Guess I'm Done with Discord
wowana.me
wowana.me
I pay them $99 a year, and their customer service treated me like shit for this. What do I care if someone hacks my account and destroys the large community that I moderate? That's their problem, not mine. But I doubt they care.
The services aren't free of course, they pay their overhead and costs by re-selling the data they collect about their users. And as other sources of revenue (like ads) have lost value the data service has filled in. And since the data buyers know that the service provider is in a weak negotiating position they keep pressing on them to get more and more datamilk out of their data cows for the same amount of money.
The pressure is on to create a low friction pay as you go service for these things that don't extract data.
So relating back to the post, their justification doesn’t necessarily make it right, but I think it’s incorrect to attribute it to a malicious cause.
I've lost count of the number of times I've tried to log in to, I dunno, eBay or whatever, and computer says no, and I have to call some bloody line and speak to someone who hates their job and doesn't understand what I mean when I talk about IP addresses.
I wish that these services had a way to check some box and say "look, I really know what I'm doing, let anyone with the correct password/SSH key/whatever in".
If it gets hacked, _then_ I can go through all of that shit. In this case we're talking about a bloody chat server for christ's sake.
I've probably made about ten discord accounts with random names to join some one off server, then gone back to IRC, because it just works.
But yeah, discord used to be held in high standards by me and plenty of other gamers, but they have made it clear that they cannot handle tough situations, and dont really care about their userbase. Someone should start a privacy focused phone number as a service, acces to texts online and through an app. Allow people to basically have a spam phone number that they can give out to online services, but make people pay for it obviously. Like 10minutemail but long term and for texts only.
Captcha v3 is even worse in this regard, because it silently flags you while appearing to let you in...
I also don't understand the 2FA point, that says nothing about your accounts' intentions.
The account history is an interesting point... if you have a long-standing history with no reports of inappropriate actions, they should factor that in somehow into their algos.
Short answer: I'm a privacy activist. That should be a valid enough reason for this context.
>I also don't understand the 2FA point, that says nothing about your accounts' intentions.
No, but it shows my account is secured from intruders, which means reCAPTCHA is just an additional nuisance to me, the legitimate account holder.
>The account history is an interesting point
Yeah, and they just glance right over it. It doesn't mean anything for my case that I've been an active user with this account for almost two years (I had a previous account for a bit and then left Discord because I was not in any communities worth sticking around for). Never have I done anything wrong on Discord's platform; haven't uploaded any lolis or evaded any bans (I believe I was only banned from one guild, even). They just don't seem to want me as a user, and that's fine.
> I will be communicating with a couple communities with which I'm involved to explain that I am unable to use Discord
Does this person not have a phone? 'Unable' seems like a stretch. If this person said, "I don't want to provide my phone number to Discord, so I'm going to stop using it" I'd understand.
Their opening email also strikes a pretty aggressive tone -- calling Discord anal, insulting, "spit in my face" then goes on to make a number of demands of the company? I'm not super surprised the customer service rep on the other side didn't go out of their way to help.
In that sense, bureaucracies are aggressive by default; that they use friendly language doesn't change this.
Imagine that one day, your car locks you out, and there's a smiley face and it says "oh hey, just call this number dude". Is that any less aggressive simply because it's 'friendly'? Of course not.
In many ways it's worse - because it's almost sarcastic (it's not _really_ that way, of course, because the customer support agent in this scenario is a robot, but it sure feels like it).
People get mad and yelling about a war, absolutely unconscionable and should be disregarded and ignored, however thousands of people dying in said war, well at least nobody said bad words publicly about it, everyone was polite and civil when the decision that they should all die was made.
Just because some automatic process has chosen to discriminate against you, for whatever reason (that mysteriously nobody ever seems to be able to disclose), doesn't make it any less of a hostile, uncivil act.
But yet getting angry about it puts you in the wrong?
Complete garbage.
As a light and funny example, Discord doesn't comply with the OpenSSL license.
In what way? Have you reached out to Discord to make them aware? They seem fairly committed to open source from everything I've read.
They know that they are violating this license; they don't care. They are free to clean up their act at any time.
