Remember you can trust Discord with your driver’s license for verification, I’m sure they won’t accidentally store them in a plain text open API call or anything.

    • shininghero@pawb.social
      link
      fedilink
      English
      arrow-up
      92
      ·
      edit-2
      23 hours ago

      If I’m reading it right, it’s kinda like how that one guy “hacked” 70,000 robot vacuums. Bad scope limits.
      Game uses token to do the rich presence stuff, and instead of just getting a confirmation back, it gets everything.

        • Quetzalcutlass@lemmy.world
          link
          fedilink
          English
          arrow-up
          41
          ·
          edit-2
          22 hours ago

          Not necessarily. Developers choose what permissions their authorization token has when they register it with Discord. In this case the game asked for an auth token with all permissions, so the game connects to Discord with the same access levels as your actual login.

          • DreamButt@lemmy.world
            link
            fedilink
            English
            arrow-up
            27
            arrow-down
            1
            ·
            17 hours ago

            Yeah that’s what the person before me said. I’m saying that the fact it’s possible at all is a horrible violation of privacy

            • Armok_the_bunny@lemmy.world
              link
              fedilink
              English
              arrow-up
              7
              ·
              9 hours ago

              There are legitimate reasons to ask for an “all permissions” token, such as setting up and using a third party client. A game is not one of the things that should be asking for that though.

              • Blackmist@feddit.uk
                link
                fedilink
                English
                arrow-up
                1
                ·
                3 hours ago

                In any case it sounds like a reason to actually read what the oauth login screens are actually telling you…

  • CosmoNova@lemmy.world
    link
    fedilink
    English
    arrow-up
    75
    ·
    23 hours ago

    Lmao. A game accidentally receiving your Discord DMs and credentials if you sent a crash report just because game devs integrated basic Discord functionality is insane. But kind of what you have to expect from Discord and why I’ll never enable Discord integration.

  • chirospasm@lemmy.ml
    link
    fedilink
    English
    arrow-up
    43
    ·
    23 hours ago

    Issue seems to be with Discord’s SDK, not Embark. Good on Embark responding quickly by patching something Discord should be responsible for, though.

    • poke@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      29
      arrow-down
      2
      ·
      23 hours ago

      Well… They quickly patched it when it went public. It was reported to them a month ago.

      • fahfahfahfah@lemmy.billiam.net
        link
        fedilink
        English
        arrow-up
        14
        ·
        22 hours ago

        Based on a post from him he had difficulty actually getting to their bug bounty report system, which is hosted by another company. So sounds like until it was made publicly they hadn’t actually received the report

  • Ms. ArmoredThirteen@lemmy.zip
    link
    fedilink
    English
    arrow-up
    8
    ·
    18 hours ago

    This shit is why I only use discord on the browser and try not to directly link any accounts anywhere. Anything sniffing around my executables and talking between them is sketchy. Anything asking for access to my other accounts is sketchy

    • popcar2@piefed.ca
      link
      fedilink
      English
      arrow-up
      10
      ·
      22 hours ago

      I’ve been using Fluxer recently. It’s been pretty nice since they migrated the servers, and as soon as self-hosting and federation gets added (which is top priority according to Herman), I hope people will switch over.

      • Coelacanth@feddit.nu
        link
        fedilink
        English
        arrow-up
        9
        ·
        22 hours ago

        Federation and easy self hosting will be killer for sure. There is already a Discord migration bot and a Discord-Fluxer bridge bot I think. Future is looking hopeful.

      • Coelacanth@feddit.nu
        link
        fedilink
        English
        arrow-up
        7
        ·
        20 hours ago

        Matrix still misses a ton of features to be a direct 1:1 Discord replacement. On top of that Fluxer has a familiar UI (it’s essentially just a Discord clone) and is simpler in onboarding (Matrix is still techy).

      • naught@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        18 hours ago

        Fluxer is a direct Discord drop-in. Matrix requires a lot of setup and tweaking to get high throughput video. Plus the default server and client are bloated and buggy

          • naught@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 hours ago

            I just assumed the python one would be more bloated inherently, and that is the common theme I’ve heard about matrix specifically. I tried using an alternative server supposedly lighter on resources but just never finished setting up ¯\_(ツ)_/¯

            I didn’t test the default server myself tho

  • Fishnoodle@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    edit-2
    23 hours ago

    All I did was take the information and put it in a paper bag and leave it on the side of the road. If a bad person picked up the bag and did bad things with the information, that’s not my fault!

    /S

    • CosmoNova@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      23 hours ago

      It‘s more like some business partner keeps hiding pages of personal information of customers in the work they submit to you. Then someone finds out you have all that information and now it‘s your job to clean up the mess. If you have friends like Discord you don‘t need enemies.

      • Katana314@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        23 hours ago

        It’s a good point around the recent CA age verification laws: Sensitive data (is this user a potential target for predators?) can’t be leaked if it was never recorded in the first place.

  • BaraCoded@literature.cafe
    link
    fedilink
    English
    arrow-up
    5
    ·
    23 hours ago

    It’s more than time to move away from Discord.

    So far, on the matrix protocol front, Commet is a good candidate.

    On the XMPP protocol front, Movim is… moving forward, developping a clone interface that is promising.

    There are others, like Stoat and Fluxxer, but I don’t know much about them.

          • BaraCoded@literature.cafe
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            4 hours ago

            Maybe, but when you’re looking to make discord users migrate to a safer/saner app, you need the new app to be as discord-like as possible.

            Same thing for an OS (thus DE) change, i’d recommend KDE above all else to a windows user because it’s the DE that is the most windows-adjacent.

            • MajinBlayze@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              18 minutes ago

              I understand the impulse, but I think it’s wrong for a few reasons:

              1. Discord didn’t become popular because of its ui. It became popular by lowering barriers to entry.
              2. I don’t think you’ll get a critical mass of people by being “discord but less evil”.
              3. A better ui or ux could be a genuine selling point, or a way to distinguish it

              Sure, kde shares a lot of the conventions of Windows. But it’s also very willing to do its own thing.

  • mr_noxx@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    23 hours ago

    To be honest, this is why I immediately disable integrated voice chat for any games that have it and use a third-party voice chat app with end to end encryption for chatting (like Signal).

    • fahfahfahfah@lemmy.billiam.net
      link
      fedilink
      English
      arrow-up
      10
      ·
      22 hours ago

      This didn’t have to do with voice chat, it was the in-game integration with discords SDK that was just supposed to be for including your discord friends in your in game friends list and being able to invite them.