• Broken@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    ·
    4 hours ago

    My take on this is a little more fundamental than the whole ID/age thing. We all knew this would happen, and why? Because nobody has addressed the first problem. Security is only as strong as the weakest link, and companies are not transparent with customers.

    Companies spell out in their Terms and Privacy statements that they have Affiliates that data gets shared with. And they want you to accept them all blindly, without clarifying who they are and what they do.

    Even here, with a reported breach, they are not naming them and just calling them “third party”. So they screwed up and many people have their information and IDs out in the wild because if them, but we don’t even get to know who they are?

    His are we to trust a company of we don’t know who they’re in bed with? How are we to rate their security and assess our risk of using their service without all the information?

    As far as I can tell Discord handled it pretty well as far as breaches go. But maybe if I know they are using a shit company as one of their vendors I might think twice about using them.

    Its the same logic as the next article in my feed, where crunchyroll is getting pushback from the subtitle service they are using. And that’s not even their own security in mind. People make choices based on what companies do, so be transparent with it all and we will have the warm fuzzies if things match up. If they don’t then the company gets customer feedback so they can adjust.