[0] https://www.openssl.org/source/license-openssl-ssleay.txt
* 3. All advertising materials mentioning features or use of this software * must display the following acknowledgement: * "This product includes cryptographic software written by * Eric Young (eay@cryptsoft.com)"
I'm not a lawyer, but my interpretation of "this software" is OpenSSL, which wouldn't apply this clause to all advertising of discord features. It would be when they run advertisements that reference discord features that rely specifically on OpenSSL features. Which, isn't going to be that often, right?
> They know that they are violating this license; they don't care. They are free to clean up their act at any time.
Is this a known issue that's been brought up before? I've never heard of it, and would be interested to read up on it! I'm especially curious as to their response.
> Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
As for condition 3, I am unable to locate any marketing materials which mention the usage of OpenSSL. However, if any such material exists that is in non-compliance we are very interested in ensuring that we are in compliance.
Hopefully you don't get too much grief for being a female on the internet with an opinion :-/
Currently Discord doesn't require a number if you use your home IP to connect, but that could change at a moment's notice with their opaque methods of operation. I've used Tor with Discord for months without any issue until recently. So, it's probably better not to start using it now than to take that risk and be upset when they do find a reason to demand your personal information.
Also, if your blog isn't meant to be read by people that don't know the context of your life already, making it public seems like an odd choice, especially when you say things that might be taken the wrong way.
Also. If you really didn't care about what others said about it, why are you responding to such comments and displaying indignation? Why are you here at all?
And re: the blog being pink, do you really think it's because there's an "adults/men can't like pink" prejudice going around on this very liberal site? Or maybe it's because pink (unless done right) is like neon green: not a very aesthetic choice?
>if your blog isn't meant to be read by people that don't know the context of your life already
People who have followed me online enough to have my blog in their feedreader or bookmarks, they'll all know why I'm approaching the issue how I do. You seem to blame me for your and others' eagerness to jump into discussions about things I didn't even link on here. Hacker News was never my target audience. That aside, reading the newer comments I can see a lot of people who do actually take a bit more time to see my background and develop a fuller opinion on my blog piece, so evidently I already must have all the information needed to come to an informed conclusion about what I write. Maybe it's just a problem for most people to assume ill-intent out of my writings that aren't even meant to attack anyone.
>why are you responding to such comments and displaying indignation? Why are you here at all?
If someone defames your image, you're telling me you would just shut up about it? You'd just let people keep kicking you in the gut while you're minding your own business? Again, stop excusing your negative actions.
>not a very aesthetic choice?
https://wowana.me/about.xht which is very clearly linked on the site, explains that I'm happy with the theme. It's my website; it only matters if I myself am content with how it looks. There's reader mode in many browsers now, I offer an Atom feed for consumption in a reader that strips that styling, and better yet, people like you don't have to read my site if you have nothing good to say about it.
If I say "I am unable to do X" that might mean "My conscience compels me to refuse to do X" or "I literally cannot do X". Both interpretations are valid.
> Their opening email also strikes a pretty aggressive tone -- calling Discord anal, insulting, "spit in my face" then goes on to make a number of demands of the company? I'm not super surprised the customer service rep on the other side didn't go out of their way to help.
I suppose I agree with you that the email is rude. Then again, I don't mind giving out my phone number and email even though companies are using these things to track me, build a profile, and spam me. I'd rather that they didn't; I think it's corrosive behavior. But it doesn't affect me much and so I put up with it. Point is, the writer of these emails could be seen as heroic because he or she has principles and is refusing to back down (despite the rudeness).
Like I said, I have similar principles but I'm not too fussed about them. This worries me sometimes. This level of invasion of privacy isn't the hill I'm willing to die on but I hope there is a hill I'd die on. If not, I'm an unprincipled person.
People underestimate how hostile the internet truly is. I run a small website for a friend-- I'd say 90% of our traffic is spam/exploit fishing. I have at times blocked whole countries because we didn't have any business in that region and the abuse would not stop.
And yes, you're right about Tor IPs being flagged at greater frequency. That's fine, but I've had a clean account for over a year and have had no prior incidents. And a lot of abuse comes from IP addresses not related in any way to Tor, as well.
I've had my own issues with Lyft that are similar. Banned from using their service even though I've never actually ordered a ride from them. Banned upon sign up. No review, no appeal, they don't even follow their own terms of service.
