I wonder who thought that would be a good implementation. Client-side validation seems like a very novice mistake.
I wonder who thought that would be a good implementation. Client-side validation seems like a very novice mistake.
it's borderline (or completely ?) illegal to threaten users to ban them if they choose to use their right to mass-delete their previous messages.
- It's cheaper not to check on every call sever-side and the people who are most likely to dodge in this way are also not likely potential sources of revenue.
- you shouldn't ban every person who tries this. They will gum up support and, on average, won't even be trying to earnestly get features for free.
- Also people who exploit the obviously vulnerable account interfaces may do other things that clue you in to vulnerabilities you care about.
It seems like it's a situation where you can let people fiddle around with this a bit (a few hours, a few days) and ban folks who do it too long (a month?). People who use it heavily are unlikely to be real revenue prospects and, at the end of the day, it's an engagement funnel. People rarely use hacks on a platform they aren't using.
You gather a bunch of offenders for weeks or months and then one day they just go poof and everyone knows why.
This way you can weed out the ones who were just experimenting (few attempts) from those who use it regularly.
I thought the point of ban waves was precisely because there's no direct cause-and-effect. E.g., if you perform an exploit and get banned immediately, you know that the system can detect your exploit. If you get banned a month later, it might have been your exploit or something else you did between then and now.
This reduces the selection pressure on black-hats to produce ban-avoiding exploits.
As someone who only sends up PRs containing complete features in their final state implemented exactly as I hoped, I have no idea.
Unrelated aside: just started my fifth new job this month. I never seem to jibe with project managers.
Of course, I am a contractor...
In my opinion paying the $10/mo (if I needed/wanted the features) is way less hassle than trying to keep on top of the mods, which probably break at every Discord update, and then hope the maintainers don't slip in exploits.
My point was exactly: how many people want to go through all of this AND would instead pay IF this route wasn't available?
a 12 year old without money won't pay for your service no matter what you do, so does it matter if you let them "hack it" for free?
I'd consider it similar to Adobe's old model (easy to crack, but converts to paying customers in a few years)
It's been a long time since I did any Discord API work but I had assumed they would have fixed this by now. I realise it makes things simpler and more cacheable, but IMO it's a critical and inexcusable user privacy issue to have this behavior with no indication to ordinary users that their hidden channel is in fact quite visible to savvy users. This would be like Google Drive allowing anyone to query filenames (just not content) of private folders
Their voice server only checks with the API to verify if you're allowed to join. Beyond that, it becomes a one-to-many packet broadcaster.
Maybe focusing on this security would have stopped them performing so well
Are they? They try to sell me Nitro at least once every month, which only gives me the impression that they're desperate to increase their revenue stream to make ends meet.
It's remarkable how much data they are extracting, if the average user knew there would likely be multiple scandals or legal proceedings
People just didn't share illegal, confidential or secret things with their own name and IP address or counted on the server admin not caring.
Of course there's the threat of data leakage, buuuut it's risk I accept, when it comes to my mundane usage of discord.
My main gripe with data collection platforms is how they turn every platform into an ad board. Chief among my disappointments is windows. It's so thoroughly shit now I can't even consider myself a user. I can't really call it an OS anymore. It's something else... An advertisement platform built on top of an os.
How people communicate on Discord isn't something you want to teach any AI you intend to use publicly =)
I have gigabit connection at home and a good GPU that does the encoding but I guess Discord doesn't have any servers near me (~1900km to Rotterdam) and it might be prioritizing low latency. The experience was terrible so I cancelled the subscription. All the other paid features seemed useless to me.
For example with AV1, if someone joins without an AV1 decoder, it fallbacks to h264: https://twitter.com/gerdelgado/status/1618285964308402180
Which is very easy to do - you can find tons of freely joinable 'official' servers for games, which are boosted, and then join one of the available voice channels.
I didn't think of this thank you! I wanted to stream in my friend's server for my friends to watch but his server isn't boosted, but now I'm gonna join a random server and stream for strangers instead!
We're talking bandwidth here.
Checking for upload is not the issue imo, the issue is that you can watch a 1080p stream a non nytro user, if you don't check it at the upload stage then you should make sure that people can only watch 720p streams.