Hacker News new | past | comments | ask | show | jobs | submit login

Is it not possible for discord to mitigate this vulnerability?



I don't know the specifics, but I'd assume not, Discord has made big steps recently in stopping this sort of malicious activity by adding the "Report Spam" feature as well as creating their own phishing link database to help detect spam in private messages.

Discord knows it's a big issue and I'd hope they've attempted to mitigate the malware but there's no way to stop the actual injection, so really all they can do is code shuffle frequently to make the injected code redundant, but that'd rely on doing releases frequently and hoping everyone updates just as frequently.


I'm glad to hear they're taking things more seriously. They banned my original Discord account when I showed them a critical bug that allowed for remote viewing of another user's activity, both in real time and in logs.


Yeah, Discord is still just a bad with that. If you join a server and find it's hosting illegal material and proceed to report the server, Discord will ban all members of that server, which includes you. It's created an environment in which no one wants to report anything to Discord, especially since if you appeal your ban you won't get unbanned as you were in the server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: