Hacktivists tried to find a workaround to Discord’s age-verification software, Persona. Instead, they found its frontend exposed to the open internet, and that was just the beginning.

https://www.therage.co/persona-age-verification/

Hackers Expose Age-Verification Software Powering Surveillance Web

Three hacktivists tried to find a workaround to Discord’s age-verification software. Instead, they found its frontend exposed to the open internet.

The Rage
@evacide Discord is carrying on like their previous age verification vendor didn’t leak a bunch of users’ sensitive data (because they were retaining said data which Discord claimed they weren’t going to do).
@evacide Why am I not surprised by the links with federal agencies? It's relentless 🫩
@evacide If it has corporate police state, you can be sure it has Peter Thiel’s fingers on it!
@evacide Persona is now non grata?
@aktbar I am extremely disappointed this was not the title.
@evacide  There is a security researcher called Celeste, just like meee! Weirdly enough, that makes me happy 

@evacide

"""
Persona’s exposed code compares your selfie to watchlist photos using facial recognition, screens you against 14 categories of adverse media from mentions of terrorism to espionage, and tags reports with codenames from active intelligence programs consisting of public-private partnerships to combat online child exploitative material, cannabis trafficking, fentanyl trafficking, romance fraud, money laundering, and illegal wildlife trade.

Once a user verifies their identity with Persona, the software performs 269 distinct verification checks and scours the internet and government sources for potential matches...
"""

So to keep kids safe from online predators, we're willing to *horribly* invade their privacy and sell all their data to predators? I see the system is working as intended 😮‍💨

@alice @evacide American 3 letter agencies are the biggest predators on the internet. scary shit.

@tootbrute @alice @evacide

> a Peter Thiel-backed venture

No need to read further.

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] That's why *"#KYC IS THE ILLICIT ACTIVITY!"* - I mean, there's a [*trivial bypass*](https://www.youtube.com/watch?v=5LsF4FF6gO4) but #Discord itself is garbage!

Infosec.Space

@alice @evacide i juste read and article by @Ivovanwilligen about persona and if he doesn't know about all this well now he does !

His article : https://thelocalstack.eu/posts/linkedin-identity-verification-privacy/

@alice
...and I'm pretty sure, if your name and picture is on the right list, your location will be hit by a hellfire missile fired from a reaper drone after you performed mandatory age verification. America! Fuck, yeah!
@evacide
@alice @evacide What a surprise. "Child protection" that can't protect children but harms everybody. I would never have thought this possible!

@evacide Ah yes, "let us protect children by scanning their faces". What could possibly be wrong??? 🤡

“the software ‘flags you as a “suspicious entity” based on your face alone’ …”

Yay! Phrenology 2.0!

@evacide
We won't surveill you
And if we do it won't be that bad
And if it was, at least it's secure
And if it' not we didn't mean it
And if we did you deserved it
@evacide AI is becoming the new infamous punch card system.

@evacide and meanwhile the Australian government is claiming credit for protecting children by standing up to social media companies to force them to use this kind of tech.

I’m sure the pressure is in the opposite direction.

@ollicle @evacide

What Australians are in rhe Epstein papers?

@kevinrns I'm sure we'll find some 😬 we have enough decadent superrichies
@ollicle @evacide

@ollicle @evacide Yep. It's brilliant from a certain perspective. Horrifying, sinister, but with a certain genius.

The tech firms get to say "Oh, no, the horrible government is making us do this. Oh well. Now give us your identity documents."

The governments get to give the appearance of responding to (genuinely) grieving parents, and say "we're protecting the children" which is game over for any alternative voice. All the while receiving funding (directly or indirectly) from the tech firms that created the problem or the supposed solution, or their fellow travellers.

And parents get to believe their children's safety is taken care of.

@evacide l, “they took the most powerful communication technology in human history and turned it into a slot machine that makes you sad. We're all rats in a skinner box pressing the lever for pellets of validation.”

Yup

This level of centralisation of data is so so dangerous. Putting all our eggs in one basket digitally makes for a very inviting target, but this sort of infrastructure also concentrates power.

Knowledge is power, and this level of control can easily calcify our political systems and eat away at democracy.

@evacide Amazing how people do everything to not use free software!
@evacide
There is an frightening thread about the use of Person for the LinkedIn verification
https://mastodon.social/@bsletten/116112393904621126
@evacide surely Discord's third age-verification partner will be completely TRUSTED and DEPENDABLE and not at all part of the Torment Nexus being built around these services.

@evacide if something is free, never forget to ask who pays for it, who benefits?

I personally think it's great, though, that there are also people striving _for_ a better internet. That gives me hope. 🙂

@evacide The Kafka-Machine is here.

@evacide
One of the many reasons to be against #ageverification software

It gives the wrong people & companies tons of data, often #biometric ones

Therefore we transfers #power exactly the wrong people & #corporations

And as we can know latest since #Edwardsnowden companies do share data with governments

The cornerstone of the #chinese #surveillance #state is #realnameregistration

Don't give #biometrics to #evilcorp, especially not for cheap thrills

Do not hand data to #fascists

#resist

@evacide just don't use #discord and refuse to #ID as a matter of principle!

https://infosec.space/@kkarhan/116114248435064645

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] That's why *"#KYC IS THE ILLICIT ACTIVITY!"* - I mean, there's a [*trivial bypass*](https://www.youtube.com/watch?v=5LsF4FF6gO4) but #Discord itself is garbage!

Infosec.Space

@evacide

I am noticing a pattern that security for unethical companies appear to have strong vibe coding traits

@evacide Persona? #Persona deserves its own social movement in opposition to its existence.