Your Kid's ID Photo Just Became Someone Else's Database
Your Kid's ID Photo Just Became Someone Else's Database
This episode is based on our article:
Read the full article →Your Kid's ID Photo Just Became Someone Else's Database
Full Episode Transcript
Tens of thousands of Discord users handed over photos of their government I.D.s to prove their age. Then the company doing the checking got hacked. Those I.D. images — driver's licenses, passports — ended up exposed. And the people affected never chose that vendor. The app did.
If you're a parent, this one lands close to home
If you're a parent, this one lands close to home. Because a new law just made moments like that far more common. The Supreme Court cleared the way for Texas to enforce a rule that forces app stores to check how old you are — and get a parent's okay before a kid can download certain apps. On its face, that sounds like child safety. But the way it actually works could put your child's identity documents into systems you've never heard of. So the real question is this — when the app asks to verify your kid's age, where does that photo actually go?
Start with what Texas actually requires. App stores now have to confirm a user's age. For minors, they need parental consent. To prove age, platforms often ask for a government I.D. or a face scan. And here's the part that matters for your family — the platform usually doesn't do that checking itself. It hires an outside company.
That outside company is where the risk concentrates. When millions of people upload I.D.s to one vendor, that vendor becomes a giant vault of sensitive data. The Discord breach is exactly what that looks like when it fails. One third party. One weak point. Thousands of real people exposed. For the rest of us, it means your kid's I.D. is only as safe as the least careful company in the chain.
Now, Texas did try to protect people. The law says platforms must delete age data once verification is done. Sounds reassuring. But policy experts point out a problem — those outside vendors work for many clients at once. They have a business reason to keep and reuse identity data for efficiency. Once your child's photo lands in that shared pool, proving it got deleted is nearly impossible.
The Bottom Line
And this isn't just a Texas story. About half the states already have similar age-check rules. Analysts expect age verification to become a default part of the internet within the next year or so. Which means this Texas decision is less a single ruling and more a starting gun. The next time your family downloads almost anything, a verification prompt may be waiting.
Here's the twist most people miss. The court required verification — it never required privacy. Judges said platforms must check ages. They said nothing about how. So the fastest, cheapest path wins, and that path runs straight through your child's data. Safer options exist. Some systems can analyze a face just long enough to answer one question — is this person old enough? — then throw the image away, keeping only a yes or no. Engineers are even building shared standards, like one from the I.E.E.E., to make that kind of privacy-first design normal. The technology to protect kids without hoarding their identities already exists. Most companies just won't choose it unless they're pushed.
So here's the whole story in plain terms. A new law makes apps check your kid's age, and to do it, they collect I.D.s and face scans. Most hand that job to outside companies, and when one of those companies gets hacked — like Discord's did — your child's documents leak. The safer way exists, but nobody's forcing anyone to use it yet. Whether you're a parent tapping "I agree" or just someone who's ever uploaded an I.D. to prove who you are, this decides where a piece of you gets stored. The full story's in the description if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
That "Prove You're 18" Pop-Up Is About to Be Everywhere — And Fakes Are Coming for Your Kid's ID
A major identity verification company left its login credentials sitting exposed online for over a year. In that time, anyone who found them could reach names, birthdates, national ID numbers — and photos of people's actu
PodcastThat Annoying "Verify Again" Text? It's Catching Fraudsters Using Real ID Numbers
Researchers at deepidv looked at four million fake identities. Nearly a quarter of them used a real government I.D. number — a legitimate number, pulled from a real record — paired with completely invented personal details. <break time="0.5s"
PodcastYour Face Is Forever. A Judge Just Ruled Companies Can't Hide What They Did With It.
A judge just ordered a company to hand over its deletion logs. Not its marketing. Not its emails. The quiet, boring records that show exactly when it erased people's faces from its systems. And that o
