submitted to our vendor partners are deleted quickly— in most cases, immediately after age confirmation"

So now it's not "immediately" but 7 days? I don't know how anyone can trust any statement from these guys.

jcgrillo•47m ago
The one thing you can trust is this:

If a tech company says something to you, and they don't give you the means to verify it on your own, they are lying to you. Do not trust anything they say, ever.

rocketpastsix•11m ago
"I don't know how anyone can trust any statement from these guys."

this is the fun part, you can't!

mkesper•1h ago
Related: I Verified My LinkedIn Identity. Here's What I Handed Over https://news.ycombinator.com/item?id=47098245
bri3d•1h ago
The referenced write-up based on the Persona front end code is here:

https://vmfunc.re/blog/persona

I definitely recommend reading this primary source before drawing conclusions about the code as most of the secondary reporting is quite low quality.

dunder_cat•52m ago
Seems to be down for me. https://web.archive.org/web/20260220192124/https://vmfunc.re...
bondarchuk•47m ago
Submitted 6 days ago but flagged https://news.ycombinator.com/item?id=47059129

@dang can this get a second chance?

vincnetas•37m ago
damn. why did the website stole my audio?
pavel_lishin•25m ago
Some of the most interesting authors in tech on the internet have just absolute awful websites. Blinking animations everywhere, weird sounds, "cute" little javascript animations like it's 1999 again.
john_strinlai•18m ago
the last time the website was submitted, over half the comments talked about website design instead of the actual content. we can probably skip doing it again.

different people have different tastes. people complain about boring websites, people complain about websites with animations or colors. the only guarantee is that the conversation isnt interesting.

if you are on the side that doesnt like music, animations, whatever, i recommend a combination of noscript and using reader mode.

dgxyz•8m ago
Good article but the web site gave me eye and ear cancer.

Please make it actually readable and don't steal my audio!

mikkupikku•1h ago
For some reason, discord has never asked more from me than a verified email address. No phone number or anything else. Maybe I'm being monitored and they don't want to spook me off the honeypot? Half joking..
harrisoned•39m ago
Same for me, and my account is almost a decade old. I think it depends a lot where are you from and the kind of activity, as i read stories of people being asked to register a number out of nowhere. Many servers requires you to have it tho, due to spam protection. I just don't talk on those.
HWR_14•38m ago
Each discord server can decide whether they only will allow people with a phone number on. When you hit one of those, Discord will ask you for your number.
harrisoned•32m ago
Those require a phone for you to send messages and interact. It will ask you to 'Verify phone', but you can chose not to and stay on the server as read-only, Discord itself won't bother you about it. I am on a few like that for quite some time.
rideontime•52m ago
I'm glad to see "Peter Thiel-backed" becoming a widely-recognized epithet.
metalliqaz•38m ago
it is truly amazing how much damage one person is able to do to civilized society

if you expand the scope to a handful of adjacent figures, the catastrophe is truly amazing

pphysch•33m ago
Thiel is one of the more public faces of what is now known as the "Epstein class" of societal predators. But one of many and certainly not the epicenter.
Kapura•28m ago
yeah, this is what unchecked wealth gives you. yay capitalism.
throw4847285•36m ago
I guess we could all forgive trying to destroy western civilization under the guise of saving it, but drew the line at poor media literacy when it comes to One Piece and Watchmen.

(This is a joke in case that wasn't clear)

jordanb•3m ago
It was always difficult to get normal people to understand why the tech billionaires are so bad until Thiel gave us that clip of him getting stumped by the "should humanity survive" question.