I'm not one to normal advocate for government regulations and oversight, but there's way to much consumer abuse for these Internet age services. Consumer protections can't come soon enough.
Had a similar experience with Uber, except that Uber actually eventually fixed it. Lyft was… unhelpful.
Digital Ocean banned be as soon as I registered. I verified my email, then was asked to confirm some personal info, as I was filling their form, I got an email telling me my account was disabled permanently and it was final. (I went on to use Linode and Scaleway after that.)
And Pokemon Go, which I never installed on any of my phones, I got an email saying my account was banned. I wonder what account, since I never signed up to their services.
Black hole of the Internet age.
I really wish I knew what it was. I use Uber mostly without issue. Same email, phone and CC. Occasionally Uber does wacky things like block my account due to fraud, but they always manage to fix it. I've figured out with Uber it's always due to travel. For example I'll order rides in Peru and then 7 hours later I'll have rides in the US, and not to my house or in my home area. Still wish they had a phone number because it can take weeks for them to unblock my account.
a) Government programs are programs, written in the language English. So let's be careful what services we launch with the stroke of the Presidential pen. They could be a cure worse than the disease.
b) Whither capitalism? A remedy to consider in parallel with government regulation would be some actual competition. How do we get the functionality we want without quite so much Orwellian peril?
Good consumer protections can actually benefit companies and the market in ways they don't expect until it happens. The Magnuson–Moss Warranty Act is an example of what I consider good consumer protections, and benefits the market as a whole.
It's a shame about your experience with Lyft. I'll have to remember this if I ever need a car ride, but seeing how all of these crowdsourced transportation initiatives are popping up with similar policies and disrespect toward open platforms (locking you into their apps, for instance) it might be better for me to consider conventional transportation entirely, if I'm ever stuck without a car and I can call up a normal taxi.
>I'm not one to normal advocate for government regulations and oversight
Yeah, I'd like to say that, this is capitalism and customers can naturally choose the right choice and stop supporting unethical companies, but this is hard especially with the network effect in play with things like Discord. Everyone's on Discord (or Facebook, or Snapchat) and suddenly a person is in the wrong for "not just signing up and using it" because their friends use it just fine. If consumer protections forced Discord to release a way to self-host servers (rather than calling guilds "servers") and made Discord fix their login and anti-spam mechanisms, and allowed users to have third-party apps to access the service, then I wouldn't complain. I still wouldn't like the concept of Discord because I'm a believer in federated networking, but it'd definitely be an improvement over the current state. These consumer / online service laws would also have great effect on financial and educational websites, which have rampant anti-consumer and security issues plastered all over their Internet presence. It's really upsetting to see how many corners people are willing to cut at others' expense.
There is no system of human <-> corporation trust in the real world. The best we have, maybe, is some record of how often you pay bills on time.
Tech companies kind of have to have these automated bans, because it's easy to create new identities on the Internet and the government doesn't care that you're defrauding a tech company. If you defraud a bank, the government pays the full cost of prosecuting and incarcerating you. If you spam Discord... nobody cares. It's Discord's problem, not the taxpayers' problem. So they really have no choice here. The world sucks. Get a helmet.
Having said that, banning people with a valid authentication token because of their IP address is simply the wrong algorithm. I can see why you might rate limit authentication attempts over Tor... but if you get your username/password right on the first attempt and provide the correct second factor... you should probably rate limit that valid session with a per-session rate limit key, rather than a per network endpoint key. (The era of IP address based rate limiting dies with IPv6 anyway, so they'll need a better plan someday.)
American banks seem to have no issue with this.
My last remaining social media with input from me is HN. But I accept that, sooner or later, HN will be just as intrusive, aggressive, just plain nasty and censoring as the rest of them. And then it will be time for me to "go completely dark" as far as my contribution to the internet is concerned.
Does that just mean "our black box NN has banned you and we won't know or care why" ?
The stuff about privacy is just nonsense from a clueless support person.
...If you can't filter out your core user base with 2FA (!!!) from bullshit like recaptch then you've got real problems
That risk is acceptableness to me though
Discord is a bit of a haven for spammers / scammers with my own account having received messages from several hundred random accounts ( to be fair the user is normally deleted before I read the message )
As a discussion / personal curiosity point how would the HN community reccomend discord handle this level of spam going forward?
