Discord is not an acceptable choice for free software projects
sneak.berlin
sneak.berlin
They later reversed the ban on my account, but kept the server deleted because they maintained that we advocated cheating. Again, we develop anti-cheat moderation software.
In my last contact with them, I was told that that it was up to us to moderate the server better too. If any user posted cheating related material, they would of course ban the server for terms of service violations anyway (this essentially inverts the typical idea of "safe harbor" protection that traditional websites have).
The problem with not using Discord is that they successfully captured the gamer and game market. As a game related tool, all of our users are on Discord. It's a shame that one company was able to do this.
It's easy to hate on Discord's practices but it's worth remembering that they're on top because their project is legitimately good.
When discord released it didn't even have a Ctrl+f function for a long time. It still doesn't have chat logs on the user end, the permissions system is bad and audio quality is mediocre. On top of all of that, because they don't allow self-hosting it means that discord ultimately controls your conversations.
It caught on because it went viral. The service they offer is good, but the lack of privacy and no self-hosting make it disappointing.
Basically it was a ripe market with extremely bad products. I don't think Discord is anything amazing (seems fine for the most part), but they're clearly significantly better than what existed when they launched.
The main thing that discord did was combine voice with the chat side of things, and with per user chats and history. A lot of people don't know that mumble has a pretty decent html capable chat, but it's the history searching, dynamic rooms etc that set discord apart. Mumble still has the superior voice capabilities (simultaneous multiroom, easy permission, hierarchical, etc)
I have put most of my hope in mattermost to do murmur integration to solve this problem.
In the meantime I find myself considering trying to get everyone back on irc+mumble.
edit: Also, just have to say I bet the gov loves having a single place to send all those NSL's... cough hint cough
But the default answer to the question "how do I have seamless transition between my desktop and my phone" for IRC remains "pay for a shell/bnc, run irssi in screen, etc" which is of course a UX nightmare.
Discord has a buttery smooth onboarding process.
The "modern" answer is "don't do that". There is a time to play social games, there is a time to do what you are doing, and you should spend some time talking to yourself too.
You mean it's easy to forget about Discord's practices because their product is good.
Seriously, you're arguing that they get to do whatever because "their product is good"??
Do I have to spell out how egotistical this attitude is?
Deleted comment
Discord has been by far the best of any app I've ever used, because I give someone a link, they click on it, they immediately join the channel, and it immediately works. They're now in the voice chat. They have great defaults.
I don't care how annoying the individual settings are, or if other apps do that better. What they have are defaults that work out-of-the-box better than everyone else.
I have had more issues with Discord than any other VOIP.
Where do you draw the line? Are jokes involving death also out of the question?
I’m not a big fan of rape jokes, but is there some specific list of things which are unacceptable to joke about in 2020?
[1] - https://www.mumble.info/
[2] - https://github.com/mumble-voip/
[3] - https://www.mumble.info/blog/mumble-1.3.0-release-announceme...
You can make whatever security arguments you want, but it's going to drive away users. And then they'll still be using passwords anyway, on whatever chat service they use instead of Mumble.
The question then becomes how to motivate the average gamer to jump onto a different messaging platform.
>Regardless of whether or not you are the kind of person who mocks or ridicules people—you should be able to use your communications tools to mock and ridicule people, if you so wish. These are normal, acceptable things to do in society. Fuck censorship.
I would guess that for the vast majority of Free Software projects, not having illegal topics discussed on the chat and not having people who mock and ridicule people are features not bugs.
it's not just illegal things that are kicked off. If you violate a third party company's terms of service, say making bots for Team Fortress 2 (a valve video game) then you'll be banned suddenly as well. And Discord is no stranger to banning things that are not illegal but just controversial like, https://www.reddit.com/r/guns/comments/cvv5da/meta_rguns_dis...
In terms of privacy: they send a tracking request for every single thing you do in their client. Clicked on someone's profile, clicked on a channel, clicked on a server, etc. The URL was named /track before but they renamed it to "/events" recently (but it's still a POST with no response).
Their desktop client is literally a remote administration toolkit, it has full access to FS (electron app) and it loads every script from their servers. They can just add something like require('fs').readFileSync(process.env.HOME + '/.ssh/id_rsa').toString() and send this to their servers, and you won't even notice that (since it doesn't require an update on client because the client is just a browser with full permissions that loads obfuscated code from their servers every time you launch it).