I'm forever grateful to Thiel for that clip, and to Musk for his crippling Twitter addiction. It was pretty impossible to get regular people to understand that folks like Bill Gates or Larry Ellison are skinwalkers when all they ever see about these people is professionally managed public relations content.

zoeysmithe•4m ago
That's fine, if not very good, but the central problem remains (ignoring the capitalist corrupted business culture and its merging with the state behind much of this). We can't centralize our communications without major concessions in significant ways that non-techies seem unaware of until a big news item like this comes out. "What, they're logging my chats, and IP, voice clips, and now they want my ID for 18+ discords?" Yes, absolutely you are being logged and those logs will go places you have no control over. Maybe even to oppress you or your loved ones.

Discord's entire value proposition was "Hey just click here, no need to pay for a teamspeak server or do peer-to-peer jank." Deeply personal stuff is said and posted in those spaces. Common communication should not be shared like this and we keep falling back to the "tapped my phone line" problem.

The difference between then and now is that for a long time there was no alternative to POTS. You just had to use the phone to call someone. The phone company and whatever government tapping was very hard to get around. But today there are other ways to do near everything if we give up on for-profit centralized services.

I think society keeps flirting with federation and other things similar to that but never quite makes the jump. The twitter exodus went back to a new centralized service like Bluesky that will one day be sold to another deep-pocketed buyer with its own agenda, thus creating this problem again. Sure, now with federation or personal servers, the privacy issue goes back to the server operator, but at least that could be someone you trust, or even you. When currently, neither of those options are possible with things like Discord or Bluesky.

I'm testing moving my friends and gaming group to self-hosted teamspeak or stout or mumble or something like that. I think we'll lose some convenience, but life isn't all about gains. Sometimes you have to sacrifice things for the greater good. I also really want to start moving away from things like reddit, bluesky, HN, etc to federated services and have dipped my toes there quite a bit, but the population isn't there (yet?).

I hope this is a wakeup call that people need, much like the wake-up call the fight against personal encryption was in the 90s. I think we're in a super bad place right now, and its worth discussing the elephant in the room, even to non-techies, and what alternatives there are to the current system. I think people need to get over the convivence of the current system and realize if they want privacy and safety, they may have to migrate to services built with that in mind.

rvz•50m ago
Do not believe them.
mentalgear•38m ago
Everyday someone cuts ties with Palentier's Peter Thiel (or the rest of the digital mafia), it's a good day for society as a whole.
stephc_int13•22m ago
This name is turning radioactive. Not a bad thing.
outside1234•21m ago
Who IS still using this verification software?
rocketpastsix•12m ago
the damage is already done though. Discord just burned years of goodwill and trust. Im in a few discord communities and while they aren't moving Im not looking to join any more right now because of this whole thing.
IgorPartola•8m ago
> politically exposed persons

I do not know what this euphemism means. Is this like the modern trend of calling inmates “justice involved individuals”?

I Pitched a Roller Coaster to Disneyland at Age 10 in 1978

https://wordglyph.xyz/one-piece-at-a-time
93•wordglyph•2h ago•32 comments

Diode – Build, program, and simulate hardware

https://www.withdiode.com/
291•rossant•3d ago•64 comments

Goodbye InnerHTML, Hello SetHTML: Stronger XSS Protection in Firefox 148

https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-fire...
151•todsacerdoti•2h ago•69 comments

λProlog: Logic programming in higher-order logic

https://www.lix.polytechnique.fr/Labo/Dale.Miller/lProlog/
85•ux266478•3d ago•18 comments

A distributed queue in a single JSON file on object storage

https://turbopuffer.com/blog/object-storage-queue
96•Sirupsen•3d ago•32 comments

Terence Tao, at 8 years old (1984) [pdf]

https://gwern.net/doc/iq/high/smpy/1984-clements.pdf
402•gurjeet•1d ago•214 comments

Tiny QR code achieved using electron microscope technology

https://newatlas.com/technology/smallest-qr-code-bacteria-tu-wien/
13•jonbaer•3d ago•8 comments

IRS Tactics Against Meta Open a New Front in the Corporate Tax Fight

https://www.nytimes.com/2026/02/24/business/irs-meta-corporate-taxes.html
45•mitchbob•2h ago•51 comments

