At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked.
I have no idea how to change it/fix it. But it seems weird to me.
At this point there is giant databases containing everything people need to take complete control of your identity sitting there just waiting to be hacked.
I have no idea how to change it/fix it. But it seems weird to me.
The government already operates an identity service via passports. The only reason they do not have an electronic identity service yet is because it is beneficial for them to be able to blame private actors when things go wrong.
Misc governments already operate 1,000s of identity, credentialing, and licensing services.
Wouldn't it be great if profiles on DoorDash, Yelp, Hotels, etc. were required to be linked to IRL identities and licenses?
If DoorDash has a fake profile for D111af5ccf's Divine Donuts, is that not a crime? Impersonation, fraud, theft of IP, etc.
Again, how does authenticity conflict with free speech?
Examples, please.
I don't think the question GP is asking is whether or not Stripe is a good way to confirm someone's real-life identity, or whether it would be better for the government to do it. I think what they're asking why we're doing identity verification for chat applications. Is this a good direction overall for the Internet to be moving in?
I don't like the idea that I should have one real-life identity that every service I sign up for online knows, even trivial services like social networks. I would argue a world like that is abridging on people's Right to Hide (https://anewdigitalmanifesto.com/#right-to-hide)
I am not suggesting all businesses be required to do it. But I do not see why businesses should be prohibited from doing it. If you do not want an identity linked service, then buy a website name, and start a business and do not require people to identify.
We can't justify every architecture decision about the web via only business costs, if that was the case we'd make adblockers illegal and deprecate HTML. You need a stronger argument if you want me as a user to care about or support your business interests. If you want my support you have to show how this benefits the web overall, not just your company.
Am I entitled to alternatives that do not verify identity? Maybe the operating costs are too high?
The "we" in this context (ordinary users) also comprise the majority of voters and regulators who will ultimately decide how the system you propose is built and what restrictions it will have; and that is a group that is not solely motivated by your business interests -- so it is kind of important for you to be able to convince them that your system benefits them, and not just a few businesses.
Why should a Congressperson vote to build the system you propose instead of introducing a harsh privacy law that restricts which businesses are allowed to collect identification?
We're already living in a world where you have to "login with Facebook" to do many things, but at the very least you can currently still create a fake account if you have no other option. If reliable identity verification starts becoming commonplace, that option goes away.
> the overall population of users on the web
You keep arguing about a non-issue. Normal users do not need to verify with Discord. It's only for bot owners of popular bots to prevent the widespread abuse Discord saw.
The linked comment is incorrect to say that Discord only requires verification for specific permissions, Discord requires verification for bots who are in more than 100 servers regardless of what permissions they use. I think it's fairly obvious that verification for Discord bots is going to gradually expand and encompass more of the service, but maybe I'm just cynical from watching other companies do the same thing with their identity verification schemes.
More importantly, I disagree that identity verification is the best way for Discord to combat abuse. I think that Discord's moderation tools and server settings are lackluster. At best, I think identity verification is a an easy way for them to avoid improving those tools, at the cost of user privacy.
I don't think your comment changes anything about what I'm saying in regards to Discord, but regardless, I also want to point out that it's not just Discord we're talking about: we are seeing a trend towards more services online requiring real-world identities. So we can fight over whether Discord in specific should be grouped in with that trend (I think it should be), but even if you disagree on that point, it still seems pretty clear to me how Stripe's service is going to be used in the future. Do you feel identity verification is also a non-issue for services like Clubhouse and Facebook?
I think the fact that Stripe is advertising both Discord and Clubhouse as early partners says a lot about the types of services they think are going to be attracted to their product.
Because of credit card fraud. I've run services where >5% of attempted transactions were done using stolen credit cards. So we used services that determine the risk of a transaction being fraudulent, and if the risk was too high, we required identity verification.
The alternative was to reject those transactions outright and permanently lose those customers, which is terrible when there is a false positive.
If credit card fraud is high, it doesn't matter whether you are a chat app or a bank app.
Does Discord need to know my identity, or does it need to know that my card hasn't been stolen? If it's the latter, then I'm unsure why Stripe is offering the business access to my passport/license, and I'm unsure why we would want to build a government ID system for Discord instead of a government payment system.
The proper way to do it is to either enforce 3D-Secure or offer passport as an option when 3DS is unavailable, but because ID verification is getting easier and cheaper with services such as this one, there will be no reason to spend extra engineering time to implement solutions such as this one when you can just ask for everyone's passports especially when this also allows you to use the data for marketing purposes or be able to reliably ban "undesirable" people (and "undesirable" in this case doesn't mean "bad" or "illegal", it could simply be someone who uses an ad-blocker or doesn't "engage" with dark patterns like the company wants them to).
There are a ton of legal requirements around you having to verify a person's identify before sending them money. These laws are often put in place to avoid money laundering, etc.
