Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. @paco @BenAveling it is just a stupid electronic device

@paco @BenAveling it is just a stupid electronic device

Scheduled Pinned Locked Moved Uncategorized
597 Posts 265 Posters 273 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • troed@swecyb.comT This user is from outside of this forum
    troed@swecyb.comT This user is from outside of this forum
    troed@swecyb.com
    wrote on last edited by
    #326

    @paco No one should let anyone get away with "third party". Your subcontractor - you own it, just as if it had been your own employees. Don't like it? Don't outsource your responsibilities.

    oscherler@tooting.chO 1 Reply Last reply
    0
    • theorangetheme@en.osm.townT This user is from outside of this forum
      theorangetheme@en.osm.townT This user is from outside of this forum
      theorangetheme@en.osm.town
      wrote on last edited by
      #327

      @paco Yet another reason in the litany of reasons I refuse to join Discord. People need to like... stop... using it.

      rolfbly@mastodon.socialR 1 Reply Last reply
      0
      • retrosponge@kind.socialR This user is from outside of this forum
        retrosponge@kind.socialR This user is from outside of this forum
        retrosponge@kind.social
        wrote on last edited by
        #328

        @paco Fucking hell 🙄

        1 Reply Last reply
        0
        • michael@westergaard.socialM This user is from outside of this forum
          michael@westergaard.socialM This user is from outside of this forum
          michael@westergaard.social
          wrote on last edited by
          #329
          No they didn’t. They did their own age verification and stored images of passports in Zendesk (iirc, or some other support desk software). Discord acted completely irresponsibly and discord NEEDS age verification due to their young target audience and child enthusiast problem. I agree with your point, but your representation of what happened at Discord is entirely wrong.
          michael@westergaard.socialM paco@infosec.exchangeP 2 Replies Last reply
          0
          • michael@westergaard.socialM michael@westergaard.social
            No they didn’t. They did their own age verification and stored images of passports in Zendesk (iirc, or some other support desk software). Discord acted completely irresponsibly and discord NEEDS age verification due to their young target audience and child enthusiast problem. I agree with your point, but your representation of what happened at Discord is entirely wrong.
            michael@westergaard.socialM This user is from outside of this forum
            michael@westergaard.socialM This user is from outside of this forum
            michael@westergaard.social
            wrote on last edited by
            #330
            Yes, I remembered correctly: it was zendesk. youtube.com/watch?v=GbXATeFfkRA
            1 Reply Last reply
            0
            • damiano_chech@techhub.socialD This user is from outside of this forum
              damiano_chech@techhub.socialD This user is from outside of this forum
              damiano_chech@techhub.social
              wrote on last edited by
              #331

              @paco Damn, this is both hilarious and terrifying. 70,000 people handed over their documents so Discord could “verify their age,” and now all those files are just floating around the internet. Does anyone really think this is safe?

              1 Reply Last reply
              0
              • tuxonbike@norden.socialT This user is from outside of this forum
                tuxonbike@norden.socialT This user is from outside of this forum
                tuxonbike@norden.social
                wrote on last edited by
                #332

                @paco “At Discord, protecting the privacy and security of our users is a top priority.” says the service without e2ee for direct messages.

                1 Reply Last reply
                0
                • elbeetoots@mastodon.nlE This user is from outside of this forum
                  elbeetoots@mastodon.nlE This user is from outside of this forum
                  elbeetoots@mastodon.nl
                  wrote on last edited by
                  #333

                  @paco Well, you know, at least that company knows how to NOT safely store sensitive personal data...

                  1 Reply Last reply
                  0
                  • theorangetheme@en.osm.townT theorangetheme@en.osm.town

                    @paco Yet another reason in the litany of reasons I refuse to join Discord. People need to like... stop... using it.

                    rolfbly@mastodon.socialR This user is from outside of this forum
                    rolfbly@mastodon.socialR This user is from outside of this forum
                    rolfbly@mastodon.social
                    wrote on last edited by
                    #334

                    @theorangetheme @paco

                    I had to ask something on a discord forum about this app I use.

                    The tone of voice is of teens on the loose.

                    While it's ok & just fine to be a teen on the loose (I've been one myself, and looking back I firmly believe it's a fundamental human right to do really dumb things), COMMA, it's, well, a state of mind I left behind. Mostly. I think. I hope.

                    1 Reply Last reply
                    0
                    • ki@chaos.socialK This user is from outside of this forum
                      ki@chaos.socialK This user is from outside of this forum
                      ki@chaos.social
                      wrote on last edited by
                      #335

                      @elaine @paco
                      So... your idea of data security is to give even more user data to these companies with too much power that we'd love to burn to the ground? (metaphorically) The very same companies that feed every piece of data they can get their hands on into LLMs?

                      shinspiegel@mastodon.socialS 1 Reply Last reply
                      0
                      • tg_esq@mastodon.onlineT tg_esq@mastodon.online

                        @paco
                        Bluesky asked me to give my ID information and documents to a third party provider when Australia introduced its under-16 ban a month or two ago.

                        I deleted Bluesky.

                        f4grx@chaos.socialF This user is from outside of this forum
                        f4grx@chaos.socialF This user is from outside of this forum
                        f4grx@chaos.social
                        wrote on last edited by
                        #336

                        @TG_Esq @paco way to go!