The Missing Semester of Your CS Education – Revised for 2026

https://missing.csail.mit.edu/
190•anishathalye•23h ago•55 comments

Discord cuts ties with Peter Thiel-backed verification software

https://fortune.com/2026/02/24/discord-peter-thiel-backed-persona-identity-verification-breach/
135•robtherobber•3h ago•45 comments

We installed a single turnstile to feel secure

https://idiallo.com/blog/installed-single-turnstile-for-security-theater
25•firefoxd•1d ago•2 comments

Show HN: enveil – hide your .env secrets from prAIng eyes

https://github.com/GreatScott/enveil
155•parkaboy•10h ago•90 comments

I Ported Coreboot to the ThinkPad X270

https://dork.dev/posts/2026-02-20-ported-coreboot/
250•todsacerdoti•15h ago•52 comments

The Age Verification Trap: Verifying age undermines everyone's data protection

https://spectrum.ieee.org/age-verification
1583•oldnetguy•1d ago•1201 comments

Show HN: X86CSS – An x86 CPU emulator written in CSS

https://lyra.horse/x86css/
201•rebane2001•13h ago•67 comments

Unsung heroes: Flickr's URLs scheme

https://unsung.aresluna.org/unsung-heroes-flickrs-urls-scheme/
184•onli•3d ago•68 comments

Blood test boosts Alzheimer's diagnosis accuracy to 94.5%, clinical study shows

https://medicalxpress.com/news/2026-02-blood-boosts-alzheimer-diagnosis-accuracy.html
362•wglb•12h ago•144 comments

Show HN: Steerling-8B, a language model that can explain any token it generates

https://www.guidelabs.ai/post/steerling-8b-base-model-release/
256•adebayoj•15h ago•77 comments

Making Wolfram tech available as a foundation tool for LLM systems

https://writings.stephenwolfram.com/2026/02/making-wolfram-tech-available-as-a-foundation-tool-fo...
249•surprisetalk•17h ago•136 comments

Decimal-Java is a library to convert java.math.BigDecimal to and from IEEE-754r

https://github.com/FirebirdSQL/decimal-java
29•mariuz•6h ago•4 comments

Firefox 148 Launches with AI Kill Switch Feature and More Enhancements

https://serverhost.com/blog/firefox-148-launches-with-exciting-ai-kill-switch-feature-and-more-en...
386•shaunpud•9h ago•325 comments

“Car Wash” test with 53 models

https://opper.ai/blog/car-wash-test
317•felix089•19h ago•378 comments

ATAboy is a USB adapter for legacy CHS only style IDE (PATA) drives

https://github.com/redruM0381/ATAboy
40•zdw•3d ago•30 comments

UNIX99, a UNIX-like OS for the TI-99/4A (2025)

https://forums.atariage.com/topic/380883-unix99-a-unix-like-os-for-the-ti-994a/page/5/#findCommen...
197•marcodiego•19h ago•60 comments

Hetzner Prices increase 30-40%

https://docs.hetzner.com/general/infrastructure-and-availability/price-adjustment/
369•williausrohr•1d ago•571 comments

Writing code is cheap now

https://simonwillison.net/guides/agentic-engineering-patterns/code-is-cheap/
292•swolpers•22h ago•367 comments

A simple web we own

https://rsdoiel.github.io/blog/2026/02/21/a_simple_web_we_own.html
287•speckx•23h ago•207 comments

Graph Topology and Battle Royale Mechanics

https://blog.lukesalamone.com/posts/beam-search-graph-pruning/
35•salamo•2d ago•3 comments

Show HN: PgDog – Scale Postgres without changing the app

https://github.com/pgdogdev/pgdog
299•levkk•1d ago•54 comments

Ladybird adopts Rust, with help from AI

https://ladybird.org/posts/adopting-rust/
1226•adius•1d ago•680 comments