The customer is always right.
> They may have had slightly better luck if they'd been friendlier and not attempted to school the Discord staff on how their app should behave.
Or not. Besides, it should not matter, either they did something bad or they did not, the tone of the message may upset the recipient but when you ban someone just like that you can expect them to be upset and your first line support people should be able to take that sort of heat in stride.
Sucking up to support staff when your account has been banned for no particular reason should not be a pre-requisite for having it dealt with professionally, in fact a good first line support worker will be able to de-escalate such a situation quickly by showing some competence and making sure the user is dealt with as they should.
This meme needs to go away. The customer is not always right, and it's deeply unhealthy for businesses to adopt this attitude. Even very customer centric businesses do not adopt this mantra.
If I was using Nitro, I'd have to agree with you, but I had a clear stance not to give a dime to a company I do not support.
That's been beaten to death by now. Let's start with that I don't agree with it. If the service is free the price is $0, that does not suddenly transform the person who the product is being delivered to into the product itself. It merely changes the revenue stream into another one that is invisible to the customer. The company then has many options in order to get paid, none of which involve selling the customer. They might sell data about the customer (illegal in many places if that data has been collected for different purposes), or they might attempt to upsell the customer on a different service.
But in no way does the actual customer get sold.
The whole thing smacks of defeatism: we don't pay so therefore we have no rights as customers so don't whine. But that simply isn't true, users are not cattle to be sold at auction and companies should not treat them as such. And users should not tell each other that they only got what they deserved.
It would be nicer not to be the product, but the world isn't always nice. Sometimes it is.
By all means, you are still providing value to the service and they need you as much as their paying customers. However, a lot of companies lose sight of this logic once they go big.
That means the same as "there's no accounting for taste". If the customer prefers the neon pink lunchbox over the blue lunchbox, they are correct.
It does not mean they can do no wrong.
https://thebaffler.com/salvos/critique-of-pure-niceness-whym...
Matrix isn't great, but it's open-source and it allows me to connect however I please. I have my own Synapse homeserver set up; might consider Construct as well, once it matures. And Matrix is the only platform I have run into that even has easy bridging with Discord and so many other services.
Yes, I believe Hacker News feedback to a blog post that was not designed for feedback is unfair to me, but I guess this means that a follow-up post saying what I am doing in response to leaving Discord is in order.
Discord gets a lot of spam. We've disabled, and/or challenged millions of accounts for trying to use our platform for unsolicited spam (trying to advertise their service, sex bots, crypto spam, etc...). Our anti-spam systems continue to evolve - just as the spammers who target our platform continue to evolve. The spam attacks against our platform vary in terms of how elaborate and skilled they are. Some are very obvious in terms of a detection perspective, and some are not. As such, we use a blend of signals, heuristics and machine learning algorithms to determine whether someone is spamming on our platform. Additionally, we look at where spam is originating from as an input to our heuristic.
One such source is TOR exit nodes - and as such, our system considers content created (DMs opened, etc..) from people using TOR exit nodes with more stringency than other sources. As such, if you are using TOR, it is definitely more likely that you may get challenged either via captcha, or phone verification. The system is definitely not perfect - and unfortunately in OP's case, it flagged the account for phone verification.
To address the 3 demands in OP's email:
> 1. Discord's anti-spam isn't so anal,
I'm not entirely sure what this means, nor what actionable steps I can take. You are using TOR, a source of a great amount of spam/attempted spam on our network.
> 2. my account (and other accounts in good standing and with proper 2FA) is exempt from such checks
Having 2fa is not a strong signal as to whether or not an account is legitimate. It is very trivial to automate setting up 2fa on an account. https://github.com/pyauth/pyotp can be used to both generate and validate 2fa codes. It'd be trivial to hook that up to the registration flow to enable 2fa - and if that was a way to 'bypass' our anti-spam measures, it'd surely be exploited.
> 3. I don't have to solve a Google reCAPTCHA for an account I have taken every step to protect against bruteforcing. Using Tor is not a crime; don't treat it as such.