                        1 Reply Last reply
                        0
                        • paco@infosec.exchangeP This user is from outside of this forum
                          paco@infosec.exchangeP This user is from outside of this forum
                          paco@infosec.exchange
                          wrote on last edited by
                          #337

                          @kerfuffle Is it worth highlighting? I mean, admitting that it happened is surely the lowest possible expectation. Do we pat them on the back and give them a participation trophy? In some jurisdictions, this disclosure is mandated by law (which is why these laws are good). Is it worth mentioning that they chose to do what the law said they must?

                          1 Reply Last reply
                          0
                          • michael@westergaard.socialM michael@westergaard.social
                            No they didn’t. They did their own age verification and stored images of passports in Zendesk (iirc, or some other support desk software). Discord acted completely irresponsibly and discord NEEDS age verification due to their young target audience and child enthusiast problem. I agree with your point, but your representation of what happened at Discord is entirely wrong.
                            paco@infosec.exchangeP This user is from outside of this forum
                            paco@infosec.exchangeP This user is from outside of this forum
                            paco@infosec.exchange
                            wrote on last edited by
                            #338

                            @michael Was it Zendesk? Someone else replied that it was 5CA and sent this link

                            https://5ca.com/blog/holding-statement-security-incident/

                            The phrase “our vendor used to review age-related appeals” in the discord disclosure made it sound like the vendor did the appeals. So maybe discord did the initial verification, but this vendor was doing more than just storing images.

                            michael@westergaard.socialM 1 Reply Last reply
                            0
                            • curiously@mastodon.auC This user is from outside of this forum
                              curiously@mastodon.auC This user is from outside of this forum
                              curiously@mastodon.au
                              wrote on last edited by
                              #339

                              @paco inevitable.
                              Too good a target of course this happened and will keep happening. Waiting for the big one that makes photo ID worthless.

                              1 Reply Last reply
                              0
                              • paco@infosec.exchangeP paco@infosec.exchange

                                @michael Was it Zendesk? Someone else replied that it was 5CA and sent this link

                                https://5ca.com/blog/holding-statement-security-incident/

                                The phrase “our vendor used to review age-related appeals” in the discord disclosure made it sound like the vendor did the appeals. So maybe discord did the initial verification, but this vendor was doing more than just storing images.

                                michael@westergaard.socialM This user is from outside of this forum
                                michael@westergaard.socialM This user is from outside of this forum
                                michael@westergaard.social
                                wrote on last edited by
                                #340
                                Then I might have been wrong and there were more leaks. They definitely had one last year, where they hosted pictures of peoples' passports in Zendesk (which is all kinds of insane).

                                If they used a "proper" age verification service and they leaked, that's an entire new can of worms. (Though I still think Discord in particular having age verification is not a bad thing.)
                                michael@westergaard.socialM 1 Reply Last reply
                                0
                                • lazysupper@famichiki.jpL This user is from outside of this forum
                                  lazysupper@famichiki.jpL This user is from outside of this forum
                                  lazysupper@famichiki.jp
                                  wrote on last edited by
                                  #341

                                  @paco
                                  When I logged back into LinkedIn a few a months ago (after years of blissful absence) it asked me to "verify" my identity. So I click "ugh, fine" and got redirected to a 3rd party asking for all of my personal info. lol. that was a quick "Cancel".

                                  1 Reply Last reply
                                  0
                                  • E This user is from outside of this forum
                                    E This user is from outside of this forum
                                    eph_lv@mastodon.social
                                    wrote on last edited by
                                    #342

                                    @paco
                                    Sadly: "called it!"

                                    1 Reply Last reply
                                    0
                                    • roohafzaluvr@mastodon.socialR This user is from outside of this forum
                                      roohafzaluvr@mastodon.socialR This user is from outside of this forum
                                      roohafzaluvr@mastodon.social
                                      wrote on last edited by
                                      #343

                                      @paco why does every company say "at [insert company] your privacy is our priority"? are they just taught this?

                                      1 Reply Last reply
                                      0
                                      • beecycling@wandering.shopB This user is from outside of this forum
                                        beecycling@wandering.shopB This user is from outside of this forum
                                        beecycling@wandering.shop
                                        wrote on last edited by
                                        #344

                                        @paco If any Discord server I use starts asking for age-verification, that's the day I leave that server.

                                        It's one thing to be asked to trust Discord (or whatever other company) who you know you're dealing with because that's their name on the website. I can decide if I trust them or not. It's another thing for them to be using some third party who I never heard of and have no idea if I should trust.

                                        1 Reply Last reply
                                        0
                                        • xoagray@tiggi.esX This user is from outside of this forum
                                          xoagray@tiggi.esX This user is from outside of this forum
                                          xoagray@tiggi.es
                                          wrote on last edited by
                                          #345

                                          @paco Yet another reason to not use Discord. It was bad from the start and it hasn't gotten better. I wish companies would stop leaning on it more and more for things like tech support too. We shouldn't have to risk identity theft for tech support.

                                          paco@infosec.exchangeP nyovaya@transfem.socialN 2 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups