Discord.io breached, 760k user accounts for sale on darknet
stackdiary.com
stackdiary.com
There was a link to join a discord server via Discord.io that showed as a top Google result.
I clicked it not even aware it was 3rd party. Thankfully OAuth gave me the friendly confirmation page saying "You are about to connect with this third party service and grant full access to your account."
I said WTF? NO
Shame on the Discord legal team and their executive team for completely lacking diligence on this.
Granted, I don't use discord.io , so maybe I'm missing something.
> Salted and hashed passwords (mainly concerning users prior to 2018 when Discord.io began exclusively using Discord for logins)
So it sounds like they used to have their own accounts before integrating via Discord OAuth, and some users may be affected by this. Unsure if they didn't delete users' hashed PWs once they migrated to the OAuth flow or something like that.
They don’t seem to mention it on their website. I don’t see any guideline for how to respect their trademark: https://discord.com/branding
Now the question, does it risk dilution if a company doesn’t say what’s allowed.
Interesting. That about sums up my opinion of their development team.
At least according to the EFF: https://www.eff.org/deeplinks/2013/11/trademark-law-does-not...
> The circumstances under which a company could actually lose a trademark—such as abandonment and genericide—are quite limited. Genericide occurs when a trademark becomes the standard term for a type of good (‘zipper’ and ‘escalator’ being two famous examples). This is very rare and would not be a problem for Canonical unless people start saying “Ubuntu” simply to mean “operating system.” Courts also set a very high bar to show abandonment (usually years of total non-use). Importantly, failure to enforce a mark against every potential infringer does not show abandonment.
This is basically all that log in with Google requires or provides and asking for more access would be abnormal.
https://support.discord.com/hc/en-us/articles/360042987951-D...
But in this case... why was Discord fine with this branding? It looks unabashedly like an alternate official domain for their own service. Googling "what is discord.io" leads to a good handful of confused redditors asking if it's legit/safe.
Isn't this explicitly against the Discord TOS? I'm surprised it wasn't shut down by Discord itself.
Darn that global Internet, allowing people to use unauthorized chat clients with impunity!
The use was not the problem; the name was the problem.
The problem here is that people are chosing to use Disord despite the fact that it is so stupidly proprietary. If Discord actually enforced it's rules all the time there'd have been far fewer teamspeak/irc/mumble/etc people lured into it's walled garden. It is a literal bait and switch.
So it's important to point out a large fraction of the ways people do use Discord are actually very much against the TOS and could be prosecuted under the CFAA as felonies if Discord corporate thought they were rocking the boat and decided to buy a district attorney. It's the worst of both worlds.
This has zero relevance to normal users. Does teamspeak/irc/mumble/etc even support live streaming with screen+audio capture to a group chat? That's a pretty basic feature in 2023. I'm not aware of any serious open source competitors in this space
pIRCh98 had video chat support, and back then we used some wrapper from FRAPS to do our screen captures.
Of course, back then, video chat was such a niche thing.
Everyone else is actually late to the game - IRC had this capability before the majority of known players.
Proprietary software. I guess the answer to my question is no, there are no open-source competitors in this space.
The good news is that even with every scope you can't take over the account and the service can just be removed cutting off their access for sure.
1. confirming the emails were not already listed in other databases / leaks;
2. going to the actual Discord platform and performing a "Forgot Password" request, entering a stolen email, and seeing if it goes through or not, as Discord confirms if an email exists or not during this flow;
3. contacting Discord.io directly, who confirmed & put out a statement.
Other data breaches are harder to verify. Troy Hunt (owner of haveibeenpwned.com) described this in far more interesting ways than I ever could[0], but for each breach, it varies.
[0]: https://www.troyhunt.com/heres-how-i-verify-data-breaches/
https://discord.io/ has been replaced with a termination notice, and they directly mention where the credentials are being sold. Google the name, it's the top result.
Leaked credentials are sold on the open internet, on sites indexed by search engines. This isn't some quadruple proxy Anonymous hacker TOR exclusive club.
