Comment on The Discord Breach Might Be Worse Than We Thought, As The Hacker Is Said To Have Two Million Age Verification Photos

plz1@lemmy.world ⁨1⁩ ⁨day⁩ ago

The fact that these photos and PII (personally identifiable information) were not destroyed after the verification process was certified is absolutely atrocious OpSec. I don’t even care which of the two companies is ultimately responsible, because they are both responsible.

  1. Zendesk for their bad OpSec
  2. Discord for both outsourcing this AND not having contractual requirements to properly secure and destroy PII when it was no longer required.

I work in IT, and treat PII like it’s dangerously radioactive, because in the digital world, it really is.

source
Sort:hotnewtop