Malicious actors constantly attempt to brute-force logins on our system - generally from public password dumps or other leaks. A lot of these brute-force attempts come from TOR, and other public proxies. In order to avoid information disclosure, we always captcha logins from these kinds of IPs, regardless of whether or not an account exists with the e-mail in question, whether the login credentials are correct, or there is 2fa enabled on the account. So, the "captchas" you notice are not really specific to your account, but rather, the origin of the login. Using TOR is not a crime, you are right - but - it's also our responsibility to our users to make it reasonably hard for their accounts to get compromised on our platform (even if they don't employ the best security practices - and reuse their passwords across the internet.)
Finally, I'd like to address: "Discord has shown to be hostile toward FOSS and privacy for a while now" and understand why that is.
As a company, we have tried to give back to open source software (either by financial sponsorship, or by contributing our bugfixes/changes upstream.) We also attribute all open source projects we use in our software here: https://discordapp.com/licenses. Additionally, we host many open source communities on our platform: https://discordapp.com/open-source. And finally, we try to open source software we make which may be useful to the eco-system in general: https://github.com/discordapp/.
As for privacy, we've stated that we don't sell your data. When you verify your phone number, we ONLY use it for the purpose of anti-spam, and it is never shared with anyone (aside from twilio, which sends you the SMS), especially for the purpose of financial gain. We're pretty up front about how we make money (freemium model: https://discordapp.com/nitro, in-app commerce: https://discordapp.com/sell-your-game). We provide privacy controls: https://support.discordapp.com/hc/en-us/articles/36000410991..., and allow you to request an export of all the data we have stored on your account: https://support.discordapp.com/hc/en-us/articles/36000402769...
I know this reply won't satisfy everyone, but hopefully, being truthful and upfront about this will help!
Solution: add a checkbox "disable account security measures", so a user who doesn't want CAPTCHAs when logging into their account doesn't see them. It would have a warning so any user selecting it would know what they're doing.
>anti-spam
My impression would be that an aged account with a good reputation would be held to much less scrutiny than a new account, regardless of my method of accessing the service.
>regardless of whether […] there is 2fa enabled on the account
Clue me in on this one because I do not understand how a bot surfing for accounts would be able to guess this code in a configured number of attempts. Many login forms have a number of tries before the account is temporarily locked and the user is notified of a potential breach. This is no substitute for a good password, but it's one additional safeguard, and it's one that doesn't depend on a nonfree CAPTCHA service. I'm trying to de-Google lately and I've been pretty successful; one of the few services I use anymore is GDrive and that's only because I have unlimited storage and GPG at my disposal. Discord isn't owned by Google, so my decision to abandon Google's services shouldn't have weighed in on my decision for third-party services.
>it's also our responsibility […] (even if they don't employ the best security practices[…].)
I understand, but there's a line one has to draw for things like this. I'm not a fan of password requirements but employing a minimum password length (if Discord doesn't already do so) would be a good start. As a public service provider, I understand the issue with compromised accounts, and how they can be used for spam and harassment, but I still believe there are smarter ways to go about this than punishing people for using the wrong IP address to log in.
>hostile toward FOSS
>we have tried to give back to open source software
That doesn't really mean much when Discord openly detests third-party FOSS clients and will not make its server available at least in a similar capacity to GitHub's self-hosted solution (I don't think GitHub is appreciative of FOSS either, and they prefer to capitalise from the walled garden they've created rather than truly express the libre ethic, but hosting servers has been a long-requested feature especially from established communities who don't wish to rely on Discord's infra).
>and privacy
>we've stated that we don't sell your data
I'm a cryptoanarchist. If an organisation has my IP address, they have my IP address. If they have my phone number, they have my phone number. Discord may have my intentions at heart, its servers may be kept updated and secure from most threats, but Discord is a high-profile platform now, and we're all no stranger to hackers leaking database information from a zero-day or some other oversight. I cannot trust words and policies, I can only fully trust audited code and myself. So, no, in this light Discord does not appreciate the concern for privacy if it does not make exceptions for verifying accounts by other, more private means.
I wish I could give an answer on how to moderate a platform without negatively impacting people, but to reuse your words, there isn't an answer that satisfies everyone, and there will always be shortcomings for any solution, whether it's a setup cost or a long-term conditioning of users to create better passwords. In fact, I talked about passwords specifically in another blog post [1] so I can only hope they are eventually phased out for something less prone to user error. Despite what we're stuck with, I do genuinely believe Discord could tune their spam and login mechanisms such that false positives are kept to a minimum.
[1] https://wowana.me/blog/are-passwords-the-right-solution.xht
"Good" accounts turn bad pretty quick. We have some betterments to make around taking account age into consideration - but it's also a well observed event that a prior good account gets compromised, moves between continents and starts sending out spam. We've also observed spammers register accounts, sit on them for a while (we've observed some age for over a year) before using them for spam. So, if we notice an "account traveling around the world at an unreasonable speed" we use that as a signal as well - and it is a very common pattern, almost exclusively exhibited by spam accounts, but also the few users whom connect via tor.
>That doesn't really mean much when Discord openly detests third-party FOSS clients and will not make its server available at least in a similar capacity to GitHub's self-hosted solution
In an ideal world, it'd be nice to support 3rd party clients - but unfortunately - we've observed on many occasions where 3rd party clients have malicious plugins that lead to account compromise. Additionally, having to support 3rd party clients can be problematic from an anti-spam perspective, as it muddles the line between "here's an obviously fake client" and "here's a legitimate 3rd party client." I actually wonder if this is why twitter struggles at anti-spam so much (but I don't know nor have talked to anyone at twitter to verify this.)
I also don't really understand why we have an obligation to offer a self-hosted solution. An advantage of our business is our server infrastructure - and although we occasionally blog about how we do things, maintaining an open source release is neither good for business, nor is it for product velocity - and definitely not something we can support given the available engineering resources. We are a very small team of engineers. For the first 3 years of the product, the infrastructure team at Discord was 2-4 people, in the current day, the IC's on the Core Infra team at Discord is less than 5.
I think a lot of people have this misconception that we are a huge company with a bunch of engineers - however, unlike a lot of valley startups, we actually hire very slowly, and deliberately - and relative to other products in our space, our team is exceptionally small. From what I hear, our entire engineering department is the size of the mobile department at another company in the voice/text chat space. As such, we work efficiently and deliberately - with the goal to build a good product, and also to ensure that we're successful as a business in the long term. These values mean that we do have to make trade-offs. But we do so in the interest of our users. Discord as a product is one that I'm passionate about working on, and a product that I use daily to play games with and talk to my friends.
> If they have my phone number, they have my phone number.
Have you considered using a burner phone? Very easy to pick one up from your local convenience store for a few bucks - and will work with phone verification on our product just fine - and will work with others that employ similar anti-spam solutions.
> Despite what we're stuck with, I do genuinely believe Discord could tune their spam and login mechanisms such that false positives are kept to a minimum.
I do agree! We are actively hiring for this position: https://discordapp.com/jobs/4286902002 - there are many betterments to be made, but we need more people such that we can work on em!
3rd party clients (eg. Ripcord) that were shared on reddit were quickly shot down with a We don't allow or support 3rd party clients or modified versions of the client.
Do you actively hunt for Discord users with a 3rd party client or is it more of a "we don't hurt you unless you abuse our API"-deal?
This surge in adopt is pretty classic. It feels artificially hot / running at too high temps if that makes sense.
I don't see a superior product so don't see this crashing, but Discord is going down only from here
Been like that for over 20 years.
2)You use proxies/tor which probably makes your concerns the concerns of 0.01% of the user-base.
Why should a company whose primary motive is to be profitable go so far out of their way for you, a non-paying client whose concerns represent basically none of the legitimate user-base?
You seem to be implying that they are not a legitimate user. What makes them any less legitimate than everybody else?
There are legitimate reasons to block TOR traffic, and even if there where none, they'd still have the right to block anyone of their users.
There are plenty of alternatives, simply remember not to choose one ran by a private company again.
I just believe that placing bans or flags on IP addresses is not the answer, and I will work on my own software and services with this ideology in mind. Ironically, Discord did have what I believe to be a stellar answer to guild moderation: invite links. They allowed a whitelisting model for private guilds, as well as varied forms of controlled access for more-public guilds. I'd like to see this kind of control everywhere.