The Future of discord.py
gist.github.com
gist.github.com
I don't write discord bots so you can type a slash command to do a thing. That's boring. Good bots can read messages. Discord will be very "not dope" and "not cool" if bots are forced to become a sterilized pick-list of interaction options.
https://support-dev.discord.com/hc/en-us/articles/4404772028....
Time will tell, I hope I'm proven wrong. I hope that preemptively voicing my concerns helps keep the conversation going to make sure small bot authors aren't left in the dark.
Are there large bots that are particularly dynamic? Every bot i've seen with any real usage across servers has a !help command with a static set of commands. Plus, on almost all of them you can change the command prefix to a special character like `~`, which was very needed with multiple bots defaulting to the `!` character, thus causing multiple bots to respond at once to commands where the user only intended one bot to respond.
Core functionality is of course behind a prefix, but that's just convenient.
Sorry for rant I moderate a sizable Discord and these are burdens a lot of political or reasonably large servers face. We get fresh raids every other week with thousands of accounts. Idk why Discord finds it normal that thousands of accounts would join any server within a minute and spam user DMs and leave. These are red flags.
It’s like a bad troll face meme
A real-world example I base this on: Twitter started squeezing developers after the IPO in ways that only make sense for a company that wants to control the experience for monetization purposes. They were desperate to justify their stock to investors. Discord might be on the same track.
I wrote a bot and then realized my boy can easily log everything even tho it was only posting some updates from somewhere else.
Since then I've been restricting bot permissions as much as possible. Most bots these days directly want admin permissions in every channel. They don't need it. They can get their 99% things done with slash commands. I should be able to deny message permissions and get those 99% things working.
If your bot is not in your own channel and is reading messages, you should be fully verified by discord.
If it is your own channel and you _host_ the bot server, you should be able to anything without verification.
Well, yes. If you join the server yourself it’s even worse. You’ll immediately be able to see it’s entire history. No logging necessary.
The issue is most bots setup instructions include adding them with tons of privileges including admin even if they don't need it. Then they get private channel access and can log those. This is not really apparent to most (non-engineering) people.
I think bots that can read messages, should always be self hosted instead of some random 3rd party.
Most bots just post updates and responds to commands. / Is the way to go.
As a user in a server, you don't really have a way to consent to whatever third party bots reading your message. You've just got to hope you see that the bot was added, or see it in the user list. The server admins consent to the bot being added (and as an admin you still need to hope and trust that they're not doing anything dodgy with all the unnecessary information they're getting), but no one else in the server gets to consent or is made aware of the new audience they're broadcasting to.
I think for the broader Discord community - which is pretty broad with a lot of younger and non-technical folk - making reading messages a privilege intent is the right move.
If you restrict this capability then ultimately you'll just end up with bots pretending to by users.
User bots I think is a different, equally valid problem (if not more problematic) that's probably harder to solve. "Rogue bots" look just like normal bots that a server admin would voluntarily install without knowing what it's dong behind the scenes. Bot users are actively malicious and breaking the ToS, and can't reach the same scale as bots (because all server admin cannot just add one to their server).
I think they're both problems, but represent different points on the threat matrix. It's kind of like saying "iPhone shouldn't restrict access to the camera roll for App Store apps when viruses can just bypass and get them anyway".
Besides, if you say something on a public discord chat it's like saying it on Twitter.
Good bots are not made for proprietary platforms.
I think Discord requiring ID for large bots is a right step towards being able to hold these bot authors to account. But it's not enough.
The only thing this prevents is new bot authors from, well, writing interesting bots.
Soon I fear my efforts are going to be thrown away because I dont want to expose personal information with Discord.
How long before we read a headline here on HN that someone hacked all Discords verified bot developer information? No thanks.
Message reading bots are very useful for many things. Limiting them because of privacy concerns sounds like a loss for no gain to me. There isn't any privacy on Discord to begin with.
My general pessimism with this situation is how proprietary everything has to be to begin with; the idea of a single company storing the full history of everyone's messages and interactions is already bad enough without them requiring the government ID of their users.
I'm tired of platforms asking me for my government-ID to allow me to use them. I'm tired of having every message I type 'privately' to someone being stored and owned by a company that has no obligation nor motive to treat it the way I'd want. I'm tired of being forced to 'log in' to services just to read important information (now being trialed by Twitter and Reddit as well!). Honestly I am just tired of having what feels like no rights or control whatsoever in the general online sense of my life, having to deal with and accept whichever new 'feature' or 'usage of my data to improve my experience' the products I 'choose' to use decide to rollout.
I apologize for this turning into a such a rant, but this has been upsetting me a lot lately. I have this wonderful illusion of choice of which products I use, but the punishments I receive for trying to opt-out have become untenable in the last few years. I can't even pay my rent without using a finance app that scrapes and sells my transaction data (which app does this? almost all of them), let alone get help with free software when the answers to my questions are now all contained within Discord chat history which asks for my phone-number to join so that I may even search it, rather than on an openly-searchable forum.
While I still am able to use the software I prefer like Signal, IRC, and Matrix with some of my unique technically-gifted friends, the network effects of having millions/billions of users and owning all of their data are a particularly strong force that I have not yet found a way to reckon with.
Effectively we have they choice of iphone, Android or complete Luddite.
The only reason you can't find important information without logging in is because these consumers profit off of the product by using it as the only place they post their findings (profit, as in, not having to deal with the headache of posting something to multiple news feeds and go through the cruft of editing a personal website with insignificant <280 character content). If these products were terrible, people might be more open to designing a website in their own image with the information in the format they choose.
As a non-user of both Twitter and Reddit, I'm genuinely curious about what "important information" is there that isn't anywhere else? Presumably I'm missing something big?
My experience with Twitter is more limited, but I know people use it as sort of a microblogging platform sometimes and it benefits from the same ease of posting+content aggregation setup I mentioned earlier.
This is all my take, of course! I just hope we can avoid balkanizing the internet, despite all of the incentives these social media companies have to do so.
For Reddit, some programming languages and frameworks have a subreddit on which issues or solutions are discussed instead of Stackoverflow
> the crux of malicious bots were, and still are, user-bots.
Seems almost laughable that Discord is making hoops for legitimate bot developers to jump through while taking little action against user-bots.
I suspect that Discord wants to get a chunk of the big money that game bot developers are making, and are pushing bot developers into a more rigid API that will eventually include in-app-purchases. The article author also said:
> No longer will bots thrive with a sandbox limited only by your imagination, but instead Discord is now the sole gatekeeper of approved use cases. The future of Discord bots relies solely on the interaction system; things have to be explicitly written and supported by Discord employees
That said, I can't express how frustrating it is to see a platform you're so grateful for grow so much in such a short amount of time, and gradually become worse because of it (or, at best, see no significant improvements). Over the years I have vented over and over to anyone who would listen about the ways I want Discord to be better (not for me, but for everyone), and I don't think I have the energy to do so anymore. I could write huge lists about the basic features Discord is missing, but to me it's a slap in the face whenever Discord prompts me to "join my university's server by inputting my e-mail" (even though I'm not a student), while 6 years after launch you still cannot collapse the sidebar on the left that insists to take up 300px of your screen no matter what.
I understand that it's pointless to complain to deaf ears. Over the years I have applied to work at Discord countless times, even talking to one of their managers over LinkedIn, but unfortunately we couldn't make it happen because of USA Visa restrictions. Because of this, I'm forced to sit at home watching a platform that has given me so much deteriorate over the years. I have considered building a competitor, alternative clients, and even bridges to other services like Matrix, but alas I'm stuck here.
Despite it's recent missteps, Discord has, if nothing else, provided us with an excellent technical foundation of what a modern one stop shop communications platform should look like. I'm keen to be involved at any level of a competitor.
The sidebar bothers me all the time, when I want to have two windows side-by-side on my screen. The actual chat ends up being smaller than the sidebar.
I wrote a javascript bookmarklet that automatically shows/hides the sidebar element on hover. I've gotten a lot of use out of it. It's 821 characters --- less than three tweets long.
Why haven't they solved this problem for users? It's shocking that the only way to shrink the sidebar is to inject javascript.
javascript:(function(){ function sleep(ms) { return new Promise(resolve => setTimeout(resolve, ms)); } let sidehover = false; let guildhover = false; let sidebar = document.getElementsByClassName("sidebar-2K8pFh")[0]; let guildbar = document.getElementsByClassName("guilds-1SWlCJ")[0]; async function hide() { await sleep(50); if (!sidehover && !guildhover) { sidebar.style.display="none"; } } async function show() { await sleep(150); if (sidehover || guildhover) { sidebar.style.display=""; } }; guildbar.addEventListener("mouseenter", () => { guildhover = true; show(); }); guildbar.addEventListener("mouseleave", () => { guildhover = false; hide() }); sidebar.addEventListener("mouseenter", () => { sidehover = true; show() }); sidebar.addEventListener("mouseleave", () => { sidehover = false; hide() }); hide(); })()
The `sleep(150)` and `sleep(50)` can be tweaked to adjust the delay between when you hover over the server bar and when the channels bar is displayed (that's the 150 ms) and between when you move the mouse off the side bar and when the channels bar disappears (the 50 ms).
If you're using the electron desktop app, you can open the javascript console with ctrl-shift-i and paste it in there for the same effect.
edit: i before e
I guess this is the end of an era
That being said, they already have a revenue stream in Nitro. I don't see them caving into advertising and selling user data very easily. Especially this late in the game where all their users are used to not having them.
It's gotten pretty far from the good old days of IRC --- which I'm quite aware is still alive! --- and that's both good and bad at times. But one of the biggest flaws is that it's not an open standard. (Interop is only done by prohibited programs like Ripcord!)
Unsure what you mean by “not a standard” - all APIs of the Matrix spec have been successfully implemented at this point by indpependent developers: this makes it an open standard. Eventually, once the standard has reached maturity, we may try to contribute to W3C or IETF - or we might turn it into a dedicated standards body like W3C did for the Web.
Just wanted to say that I had a completely different read of Mason's response - without any other context, it seemed like he was joking around. "We won't ban you, y'know, unless you're into that kind of thing" style. Am I totally off base?
I think a lighter interpretation like "We won't ban you unless you want us to" has a different context that usually doesn't follow a question about your service in particular banned, nor does it imply someone might have a specific "quest" to be banned - especially as a random person who also has had grievances with low communication to the point of making a competing API discord.
In this context, it feels very rude.
That's not how I read it, I think almost everyone would read it as Rapptz did.
Tone is difficult to gauge over the Internet. Maybe Mason just messed up how it would be interpreted. I suspect we've all done that. I know I have.
But the term "martyr" is a really loaded one. This didn't feel like a playful tone misjudged to me.
Both of the Discord employees in that were screenshotted come out of this looking really bad. Unprofessional and hostile. The question is just whether they were actually also hostile, or just unprofessional.
This is a recurring theme and I am puzzled that there isn't a bigger dev audience at internet of ownership ( https://ioo.coop/ ) or for platform cooperativism ( https://platform.coop/ )
Which means if your platform doesn't let me talk to the users I personally want to talk to/do the things I want to do, I'm not going to write anything for it without compensation.
In other news, water is wet.
Sorry for the snark, but WHY DOES THIS KEEP HAPPENING? Is it just not happening frequently enough for people to take note or learn?
Quick, move your whole infra to the azure cloud, M365! 3000% price hike? Better accept it or you'll be shut down. Can't even just keep running the old version, cause you're not actually running anything anymore yourself.
It seems to me like Discord has, for some reason, decided that small bots are a problem. Which is a bummer.
I've been on Discord since 2016, in programming and academic circles, and the grassroots bot community has always been amazing. I'm in a server with 30 of friends, which has 4 bots made by members of the server.
Something about the simplicity of listening for messages, parsing them how you want, and sending back text that shows up just like a user is really satisfying. I know it's been a motivation for many people who have little to no interest in programming anything else.
Even though unpaid in the programming field, very much a professional IMO.
First it was AIM/YIM, then MSN, then Skype, then Discord, and so on. Some people used IRC or ICQ or whatever, or still do, I know. But many of us have migrated from one platform to the next as each one was ruined in turn.
By the way, check out how hard Discord makes it to report abuse: https://support.discord.com/hc/en-us/articles/360000291932-H...
This is, funnily enough, easier than it used to be - you used to have to enable an "advanced setting" to even see the message ID.
From a dev POV, I'd say it is a deliberate choice from Discord. If they added a "Report" button to every message, people would assume that the report is sent to the server manager and mods, so there'd be a heap of reports while the messages do not necessarily break Discord's TOS, but rather the server's rules. It's the kind of thing that you need to establish/take into account when enabling customers to create their own "platforms."
Always assume that customers do not read everything, even the most important messages. (Because they don't.)
> Or, add true reporting functionality for mods themselves.
Yes, this could be a solution.
> At the very bottom are plugins, extensions, mods and hacks. They fundamentally depend on the indifference or obliviousness of a larger company, who they often mean very little to. And when their goals differ the larger company always wins.
Any third-party dependent on another party will be at the whims of the other party. yt-dl can see it happening with age-restricted videos, people using tools to migrate from Spotify depend on them turning a blind eye to leaving customers taking their data with them, fan-made games that continue a story (pokemon for example) and get a cease-and-desist, probably many other examples, and now this too.
Kudos to this dude for writing an entire framework for bots as a friggin' doctor in his spare time. Hats off for staying at it for so long. Also, respect for drawing a line in the sand and not giving in to any demands from Discord or users to just lie down, take it, and continue developing the framework with more constraints.
In a similar vein, discord doesn't allow custom clients. I think this is a situation where the legal situation should be adjusted.
This also explains why discord is so focused on bots using the bot-api, instead of user-bots. Bots using the API are in some sense condoned by discord, so it's much easier to argue that they're liable for abuse. While user-bots are already disallowed and get banned when detected, so they can already argue that those aren't their fault.
2. Bots often require excessive privileges. For example music bots wanting the right to read messages in all channels or even manage channels (presumably for easier setup), while they should be fine with slash commands and other harmless privileges. I would like to see bots reduce the privileges required to use them.
3. It sounds like the transition was mishandled by discord
Can you imagine such a tool to one of your customers like that? It seems unfathomable. Is Discord full of these types of people?
Working for Discord and getting that badge must give you quite the ego boost. Conversations with them feel very arbitrary and it's like they consider any word they say to you wasted - of course this doesn't have to apply to all of their staff, but it's certainly a pattern.
Think a lot of companies who were in the bidding war for Discord dodged a bullet when Discord pulled themselves off the market. Reading the way the people "Mason" and "kadybat" mentioned in the gist conduct themselves with users, especially competent library developers, of the service is concerning. Might even prefer if a BigCorp™ expand their more sterile chat client into Discord's market at this rate.
Perhaps the goal is to kill the bot dev community in order to centralize it around Discord corporate, and then start putting more bot-related features behind Nitro and other subscription paywalls.
Seems like a nasty way to go about it, but I can't imagine any other reason to behave this way towards a community of unpaid volunteers who add tremendous value to your platform.
I think there's a lot of potential for a VC-funded startup to pour some cash into Matrix and then swoop in when the Discord ecosystem eventually starts falling apart.
0: > Discord declined to share how many Nitro subscribers it has, but the Wall Street Journal reported that Discord generated $130 million in revenue last year, up from $45 million in 2019. In the same time period, its monthly user base doubled.
0: https://qz.com/2034087/chat-app-discord-is-shedding-its-game...
Edit: I mean, imgur has an estimated revenue of twelve million. Staple a hundred IRC servers on the side and you have most of discord's functionality accounted for. Unless the voice calls are really tough, and they're actually a streaming company by majority of expenses, where would the costs come from?
Can someone explain why that is? My understanding is that adding bots to a server requires Admin/Owner access, who are already at liberty to read all messages. If you don't trust bots scraping your messages in a server, don't you implicitely distrust the owners? Just leave the server?
That said, this looks like very poor communication and imposition of a lot of developer toil on Discord's part.
If the OP fails to present or hide the full picture to me it harms his credibility.
> Most library developers felt the changes were misdirected and targeted the wrong type of bot. The threat model was based on user-bots being bad actors, and not regular bots, while the changes targeted regular bots. We also felt that it was easy to sidestep the restrictions by just having a bot ring, similar to what is now done today with user-bots.
> Discord claimed [the new requirements, including government ID] would help with security and privacy by preventing malicious bots from growing and obtaining sensitive data. The library developers responded that it wouldn't help since malicious bots had to be invited and the crux of malicious bots were, and still are, user-bots.
Seems like a reasonable description of the issue to me, covering everything in that comment.
If you feel it gets lost in the words then I think the proper thing to criticize is the writing style, not the credibility.
(If the term is unclear, "user-bot" means it's a normal user account being used in an automated way.)
I run a bridge but that's just one server.
Guess I’m back to IRC.
I get people complaining about this situation, but there is a gradient of access between "no content access whatsoever" and "the bot can see everything". Slack's API does a pretty good job of making some of this work
The bot can do interactive button/menu etc. I have been putting lot of my automation into Telegram bot.
GameSDK is not an option for some applications, such as those wishing to include only open-source dependencies.
Tweepy is a perfect example, although I don’t think they’ve halted.