← Back to context

Comment by Aurornis

16 days ago

They explained it in their announcement at https://discord.com/press-releases/update-on-security-incide...

TL;DR: The IDs were used in age-related appeals. If someone's account was banned for being too young they have to submit an ID as part of the appeal. Appeals take time to process and review.

Discord has 200,000,000 users and age verification happens a lot due to the number of young users and different countries.

This is corporate cover speak for “we keep all data”

  • Yeaaah, nope.

    GDPR is no joke and storing people’s actual ID card photos is a gigantic liability. Companies treat that stuff like it’s toxic waste, they want to get rid of it as fast as possible and permanently.

    • So Discord only just survived financially because of heavy fines imposed from their earlier breach of trust? All their C-suite were fined commensurate with their remunerations+wealth?

    • Maybe that's generally true but you're saying that about a company that has leaked 70,000 IDs that were supposed to not exist just last October.

    • How come they didn’t do that the first time? There’s really no guarantee this time will be different or that the 3rd party is any better.

    • We’re talking about Discord. The same people who put everyone’s “server” as a chat room on WebRTC.

      They don’t share your same sense of toxicity.

Why should we suspect the age verification and age-related appeals would involve different teams or processes?

  • Age verification is done by an iframe to k-id.com.

    Appeals are done in the actual Discord ticketing system.

Uh... EVERYONE with a Discord account has to go through age-related appeals now. That's what the announcement is.