132
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 10 Sep 2026
132 points (98.5% liked)
Privacy
10763 readers
251 users here now
A community for Lemmy users interested in privacy
Rules:
- Be civil
- No spam posting
- Keep posts on-topic
- No trolling
founded 3 years ago
MODERATORS
There is no safe way to aggregate such identity information in an internet-connected database. They always get breached. Discord tried to do this and all the collected IDs got stolen almost immediately.
https://arstechnica.com/tech-policy/2026/02/discord-faces-backlash-over-age-checks-after-data-breach-exposed-70000-ids/
No party can be trusted to store identification information safely.
The idea is that they don't store it at all.
"They" who? If the party checking the IDs does not store the information, then they must be cross-checking them against a reference database, which must be online somewhere.
They check a signature, not a physical passport.
Uh huh, and where does the signature come from?
It doesn't matter how many process steps or layers of obfuscation you put in the way, at some point the verification ends at a database of original ID information which must be network connected in order to be useful. No one can be trusted to hold such a database safely.
No
O...k... sure, if you say so buddy.