Discord fined €800k
cnil.fr
cnil.fr
https://news.ycombinator.com/item?id=33637977 (258 points | 9 days ago | 285 comments)
Sounds like a fun and entertaining publication.
Is it? I suppose you can take their turning down of Microsoft as a token of good faith, but it's also possible that they just think they can cash out for more in the future. If that's the case, then accumulating a massive user dataset is very much the business model, because the business model is to eventually sell the company for as much as possible.
Absolutely not arbitrary at all :')
That's strange, given the software's functionality includes showing friends and people in servers you're in what games you're playing, for how long, and even what game mode and so on. There's zero chance they're not monetizing that in some fashion. Almost certainly in aggregate, but I'd be shocked if they aren't doing non-aggregate data sharing behind some very tightly closed doors.
Also, just an fyi that tencent has heavily invested in Discord - though the exact amount is unknown.
How is this "time" and not "infringements" from your view?
>Discord not deleting inactive accounts
I personally don't want my old accounts to be deleted. Just because I don't sign on to a site that doesn't mean I want everything to be deleted.
>Closing the Discord window doesn't quit the entire application and just closes the window
This is normal behaviour of programs. In fact most macos programs work this way. Windows still shows Discord in the bottom right no people can access it if they need it even if they don't want a window for it.
>Discord's password requirements were not what they wanted
Most people's discords accounts are stolen via token stealers and not by having their passwords guessed. They had proper rate limiting so this isn't a big deal.
>They didn't create various paperwork
Legal compliance is annoying.
I hate how foreign governments can trample over US products.
As if the US government never trampled over non-US companies. The US runs one of the most protectionist economies out there.
Excuse me, it's the EU who determines what is normal and what is not. Not some decades old conventions.
On my computer it goes to a little arrow menu in the bottom left where you can't see it unless you click in. And when I first found out this behavior I ended up accidentally treating a lobby to some very bad singing.
I'm very skeptical of GDPR regulation, including multiple of the other things CNIL listed here. (If your "data protection impact assessment" concludes that there's nothing high-risk, doesn't that suggest it wasn't in the GDPR's bucket of "likely to result in a high risk"?) But this point seems pretty reasonable.
Let's say you're a community moderator, and you type out the rules for the community. Well... now, unless someone wants to re-do everything you did, those rules will forever say, "YourName said..." and if someone leaves a server, and asks for their content to be removed... it would make for a big mess for users and moderators, "See the pinned posts!" "Uh, what pinned posts?"
Also, quotes and replies of your messages... do those have to be removed? Someone responds to your message, and quotes, "> YourName said..." before their response. And along the same logic... there are a lot of bots that automatically track all the updates to messages, so that people can't say something nasty, and edit it and say, "No, I didn't say anything nasty!" The bots see all... and normally they record it in a public channel for the admins, where the bot just says, "YourName edited their post from X, to Y!" Do all those have to be removed?
Not to mention emoji, and sponsorship, and the list of "joined the server" / "YourName kicked SomePunk because..." where the admin leaves a note outlining why they booted someone. Would all that have to be expunged upon request?
Dunno man, I'm all for GDPR, but I think Discord is sort of like Hacker News... like public forums shouldn't have to remove content someone put up. Just find a way to change ownership or change YourName to [DeletedUser123] would be fine... still sucks from a UX perspective I think, and all the messages quoting you, and bots recording your changes... those are still there. Can't really un-pee in the pool. But you know that using Discord.
Edit... I confused GDPR with CCPA for "request to export" / "request to delete" -- sorry. Meh, I'll leave this up because I'm an idiot, and I still think Discord / "public" places should be except from requests to delete data.
Coincidence I THINK NOT
> The restricted committee considered that DISCORD's password management policy was not sufficiently strong and restrictive to ensure the security of users' accounts.
Ahh yes, finally, government-enforced password policies. They have lost their mind.
> However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applications.
And they have thoughts on UI design too!
This is like the opposite of what GDPR should be.
When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applications.
DISCORD's behavior is different and may lead to users being heard by other members in the voice room when they thought they had left. The restricted committee considered that DISCORD should specifically inform users by making them aware that their words are still being transmitted and heard by others.
However, as part of the procedure, DISCORD INC.set up a pop-up window to alert people connected to a voice room, when the window is closed for the first time, that the DISCORD application is still running and that this setting can be changed directly by the user.
> When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applications. > > DISCORD's behavior is different and may lead to users being heard by other members in the voice room when they thought they had left. The restricted committee considered that DISCORD should specifically inform users by making them aware that their words are still being transmitted and heard by others. > > However, as part of the procedure, DISCORD INC.set up a pop-up window to alert people connected to a voice room, when the window is closed for the first time, that the DISCORD application is still running and that this setting can be changed directly by the user.
Rather the issue was that you could close to tray while in a call without any prompt.
When a user logged into a voice room closes the DISCORD application window by clicking on the "X" icon at the top right of the window in Microsoft Windows, they actually just put the application in the background and stay logged into the voice room. However, in Microsoft Windows, clicking on the "X" at the top right of the last visible application window will exit the application for the vast majority of applications.
DISCORD's behavior is different and may lead to users being heard by other members in the voice room when they thought they had left. The restricted committee considered that DISCORD should specifically inform users by making them aware that their words are still being transmitted and heard by others.
However, as part of the procedure, DISCORD INC.set up a pop-up window to alert people connected to a voice room, when the window is closed for the first time, that the DISCORD application is still running and that this setting can be changed directly by the user.
> Ahh yes, finally, government-enforced password policies. They have lost their mind.
Sure arguing over the password policy itself is somewhat silly however those shorter/lower complexity passwords are trivial to crack in the event of a data leak even when properly salted and hashed.
> And they have thoughts on UI design too!
This one makes perfect sense. The complaint is that you can close the window while in a call without any prompts. It's not that the UX is bad (IMHO it's very useful) but that it can lead to accidental leaks of information that could be trivially avoided with minor changes.
The solution to this is trivial. Prompt on close (but not minimise) when in a call to warn the user and provide a setting to hide this prompt.
And because of habit to have minimize-to-tray on [x] I would also dislike moving that option to [_] and reserve [x] to exit. I know I will just press it because of habit and close my active chat with app. And discord is not fast app to load on my PC.
But technically it will be best solution if they want to comply with the requirements of officials. Or maybe already implemented one-time prompt is enough for them.
Ideally it's a warning that you can disable. With safety/privacy it's generally preferable to have warnings as the default and allow users to take the trainer wheels off rather than risk a new user exposing themself accidentally.
A non-paywalled (but not great) article (use an ad blocker): https://www.bankinfosecurity.com/discord-fined-by-french-cni...