Edit: One better - any time you hear Microsoft, or Google, or Crebs, talking about some new "advanced" "Russian" "APT", 9 times out of 10 it's a kid posting on one of these forums, reselling stale credentials, or a fork of Mirai, or some other totally non-credible threat.
This stuff is WAY less cool than people make it seem.
But you can always check at the link below. That guy gets a lot of donated packages of cracked data:
Google also has their own people seemingly trolling through onion sites buying up packages of cracked data so they can run it against their own properties and see if anyone is affected.
discordapp back then was really just a collection of servers pretty siloed/insulated from each other, with barebones voice and text chat functionality.
discordio offered some basic form of discovery and cross-server exploration/networking when it was effectively nonexistent back then. it, along with other outreach efforts on our part, certainly helped boost our community size and amusingly also attracted a lot of teens approaching us to ask if we wanted to "partner up" with their server (i help administer a studygroup server on discord).
my 2c, as a fairly active user since '16.
anyway, 'partnered', to my recollection, means a formal arrangement with discord where the particular server community is directly promoted by discord on front pages and such, in exchange for meeting a higher bar of conduct that represents a model community (SFW, PC, etc.).
one of the perks that comes with this is being granted "Level 3" boost status, free of charge (normally costing anywhere from $49-70/mo, depending on circumstances), which is what directly grants the custom link feature.
.gg and .io are being used for novelty value.
I found: kubernetes.io , sentry.io , codepen.io , itch.io , not to mention lever.co , elastic.co and last but not the least, notion.so .
A tourist attraction in Guernsey can very reasonably use .gg and maintain full credibility.
Thinking through websites I use in Denmark, I struggle to recall one that isn't .dk.
Supermarkets (netto.dk, foetex.dk), public transport (dsb.dk, m.dk, cph.dk), newspapers/TV (politiken.dk, berlingske.dk, dr.dk), University (ku.dk, au.dk), local government (kk.dk), other retailers (computersalg.dk, proshop.dk, elgiganten.dk) ...
The largest grocery delivery company uses nemlig.com, and Ikea uses ikea.com.
As another example, if I'm applying online for a visa to Thailand, that site had better end .th.
And for .io of course that one is/was popular among tech companies because it looks similar to “I/O” (input/output).
It is a little surprising given their field that they didn’t also grab the .io.
(My dog uses the native Discord client because he's too cheap to pay for a baby cam.)
Can you pay for Discord in grissinis?
Serious question though, do you use it as a dog monitor? That’s a good idea.
This way both my partner and I can check up on him if we both leave the house for longer and it's noisy outside. He's a rescue and sometimes gets anxious/loud, but he's getting better.
Side effect: once I came home to spot him with my brothers who live across the continent chatting and drinking beer.
Your last paragraph gave me a funny mental image of your dog sitting in front of a monitor, beer in paw, chatting with your brothers! :)
Meanwhile discord.io is free and you won't lose your URL to a crypto scam server when someone forgets to renew their boost. Kind of inevitable that such a service would pop up.
https://support.discord.com/hc/en-us/articles/360042987951-D...
I remembered vaguely that it was something different from discord.com, and was fooled by discord.io :D
https://en.wikipedia.org/wiki/Mr._Brainwash
(Don't read if you don't want spoilers. Exit Through the Gift Shop is phenomenal and should be watched without knowing about this guy. Watch it, then read the Wikipedia article for yet another surprise.)
“Ghost Kitchens” have a more nefarious connotation than “delivery only” though because often it will be a single kitchen yet be advertised as many distinct restaurants. I saw one in one major city that was something like fifteen “different restaurants” operating from the same small space, which is sketchy.
But I think the person to whom you’re responding was relying more on the word “thousands” here. So given the connotation I think opening thousands of these things is pretty sketchy for some random YouTube personality with presumably no experience with restaurants to be opening simultaneously.
I don't believe the contract between him and VDC is out outlining the contractual obligations, SLAs, trademark and marketing issues etc.