Phishing using Discord webhooks will be harder.

“Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.”

This is… annoying. I get the intent for malware, but honestly it’s a BS reason. The content will just be uploaded elsewhere. But what this will do is drastically lower their storage cost under the guise of… not even user safety, more “slightly inconveniencing malware writers.”

@LufyCZ@lemmy.world
link
fedilink
English
710M

Yes, it’ll be uploaded elsewhere. That’s the whole point.

Discord doesn’t want to host any of this data, they don’t want to be connected to criminal activity. It makes sense.

Also, while it might slightly lower their storage costs (if the hackers move elsewhere), if you send a file to someone, it’ll still stay on Discord’s servers. Only difference is the link to said file - it’ll only be valid for a day, and then you’ll have to use a new one (in a way that’s probably transparent to the user)

Solar Bear
link
fedilink
English
510M

The goal here is to make it difficult to link to things uploaded to discord from outside of discord. The malware reason is BS. If they wanted to curb malware it would be as easy as making it a nitro feature. What that doesn’t fix is all the people piggybacking on discord as a free CDN.

Discord isn’t even wrong for doing this. I just resent their dishonesty.

@LufyCZ@lemmy.world
link
fedilink
English
110M

Not sure rolling it into Nitro would be worth the effort, I’d consider that quite complex personally

Dandroid
link
fedilink
English
6810M

I wonder if McAfee changing their name to Trellix to escape how much the general public hates them will work better than Comcast rebranding as Xfinity.

@mihnt@lemmy.world
link
fedilink
English
310M

deleted by creator

Dandroid
link
fedilink
English
710M

Idk, but this issue was discovered by “Trellix” which is McAfee.

@SheeEttin@lemmy.world
link
fedilink
English
3810M

The general public doesn’t hate McAfee that much, so I’d bet it’ll work. Heck, I work in IT and I didn’t even know about the rebrand (mostly because I engage with McAfee as little as possible).

probably about as well as Twitter becoming “X, formerly known as Twitter”

Scrubbles
link
fedilink
English
1410M

Yeah let’s keep that going here. From here on our whenever I see Trelix I will say “Trelix, the brand fomally known as McAfee.”

@theolodger@feddit.uk
link
fedilink
English
210M

Or Evri, the brand formerly known as Hermes

@Jumuta@sh.itjust.works
link
fedilink
English
110M

or just call them mcafee, twitter, facebook, etc

Scrubbles
link
fedilink
English
710M

Yes, but I like this because it ingrains in people’s heads that when they hear Trelix they should think McAfee, to make that connection. Like with Xfinity, they don’t want that connection made, they want people thinking “Oh I don’t have that crappy Comcast service, I have Xfinity”. I’ll be saying it this way to show people that they’re the same thing

@Jumuta@sh.itjust.works
link
fedilink
English
210M

fair point, maybe I’ll do that from now on

@NegativeInf@lemmy.world
link
fedilink
English
910M

Trying to keep those classified documents on the DL for home grown radical terror.

@Flex@lemmy.world
link
fedilink
English
1210M

Interesting news but I don’t really get how this is self-hosted?

paraphrand
link
fedilink
English
10210M

I always thought it was a bad idea for people to treat Discord as a free CDN.

I mean it worked for long enough 🤷‍♂️

@nephs@lemmy.world
link
fedilink
English
410M

If its going away now, it isn’t quite long enough…

Possibly linux
link
fedilink
English
4810M

I don’t care what you say, Discord is terrible.

Nik282000
link
fedilink
English
2610M

It’s just like IRC but with privacy violations and ads!

And without an ability to host the network yourself!

@uis@lemmy.world
link
fedilink
English
510M

More like Mumble, but with privacy violations and ads

Chewy
link
fedilink
English
1510M

It’s an annoying change for anyone using discord to share files outside of it’s closed platform but doesn’t affect most people.

I wonder whether bridges for matrix have to be fixed or if they’re already editing messages bridged to matrix to the new url.

Depends on how it’s implemented. Anyone using a “media proxy” will see their discord bridged media probably fail to load (outside of possible caches) after a day. Anyone who has their bridge configured to reupload discord media to their homeserver should see no change.

@ndguardian@lemmy.world
link
fedilink
English
1410M

Honestly, I’m okay with this at least until they fix the fact that all shared files are accessible without authentication. Granted, you still had to get the link before downloading an uploaded file, but the fact that there was no authentication required to download a file uploaded to Discord was pretty surprising.

It’s probably also way cheaper to do it that way. As far as I could tell when I checked in on it some time ago, most of the content goes through a Cloudflare proxy straight to a GCP S3-compatible bucket.

@uis@lemmy.world
link
fedilink
English
110M

You still need to know magical numbers to download file.

@LufyCZ@lemmy.world
link
fedilink
English
010M

What is a password? A string of characters. What is a link? A string of characters.

If you make it long enough, it’ll be impossible to guess one.

Your files are safe

@kalkulat@lemmy.world
creator
link
fedilink
English
110M

And a LOT risky

@justaveg@lemmy.world
link
fedilink
English
5110M

lol@ this. My bet what is actually happening: cost cutting or future nitro feature.

Create a post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

  • 1 user online
  • 279 users / day
  • 589 users / week
  • 1.34K users / month
  • 4.55K users / 6 months
  • 1 subscriber
  • 3.49K Posts
  • 69.8K Comments
  • Modlog