I doubt they'd require every single user to go through the friction of verifying their identity.
Discord are doing it for verifying bot ownership, because bots can do a lot of damage if they're just free to sign up to Discord and start "talking" to people. A good way of omitting bad bots from the network is by verifying and tying the bot to the (verified) identity of a real person.
I run a server with 1,200 people on it - I've never needed to verify my identity. You don't need to verify your identity for using Discord.
Is it?
I am much less charitable than you about whether Discord's bot verification is intended purely for user safety or whether it's a combination of laziness and a way of slowly clamping down control over how users access the service, how it can be extended, and what services/clients can interop.
I disagree that 100 servers is a particularly large number for a popular bot to join, but more importantly I think the threat model you describe illustrates a deeper problem with Discord overall. If the issue is that bots can sign up to Discord and just start talking to people, that's a permissions issue. Why can bots do that? And why is it OK for bots to keep doing that as long as they're in fewer than 100 servers?
So sure, we can have an extremely invasive form of verification, but we could also just... not let bots join random servers in the first place. We're jumping straight to real-life identification in a system that doesn't even support granular control over invites. In my opinion Discord's moderation and user-vetting tools are basically non-existent, so I am at least a little bit skeptical about whether verification is a completely necessary tradeoff between security and privacy.
HN does quite well without requiring anything other than an IP address. So does Mastodon. And mailing lists generally have no way of knowing even that!
Pretty certain HN does way more than this.
(Of course they also have my entire post, view, and vote histories. Those are arguably far more sensitive than any PII I could possibly provide, but I seem to have developed a habit of repeatedly forcing that information on them so I guess that's on me.)
I'm saying HN do anything of this, but I doubt they only look at your IP when you're interacting with the service.
So what? It's a private network and a private service. They can have it function however they like. That's why free market economies work - people will go find something else, or demand something else, should what's available not fit their needs or they feel too restrictive.
Something like Discord can be replicated easily enough by someone with enough money and a decent engineering team. And it's not like there aren't other options already.
> I disagree that 100 servers is a particularly large number for a popular bot to join
I'm not sure what you mean by "100 servers". I guess that's the maximum amount of servers a bot can join?
There are some pretty big servers out there. If a bot can join 100 servers, and they have an average of 10,000 users, then that's literally 100,000 people that can attached with malware, scams, and more.
Are you saying that's not a problem?
> If the issue is that bots can sign up to Discord and just start talking to people, that's a permissions issue. Why can bots do that?
I don't believe they can. I believe the verification process prevents this? I could be wrong.
> So sure, we can have an extremely invasive form of verification, but we could also just... not let bots join random servers in the first place
I don't believe they can.
> ... we can have an extremely invasive form of verification ...
Is it that invasive? Is requiring people to validate their identity before introducing something that has the potential to directly address millions of people all at once really that invasive?
Should my credentials (and character, intention, etc.) by validated before I'm allowed to talk on a radio station listened to by millions of people, or is the (privately owned) radio station being, "extremely invasive" by asking me to validate who I am before they let me use their network?
> Discord's moderation and user-vetting tools are basically non-existent
There are five levels of verification you can select from, ranging from none to highest. The former requires a validated phone be added to their account.
Their moderation tools are pretty powerful. You can create roles that are flexible enough to allow you to create some pretty interesting setups.
What is it about these tools that you feel could be better?
You're commenting under a thread that proposes creating a government service to reduce the implementation costs of identity verification. When we start talking about essentially subsidizing a business practice, then this isn't really about the free market anymore.
But even if it was, criticism is a fundamental part of how the free market works. People are free to advocate against a company's policy, to publicly criticize them, to encourage people not to use them, to argue for an industry to move in a certain direction... the free market has never been a shield against the kind of criticism happening on this thread. The invisible hand of the free market isn't actually invisible, when you see people complaining about companies and making arguments about the overall direction of the market, that is the free market at work.
> Is requiring people to validate their identity before introducing something that has the potential to directly address millions of people all at once really that invasive?
In this context, yes. In a different context, maybe not. But the Internet has different social norms surrounding anonymity, and most people online aren't thrown off by the fact that they might not know the physical identity of someone who makes a website or runs a Twitter account or releases a piece of code/bot.
I think that Discord's policy runs counter to how people expect to consume content online, and I think it's reasonable to describe their request as invasive in the context of Internet norms. You're on HN right now. Does it bother you that the site hasn't asked you for your drivers license yet?
And just as a quick side note on this point, Facebook has been around for long enough that I feel like we should drop the argument that tying accounts to real-world identities inherently prevents abuse or curbs misinformation. Heck, talk radio and cable news has been around long enough that we should probably drop the argument that vetting guests in traditional settings inherently means we'll have less misinformation.
> If a bot can join 100 servers, and they have an average of 10,000 users, then that's literally 100,000[1,000,000] people that can attached with malware, scams, and more. Are you saying that's not a problem?
I think the much more interesting question in your scenario is why Discord thinks it's OK for a malicious bot to target 990,000 people. I don't think 100 servers is a particularly high limit for a popular bot or a meaningful line for when abuse becomes a problem. I don't see how identity verification solves the abuse problem overall when hackers/spammers can just create multiple bots that can target smaller numbers of servers. I think it's really weird to act like this becomes a problem at 100 servers.
> What is it about these tools that you feel could be better?
The ability to create private invites that can only be used by a single person, the ability to require users to be approved before they join your server. The ability to ban words, the ability to block links (or better, the ability to only allow links to certain domains), the ability to block bots outright from joining (what seems to be the entire reason this verification process exists), the ability to easily share blocklists between servers, the ability to hold comments from new accounts in limbo until they're approved.
Some of this can be replicated by setting up your own bots and figuring out some kind of custom role where new users jump through hoops; and that's basically what a lot of servers I run into on Discord have to do. But it's really awful and it's a bad experience and it makes moderation unnecessarily complicated for non-technical users. As a result, most servers don't really set anything up because it's time consuming, so we end up with bad defaults on most servers. And that situation doesn't have to exist. Why do I need to find a bot to ban certain words on a server? That's something that belongs in the settings in a text input. Why do I have to go through this weird song-and-dance with invite codes, why can't I add people by their account ID? Why is there no one-click setting to just block new bots from joining my server unless I specifically grant them permission?
I've joined Discord servers that have these complicated house-of-cards setups where you're entering passwords into dedicated rooms to get granted access to other rooms by moderator bots. It's really bad, moderators shouldn't have to spend hours building custom rube goldberg machine to handle new users. This is stuff that should be configurable within 30 seconds from the settings page.
You mention that you "don't believe they can" block bots from abusing servers this way. But I just do not understand what the technical problem is. If the problem is that bots are joining random servers, and if bots can join my server without my permission, give me a single checkbox somewhere in settings to turn that off.
For the same reason that Facebook required proof that you were a college student. A platform with a barrier to entry and a degree of exclusivity (but not too exclusive), will tend to have higher quality content and interactions than an anonymous forum that anybody (and anybot) can join.
Whether it's a good direction for the internet to be moving in, I have no idea. But it's certainly good business, which naturally makes me suspect it's the wrong trajectory.
Maybe not those two, but your bank does, your insurance company does, your employer does, your business partner does.
There's a lot of places where there's trust placed in a specific citizen and their identity. The "root of trust" of being a citizen is the government, it'd be nothing new really to provide that digitally.
The proof of it being doable are the governments providing electronic ID's for decade or two now. Solving those really hairy problems hundreds of millions of Americans are struggling or encumbered by daily.
Agreed. An example: https://www.realme.govt.nz/
The government (in the US at least) does offer some form of identity services like everify for employment.
The government is using 2FA SMS as your identity (for government services themselves), effectively offloading their liability into the mobile operators. But not really, because the mobile operators are not liable either. So as a little person, you are screwed all around.
If the government were to make an electronic identity, which it needs to for its own services, it might as well be accessible for all so you do not have to trust private businesses with it.
1. I don't trust my government to have better security than anybody else.
2. I'm worried that I would lose the ability to opt out of a government-provided IaaS. Unlike Stripe, and I can't avoid using the government even if I try really hard. They already have my identity, so my privacy is dependent upon whatever their current policy happens to be. I do not trust unknown future administrations not to sell my data to the highest bidder.
3. The U.S. government has an... uneven track record delivering services and software, especially when there is no competition.
Those are my anxieties: what are the advantages to this approach that I'm not seeing?
It is all the same reasons the government does not outsource issuing of passports. It needs to be from an official source with legal protections.
To make it even more complicated, regulators often hold contradictory views. They want to see increased safety, but in the same breath will announce actions against companies for violating privacy. This is a super-difficult balance to strike.
Specifically for Stripe, I trust them. So if I see that a new start-up is using them rather than rolling their own solution, that increases my trust. But it means there is now a big giant server in the cloud with millions (billions?) of identity documents that is worth a lot of money for hackers.
Note that Stripe allows their customers access to the "captured images of the ID document, selfies, extracted data from the ID document, keyed-in information"[1]. So you still have to trust any company using Stripe not to download, store, and later leak your personal information, and you also have to trust them not to let their Stripe API token be compromised and exploited by identity thieves.
[1] https://support.stripe.com/questions/managing-your-id-verifi...
The problem with this is that the user isn't trusting Stripe today, they are trusting Stripe today, and all future Stripe managers and owners until the user dies and no longer cares. That's a big bet! Bad CEOs and sales happen.
Has anyone told you they are really happy about it? I haven't heard someone say that. Most users have no idea about it.