(Not defending it on the other counts, though. If I wanted a platform for anything controversial or privacy-sensitive, I wouldn't trust Discord or any other centralized, unencrypted service.)
I think it's reasonable to call it a RAT because it executes arbitrary remote code AND has those permissions.
There's still room for problems... the auto-update could deliver a special version for special people or deliver a version that has special code targeted at run-time, but it's not as easy. And I'd love to see work on minimizing problematic updates as well.
We should avoid and shame the programs that do that. This is literally a backdoor.
Like shit, I have 3rd party mod managers for video games that are exclusively built to do such that
I have Discord installed, because unfortunately that's where my friends are. However, it cannot access arbitrary parts of the file system because it is installed via flatpak; it only has access to ~/Downloads and ~/Pictures.
No, a program with an 'update' feature built in is much less offensive than a program who's entire code is remote and new every time but still has local privs.
There are no alternatives. Bandwidth costs money, and P2P is deadly. That's why discord exists in the first place.
Pretty sure it has been /science for at least 2 years.
And that is why you encrypt your SSH keys with a passphrase, use a Keychain, etc. Discord isn’t unique in its ability to read file on the FS. Pretty much anything can do that.
Nah, pretty much anything except proprietary software has a higher chance of being written by people I trust and packaged by people I trust and probably audited by me and other people, and is not capable of loading executable code from any server after installation.
And a lot of projects have codes of conduct explicitly to prohibit participants from mocking and ridiculing others, in fact.
(As a note, I refuse to install the actual Discord client on my PC, because it's default behavior includes "detecting" accounts you can link on other software on your PC. Aka, it, by default, noses around in other apps on your PC for data.)
For software that works under wine, I guess it wouldn't be too hard to simply set a wineprefix and do it like that, but that is a bit of a hack, and wouldn't work with a lot of software.
However, I use Virtualbox and/or VMware Player a lot, and Hyper-V doesn't play well with others, so I can't use any features of Windows that depend on Hyper-V virtualization.
I personally use a UWP app that embeds Discord's web interface. It's surprisingly serviceable.
You can use it via tor, so it can’t access a persistent record of your location history, as Discord can. The public logget doesn’t log DMs. Likely, anyone can join without being forced to give up PII.
As for the CoCs, that’s a good thing! That’s the right way to do it. Demanding that your users enter into an absurd legal agreement with a third party to be able to participate is not.
"Phone numbers are bad and shouldn't be used but also you should use Signal!"
"The only thing I used my account for was DMing a link to a bunch of people and they banned me in a way I could contest because it looks like spamming!"
"For notifying people about stuff you should use electronic mail but don't notify them more than once every two months!"
> You should not use services that can rat on you and your friends to the cops.
in a post about [checks notes] FOSS software development, puts things in a certain light.
FWIW I'm privacy-conscious myself. If the author had just made a general effort to point out the privacy implications of using Discord, that would be one thing. Instead he made a contrived effort to connect it to FOSS development - arguably one of the least-private activities one might be doing online - and then went on to call Discord altogether "unacceptable", instead of just saying "don't assume that what you say on Discord is private".
Taking your use of "secret" to mean "private," because no one was discussing "secret communication channels":
This isn't actually true; a lot of Free Software projects have private mailing lists.
I honestly have a hard time seeing eye to eye with the idea that private organizations have to let users of their platforms do whatever they want. It strikes me as representing a rather solipsistic concept of freedom. One could argue that the specific restrictions Discord is making are shitty. It certainly sounds to me like they are, and one could then mount an argument that people should steer clear of them because they are acting shitty. But doing shitty things is not necessarily the same thing as violating a moral obligation.
IOW, it's not necessarily because I think Discord is actually going to tell Joseph McCarthy how often I pick my nose. (You'd be amazed how rarely I manage to work that into group chat conversations about code style, anyway.) It's more the principle of the thing.
The part about ridicule/mocking is an example of why Discord’s legal agreement is unreasonable, not advocating for the ability to mock or ridicule people.
The tools should not enforce censorship.
[1] https://www.amazon.com/Three-Felonies-Day-Target-Innocent-eb... [2] http://ulrichboser.com/how-many-felonies-did-you-commit-toda...
https://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp...
It's not without its criticisms:
https://skeptics.stackexchange.com/questions/22530/does-the-...
It has also been estimated that the above statement is poppycock (just now.)
I just feel like saying this here: I don't find that censorship itself is a problem. Self-censorship, for example, is generally not problematic, and everyone does it. A great example of voluntary self-censorship is with swearing -- it's not illegal to swear in public, but most people choose not to do it. That's not to say self-censorship is always problematic, but simply that it is not inherently oppressive. Sometimes, it's the right thing to do.
However, in larger group contexts, censorship earns legitimacy when it is agreed upon by those who are participating in that group. If a group of people agree to not swear in the context of their organization, then by all means it is fair for them to censor. In broader forms of censorship, such as the example of FOSS projects censoring toxic and illegal behaviors, as long as it is decided democratically, then it's absolutely a feature and not a bug.
I wish the folks saying things were not acceptable would work on options that had the benefits they wanted.
Steve jobs didn't say - locked down phones with no access to the web in unacceptable, he built a better phone (and was rewarded very well).
He didn't say the way digital music is sold is stupid - he built a better music buying experience that let you authorize multiple devices to play your music etc.
I took some time to reflect on why OSS wasn't the default for these messaging tools, rather than proprietary alternatives — and what it would take to make more users use OSS alternatives:
> As Slack has continued to grow, open source developers have had lengthy debates about using it rather than IRC. For some, the fact that Slack is closed source and a walled garden makes it unsuitable when building projects that are open.
> I’ll take a different approach: in the age of software, why is open software not more competitive for many products used by non-engineers and what can be done?
What Open Source Can Learn From Slack
https://www.nemil.com/musings/oss-and-slack.html
-------
Setting up Mattermost on a VPS isn't hard.
It's also $0 software, in that it being free software and open source, you can simply and legally patch out their license checks and recompile, if you so wish.
Ease of hosting is one of the very biggest advantages to something like Slack or Discord.
The main thing that worries me about is discord is their revenue model... I just don't see how they're making money, and they keep on raising money.
There are a few good alternatives like zulip [0], matrix [1], discourse [2], Rocket Chat [3], or just plain old irc.
Although discourse isn't really a chat application but more of a open source forum software.
[2]: https://github.com/discourse/discourse
[3]: https://rocket.chat/
[4]: You can get around this by messaging relevant information to yourself. Or just saving things locally, like a weirdo.
I never said anything about Slack or Discord being better/worse than each other.
Of course git itself is an open tool, so the repos are totally interoperable, but the OSS community's dependence on GitHub for issue tracking, PRs, etc. has always made me uncomfortable.
It’s popularity is due to marketing and abusing some social phenomena, not merit.
“Free” refers to the software license of the source code. That is it.
The maintainers of a free software project don’t even have to accept contributions outside of their organization or club.
Private companies that use all kinds of proprietary communication tools regularly contribute to free software. Are all of Red Hat’s internal conversations about Fedora guaranteed to make it into the public?
People are also perfectly capable of having private conversations about contributions to free software projects. These conversations don’t ever have to be made public. Again, only the code license is what makes a piece of software free.
So if you don’t like a project’s method of communication, my advice would be to not contribute to it. It’s the project’s own risk of deterring potential contributors, not yours.
I find it hilarious that someone would find themselves feeling entitled enough to tell a bunch of unpaid open source developers how to communicate with one another as if that someone were their boss at a company. The only place where I’m told what communication tools to use is at work, where I’m paid to comply.
I feel like this should be obvious to anyone who has ever read a blogpost or editorial, but the author isn't literally commanding all free software projects to stop using discord as if he has that kind of authority, he's making a recommendation and then goes into detail about why he thinks this way, ending with some alternatives. It's bizarre seeing someone react to an article like this with offense not because of any of the content or points, but for... not showing enough deference in their title?
Hopefully the free software ethos police doesn’t come knocking on my door because I used GPL 3.0 without having the right mindset.
However if you said "I'm creating this project because I care about user freedom" someone might point out "Great. Well, since we're on the same page as far as user freedom, let's take a look at the tools we're using..."
Yes, private conversions about contributions to free software projects are possible and are sometimes desirable. But, messages on the official channels for communications should normally be public; people can (and should) of course still use their own private communication as needed, too, but does not mean you cannot have a public one too.
They are making a moral argument against discord. If they said it was not acceptable for free software projects to go around hitting people on the head with clubs would that be entitled?
Tin foil hat paranoia isn’t enough for me. The author is assuming their door is gonna get busted down and they’re going to get arrested over their discussions about a bug fix for an open source widget.
I’m telling people what they should not do: that is, don’t discriminate against people who insist on privacy.
Choosing to use Discord does that, so people who don’t want to discriminate should not choose to use Discord.
I’m also offering them alternatives that don’t discriminate against those people, so that they can make better choices if they decide that they don’t want to be the kinds of projects that discriminate against segments of their userbase.
This person isn't being wronged. They just don't like the software other people chose to use in their projects which have nothing to do with the author of the blog post!
If someone tells you they're suffering racism you should listen no matter how it sounds to you. If someone tells you they don't like that you're using Slack and that you should not use it, you're right to tell them to sod off until they can be polite.
> I’m telling people what they should not do
Those two things are the same.
You might want to read this: https://www.gnu.org/philosophy/open-source-misses-the-point....
""" Many people in the free software movement find censorship in general to be abhorrent. (That’s one very good reason, for example, why emails you receive that might be spam go into a special folder, instead of being silently deleted without you having a option to choose to see them if you wish. Your email server could just delete them! The fact that it doesn’t was a deliberate design choice to avoid censorship.) """
Lots of people's email servers do, in fact, silently delete quite a bit of email, because the signal-noise ratio in the world of email spam is so bad it swamped the attention budget of users (and in some cases the storage budget of service providers) ages ago, even with a spam folder attached.
https://en.wikipedia.org/wiki/Backscatter_(email)
https://answers.microsoft.com/en-us/outlook_com/forum/all/ho...
https://blog.paranoidpenguin.net/2015/01/outlook-com-is-sile...
http://www.enterprisenetworkingplanet.com/netsp/article.php/...
You want your email server to censor all entirely-obviously-over-the-top spam messages, for example (e.g. SA score >20). Most people want Facebook and Discord et al to censor spam postings.
However, when censorship veers from basic utility into editorializing (e.g. Facebook and Instagram's algorithmic prioritization/deprioritization in user feeds, Discord banning the legal and regulation-compliant /r/guns subreddit's Discord, or Facebook banning posts with male nipples, or Youtube banning instructional/educational videos about computer security, or Apple and the Taiwanese flag, or Gmail spam-foldering emails from smaller email providers not part of the deliverability cartel, or a million other examples), then it becomes a social issue and a potential problem that we need to address.
Email that is not 100% not-a-false-positive should never be silently trashed.
So I clicked a link on their GitHub page for some online IRC client.
I had a conversation it was great. Except for the part where I wanted to paste some code and it didn't format. And then I was recommended to use pastebin and paste a link.
Then I went away for a bit. Came back later and my computer had rebooted while in standby. (It's an old laptop and is a bit flaky with resume from standby)
I returned and click the link for the IRC chat. And I couldn't see the previous messages.
And they had a link to a log but it wasn't working.
And apparently the server doesn't log by default.
Look, no offence to IRC. But this is some crazy bullshit.
Like Discord, Slack, Gitter, Teams. Whatever. Isn't going have this issue.
At the end of the day people want to communicate and get their stuff done.
For a free software project, sure, using opensource tools is a great idea.
But sometimes faffing around with none core things just wastes everyone's time. Especially with they could instead be working on features and bug fixes.
Matrix channels can even be bridged with IRC using bots, allowing people to use their tool of preference.
Slack, Discord & Gitter don't monetize data either, so that's a pretty weak argument.
If you had used a persistent IRC system (like quassel) then you'd even be "online" permanently, whether or not you reader-client was running.
IRC has different semantics and goals than "modern" chat/msg systems. Even though they overlap quite a lot, it's a mistake to think that one is a substitute for the other.
Surely a donut tastes better bare. Not good for your heart as well. Now that most people don’t have a kitchen it seems like a problem to me as well.
As noted by another commenter, the fact that you know how "most modern chat/msg apps work" doesn't mean that they all have good UX - it means that they all have the same UX, and you've already learned it.
because if you were raised as i was in the internet of the mid-90s, logs and real names are weapons, and we don’t do that to our friends.
On the Ardour's project's main IRC channel, it makes absolutely zero sense for the vast majority of people in the channel to be able to drop off the channel for 2 days, and come back and read everything they missed. The social expectations and norms there don't make this a sensible or reasonable expectation.
Contrast with "modern chat systems" ... in most of their uses, this is an entirely reasonable expectation because you are a _member_ of the group, and simply being offline isn't a reason for you to miss messages.
In our case (Ardour), we have private IRC channels where this sort of expectation is more reasonable, and we run a Quassel server to provide "always-on" messaging for people who are "members" (i.e. people for whom it's sensible to expect that they never miss messages).
But the expectations for chat today has changed a lot
But.
Discord (not to mention Slack) will simply continue to be the lowest friction choice until a FOSS alternative comes along that is free to use, comes with rich moderation tools, supports fine-grained notification settings, supports offline history without additional effort, supports rich bots, has a mobile client that shares state with the desktop clients, and already exists on most people's desktops.
So to impact the open source communication landscape, the standard that needs to be exceeded is Slack and Discord, not IRC.
It's also a bit of a chore to even identify how to get a server. Matrix.org points you towards other implementers, Riot.im pushes you back to matrix.org for a login, and to "Modular" for a server.
This is kind of the opposite of low friction and ease of use.
It seems pretty slick from a technological point of view, but a bit of a mess from an implementation point of view.
Now, I looked up each of them, and found that they all rely on hosting your own server, or some kind of strictly limited "community" plan. The managed (and for Mattermost even self-hosted) servers all hide features (such as message history, rich moderation tools, or support tickets) behind a paywall.
These are solutions aimed at enterprises, and they use open source (or open core) licenses as the foot in the door. It's commendable that they offer to let you host the server yourself, but I would not call it "simple" to do so.
I believe that this high friction and low install base will make them effective non-starters in the open source development space.
Happily this is not true of Zulip! Open-source projects get free hosting on zulipchat.com, with the exact same features as our corporate customers. Quoting from https://zulipchat.com/for/open-source/ :
> The hosting is supported by (and is identical to) zulipchat.com's commercial offerings. This offer extends to any community involved in supporting free and open source software: development projects, foundations, meetups, hackathons, conference committees, and more.
(I work on Zulip.)
I know nothing about the other systems but this isn't true for Mattermost. We run Mattermost ourselves and it does indeed offer message history and moderation tools, they're part of the open source Mattermost version. I can't think of any feature that I miss from it, to be honest.
How can I assert this? If they were not a minority, they would have sufficient clout behind them to push the project onto a FOSS chat solution.
At least that's my experience.
IRC can be part of a solution but it's not a solution on its own.
Properly implemented, I've had much better availability with this sort of solution than with Slack. I've seen multiple hour outages of Slack services just within the past 6 months, it's well below four or five nines reliability.
Slack/Discord/etc. fix the problem for everyone.
Trying to community-build on IRC just seems like an exercise in masochism. I think most projects and their users deserve better than that, and it's hard to do worse than IRC.
https://ircv3.net/specs/extensions/batch/chathistory-3.3
https://github.com/ircv3/ircv3-specifications/pull/393/files
That's not really how it works, and if we take history as an example, most of what you say can be used for profiling and targeting potentially. So no, the above argument misses the point, completely.
We can do better as educated folks. A good starting point to learn bout privacy would be to read -at least a bit- of Daniel J. Solove's "The Digital Person: Technology and Privacy in the Information Age". Also, learning more about history and what happened with PII (personable identifiable information) in WW2 is important.
There's nothing uneducated about having a differentiated view on privacy, which this blog post has not, it's mostly just an incoherent rant.
There's nothing wrong with not having any expectation of privacy for discourse that is supposed to be public. I don't care if my open source development discussions are public because they're intended for a public audience. Same goes for any discussion I have on a discord.
People with an educated mindset are able to discern what information deserves what level of privacy, rather than larping as privacy advocates to stick it to the man or whatever the motivation is.
Despite being a strong privacy advocate, I didn't find the post particularly compelling. For the vast majority of open source projects, discussion of anything illegal would be considered off topic, and there is no expectation of privacy since all discussion is public record. Having those discussions being public and searchable is a valuable feature.
Does that mean I am against good tools that enable private discourse (like Signal)? Of course not! Some open source projects probably have a need for private discussion channels. I'm all for them using them. But to then extrapolate from that: "don't use Discord to discuss your open source JS widget library" doesn't make sense to me.
I should have been more clear. I just read through the comments here in HN and tried to make an observation about the level of the conversation that the HN community (is it a community?) seems to be having. Mainly wanted to express that I hoped that we could all learn more about privacy in this day and age, given that it's (or should be) a fundamental matter that relates to most of what we work on these days (at least as people working in tech).
There's a very long chasm between "You can get the software running, and have it respond on a port to requests" and "Providing a mission critical service that your project relies on".
The key word here is service. It is often drastically underestimated how much effort is required to have a service available, especially at any sort of scale.
Free/Open Source software is irrelevant as soon as you are providing a service, because by design, the only people who have control over the service, are the service operators, and the only people who really know whats running in production are the people who deployed the code.
Given that, the only choice a user has is whether or not to trust whomever is providing the service, regardless of whether or not the software they are running is free/open source, or proprietary/in house software.
I think he would get good results by putting an obvious signup form on his sidebar, underneath his contact details. Make it easy to notice, but don't make it an interruption.
That said: totally agree, I hate modals like this.
This idea that the primary way to get people to come read what you have to say is to push it to them, and that this is such an important goal that it justifies nagging them for permission to be allowed to blast communiqués in their general direction, and that you can excuse yourself for annoying behavior like this by claiming that it's for the benefit of people who want the email but wouldn't be able to find a sign-up field in a sidebar - presumably a small minority of a small minority of total visitors - strikes me as being so very entitled. But then, I suppose that the basic idea of the attention economy is that you're supposed to be clawing at every scrap of Whuffie you can get.
Granted, it's the author's website, and they get to do what they want with it. And we have apparently collectively decided that it's OK for any webpage, even one that contains only static content, to require JavaScript in order to function properly. A corollary to that would be that simply using the web is tacit consent to be pestered, since it's not really possible to have JavaScript enabled while also avoiding modern-day incarnations of the blink tag. So there's that.
But still. . . I'd love to see RSS make a comeback, just to at least take away the "but RSS is dying" excuse.
There is no javascript in the feed. :)
The ultra mega hyperbolized text and the needless association with open source (what, people not working on open source don't deserve privacy?) don't help either.
Of course he is, that's the whole point of writing.
Sort of, there's Jami [0] (formely GNU/Ring) which is actually free software and looks nice, but I haven't tried it yet. Another option is the Matrix protocol [1] and some of its clients like Riot.im [2] fit this free software criteria.
If it's really important to you, as a stopgap measure, you could sideload a second copy onto your phone.
There are so many discussions, QAs, tips&tricks etc. shared on these chat rooms, that are impossible to find for those not a part of it. If it was discussed in a public forum somewhere, it would pop up in a search engine. I may have a problem with tool X and google for a solution, but since the discussion happened in some closed Discord server I will never find the solution someone else there has posted.
So kinda the opposite of the author's point about privacy: I prefer everything to be open and accessible. Hiding this stuff hampers the adoption without people realizing. I don't join a discord for everything I use, and often I'm not even aware that it exists.
An example I had a few weeks ago: Elm package repo died so I got some weird errors when building my project. Apparently lots of people were aware and knew about the problem and the status. But it was discussed in some Elm slack (I think), so for me not a member there I had no idea what was going on and couldn't find anything about it.
Teams using Discord force their team participants to share this information with Discord to participate, who can then share it with whomever they want, with no legal recourse if they harm you as a result.
Public things, like discussion and documentation, should be open and available.
Teams using Discord have outsourced to Discord the decision of who is allowed to even read information that should be public. People who don’t ID themselves to Discord and agree to not sue them are prohibited from reading.
It fails on both counts.
Discord is, for all intents and purposes, a privately owned public space. What you say and do there is public, is publically viewable effectively, and that extends to DMs.
Likewise, Discord wants to maintain their public space with their rules. I disagree with these rules, but Discord is free to moderate their space as they see fit.
Just like the owner of a private campground can kick you out for cursing, despite using curse words not being a crime, so can Discord ban you for posting nipples or cheat software.
I think the only malfeasance here is that Discord looks and feels like a private space. It feels like a space where you can talk privately or share things privately, and so people are upset when that expectation turns out to be wrong.
For some FOSS projects, I think Discord is a fine choice. It's low friction and it works well. I use it for my social groups. For many projects that might touch on software or topics that Discord dislikes, or that strongly disagree with Discords moderation, they should use an alternative (whether that's still public like IRC or potentially private like Riot)
That's the base vanilla behavior template for a pornbot.
(Arguably, the use-case in question isn't even what the service would consider "legitimate;" user was trying to tickle the tiger's tail on purpose. If one doesn't want to get kicked off like a porn-bot, it's not hard to avoid acting like a porn-bot).
good, we get crankier when young punks repeat our advice without understanding why it was given.
"There’s no single free/self-hostable alternative that has all of the features of Discord,"
... so, just maybe, someone who's got a project to do might want to keep with discord, despite its flaws, instead of fucking around with recreating the same thing only more philosophically pure?
1. I'm not going to self-host any of that stuff for my own projects, nor am I willing to pay for an alternative SaaS that a privacy-extremist finds less objectionable.
2. Few projects are important enough to me to sign up to use their weird self-hosted or non-mainstream-SaaS solutions.
Discord wins for the same reasons that GitHub wins, that Sourceforge used to win, and for the same reasons that no upstart projects are standing up their own Trac or Bugzilla servers any more.
Insert "Old Man Yelling at Clouds" meme.
I agree with part of one of 'sneak's points, though, if not the way it's presented and some of the way it's worded. Discord isn't a good choice for Free Software.
I was talking about it without CSS.
Turning CSS-blocking on for it with uMatrix makes it look fantastic once more.
No one with sensible browser settings/extensions will see a pop-up, it's certainly not exclusive to Brave.
Blocking these anti-features comes automatically with Brave, no effort or setup. As more of us block this nonsense, whether with extensions or with Brave, the less incentive to write excessive CSS and annoying pop-ups.
It also insisted that my firefox was outdated even though it was not. It kept being laggy and glitchy, lacks e2ee/e2ea, bans 3rd party clients, is not accessible to people with disabilities, etc.
So yeah, Discord is one of the worst choices, and not only for free software projects.
It’s effectively impossible for anyone with visual impairment that use a screen-reader to use Discord. I could go into (/very/) great length into this, but that’s the gist. What makes this even better is that there’s no getting around this limitation: third-party clients or client modifications are disallowed in the TOS and will cause your account to be banned.
It's not spying if it is in their Terms of Service. Full of hyperbole. Yes, common sense SHOULD tell you: If you are using a free service such as this that is not free to operate, then YOU are the product. And you will be marketed to and you will not have privacy. Get over it.
So for civil rights perspective there should be single account database, THE Civil Registry of Internet that let you tie, link-unlink, manage accounts. A face-book in modern term but not necessarily in your real name or for always fully disclosing your genitals. What OAuth realized for a brief moment.
One of the oldest core function of a nation, and we need it. Well that used to be my billionaire dream idea for this quarter and there it goes...
How is that remotely acceptable?
There really should be some kind of law against ludicrous shit like that.
People will say "Discord is a private service and nobody's forcing you to use it" but reality is not as black and white as that.
For example, what if your employer invites you to a meeting using a privacy-abusing service like Discord or Google Hangouts? Are you going to risk telling your employer that you're not joining an important meeting because you don't want to use a service without your VPN? What if some important club/charity/etc. has its members in a Discord group?
These services blur the lines between private enterprise and social utility. Like Facebook, services offering "mass interaction" or whatever should be subject to much stronger privacy laws.
The current state of things can't continue.
It's not a public "social utility". It is a service run by a private company with their specific ToS. I'm getting so frustrated about people not understanding that YOU ARE THE PRODUCT - in many cases like Discord. You will be monitored, your clicks will be recorded, heck you have NO guarantee that the Open Source version they might have is the code RUNNING on their servers. Even if a company claims they can't read your messages or never will: You can't trust it. Ever.
Someone's gotta pay the Ramen.
I'm not going to risk losing my employment, but I'm going to tell them I have a problem using the service without a VPN. If they are willing to fire you for raising privacy concerns then you should have concerns over the culture. Plus most companies I've worked for always want the VPN connected when you are off their network.
Why is discord so delighting in logging everything? Who knows? One low effort answer is: To sell it. Privacy is a commodity that can be sold.
And yes, I use discord for all sorts of purposes.
