Home › Forums › News, Rumours & General Discussion › [Discord] Discord Launches Teen-by-Default Settings Globally › Reply To: [Discord] Discord Launches Teen-by-Default Settings Globally
More proof that these claims of ‘safe and secure’ cannot be trusted:
https://fortune.com/2026/02/24/discord-peter-thiel-backed-persona-identity-verification-breach/
(1) Nearly 2,500 accessible files were found sitting on a U.S. government-authorized endpoint, researchers pointed out on X. The files showed Persona conducted facial recognition checks against watchlists and screened users against lists of politically exposed persons.
Let this sink in for a minute.
This was not a mere ‘age verification’ tool.
This is an intel gathering tool for governments and others alike.
(2) In addition to verifying a user’s age, researchers found Persona performs 269 distinct verification checks, including screening for “adverse media” across 14 different categories such as terrorism and espionage. It then assigns risk and similarity scores to user information.
Your face will be tagged as someone who may or may not look like a wanted terrorist … or possibly worse.
You don’t get any notification.
You don’t get to object to false positives.
You will be on a list … and anyone with brain will know what happens when those lists are used by bad actors who will have no reason to want to check for accuracy.
And to reiterate how dangerous this is:
“In a statement from Oct. 9, 2025, the company said the attack was “not a breach of Discord, but rather a breach of a third party service provider, 5CA.” Discord stated the breach affected only users who communicated with the company’s Customer Support or Trust and Safety teams.”
Yes … technically Discord did not suffer a security breach.
This happened at the 3rd party they were using.
And why were they using a 3rd party ?
It’s because the kind of security requirements to be competent at this is not Discord’s (or Reddit or Roblox) primary business.
You do not want to re-invent the wheel, because you are likely to make the same mistakes that more established companies have fixed.
Unfortunately this also means that these companies get an easy way out if such a data breach occurs, because they can point fingers at someone else.
True … Discord may have cut ties with Palantir after a month.
But only after they were discovered and not because Discord decided that whatever Palantir was doing was bad for their customers.
https://x.com/vmfunc/status/2023523892208517220
Do not give these guys any data.
Do not trust them when they say ‘we shall delete it’
Because while they may technically delete it … the damage has already been done.
Your data is in the system used by 3rd parties as either an actual ID or proof of an actual person.
