“Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.”

48 points

I don’t care what you say, Discord is terrible.

permalink
report
reply
26 points

It’s just like IRC but with privacy violations and ads!

permalink
report
parent
reply
5 points

More like Mumble, but with privacy violations and ads

permalink
report
parent
reply
4 points

And without an ability to host the network yourself!

permalink
report
parent
reply
52 points

lol@ this. My bet what is actually happening: cost cutting or future nitro feature.

permalink
report
reply
88 points

This is… annoying. I get the intent for malware, but honestly it’s a BS reason. The content will just be uploaded elsewhere. But what this will do is drastically lower their storage cost under the guise of… not even user safety, more “slightly inconveniencing malware writers.”

permalink
report
reply
7 points

Yes, it’ll be uploaded elsewhere. That’s the whole point.

Discord doesn’t want to host any of this data, they don’t want to be connected to criminal activity. It makes sense.

Also, while it might slightly lower their storage costs (if the hackers move elsewhere), if you send a file to someone, it’ll still stay on Discord’s servers. Only difference is the link to said file - it’ll only be valid for a day, and then you’ll have to use a new one (in a way that’s probably transparent to the user)

permalink
report
parent
reply
5 points

The goal here is to make it difficult to link to things uploaded to discord from outside of discord. The malware reason is BS. If they wanted to curb malware it would be as easy as making it a nitro feature. What that doesn’t fix is all the people piggybacking on discord as a free CDN.

Discord isn’t even wrong for doing this. I just resent their dishonesty.

permalink
report
parent
reply
1 point

Not sure rolling it into Nitro would be worth the effort, I’d consider that quite complex personally

permalink
report
parent
reply
9 points

Trying to keep those classified documents on the DL for home grown radical terror.

permalink
report
reply
14 points

Honestly, I’m okay with this at least until they fix the fact that all shared files are accessible without authentication. Granted, you still had to get the link before downloading an uploaded file, but the fact that there was no authentication required to download a file uploaded to Discord was pretty surprising.

permalink
report
reply
0 points

What is a password? A string of characters. What is a link? A string of characters.

If you make it long enough, it’ll be impossible to guess one.

Your files are safe

permalink
report
parent
reply
1 point

You still need to know magical numbers to download file.

permalink
report
parent
reply
1 point

And a LOT risky

permalink
report
parent
reply
3 points

It’s probably also way cheaper to do it that way. As far as I could tell when I checked in on it some time ago, most of the content goes through a Cloudflare proxy straight to a GCP S3-compatible bucket.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 3.6K

    Monthly active users

  • 3.3K

    Posts

  • 71K

    Comments