Hmmm. Might need to rethink things. What alternatives exist? Signal?
The big problem is the ability to create a group chat for text, voice, multimedia sharing, eg images, as part of that chat.
I agree with the article. That said, both being a ruthless bastard and to play devil's advocate, those people also tend to be drama lightning rods and I would happily exclude them given the option.
Just make a cute, free client and people won't care about the underlying tech.
Most of the better IRC clients throughout history have been paid, but when Microsoft Comic Chat was bundled with Windows, IRC got an influx of tons of new users, in an era with generally fewer computer-literate people than today.
That kind of resurgence can be repeated today if somebody can make a free IRC client on par with Discord's functionality.
I'm not really a heavy IRC user, but is it really that hard for somebody to make a slick IRC frontend with a mobile app as well? I would think that IRC already existing takes away the hardest part for making a chat system like this.
[1]: https://riot.im
It won't replace Discord for gamer chat, but for FOSS projects with small communities and privacy-minded proponents, it should fit needs nicely.
Someone's gotta run the trackers.
Options:
- Signal, Wire (maybe) - e2e cloud
- XMPP-based
server - Aenigma[0] - e2e self-hosted XMPP based on ejabberd, preferably in Iceland, Greenland or someplace out-of-reach of regimes unfriendly to human rights
client - Jitsi - multiplatform SIP and XMPP app includes OTR for e2e
- riot.im - e2e Discord-like replacement (of unknown-to-me construction)
- i2p - decentralized garlic routing with multiple services
additionally: VPN - self-hosted WireGuard on an anonymous cryptoc-paid VPS
"John Gilmore, one of the founders of the EFF, once famously wrote, “The ‘net interprets censorship as damage and routes around it.”"
HN should take that to heart.
Why? It's nonsense. If the `net really worked that way, no one would even be concerned about censorship on social media or Discord, because it wouldn't exist.
There's a lot of malicious damage out there, and the Internet has been steadily centralizing, de facto, for a couple decades now.
It's an arms race, basically. I support the defensive side here, but victory is by no means assured.
I think IRC is better. (I think you can also bridge Matrix with IRC, in case you want to have both. Or maybe you can also bridge IRC with Mattermost; I don't know. But they recommend Mattermost, so if you can bridge it in this way, then it can be helpful.)
Don't IRC servers face the same issues of someone being able to read whatever you put through the service?
(More than privacy concerns, a major concern for IRC in this era of mobile devices is protocol chattiness. Phones save battery power by minimizing messages per second required, and IRC's protocol isn't designed to work well with that architecture).
But since this communication is public, anyone should read it if they want to do, so IRC is good.
2) Telegram is not based in Russia. In fact, it's been intermittently blocked in the country.
Remembered me the Win10 installer settings :)
But the article's actual argument is that contributing to a specific FOSS project is a basic human right, which it is not.
The bottom line is that Discord doesn't stand out as a particular offender here, and the steps required to alleviate the author's concerns are inconvenient. Most projects have more important things to worry about with their limited resources.
Communication secrecy simply isn't a priority for most open source projects. In fact it's antithetical to the majority of open source goals. Someone pointed out that users might want to discuss security issues privately, and while there's a little bit of merit to that, it's a contrived example. It's not one of the author's concerns, and it's not an issue that arises with most projects. Open source development benefits from being done openly, and secure communication isn't a priority.
I'm in favor of using open source, private, self-hosted tools whenever and wherever practical. I'm not defending Discord specifically, nor encouraging its use. This author is just hung up on something that most people don't care about, especially in the context of software that's meant to be open and public.
There's something about this sort of obsessive fixation on a non-issue that makes people roll their eyes and not want to work with you. People who are using their limited free time to work on some random small project don't want to be lectured at over principles they don't share.
E2E does have a legitimate downside of letting low-quality content run wild.
Email is a protocol. Implementation is a practical nightmare because of bad actors. Something to control bad actors is vital to any communications system, regardless of whether you classify it as "service" or "protocol."
You have to read and agree to their Terms of Service and Privacy Policy to use their services.
Yes, we all know nobody reads the TOS. It's still extremely inaccurate to claim Discord has these behaviors without asking consent, when they ask for exactly that.
It can still be spyware, even with "consent". The original statement still stands, "silently logging, tracking every action performed". They could just add some text that will be shown when something is recorded.