Discord: Difference between revisions
→Incidents: added SDK vulnerability with Arc Raiders |
→Incidents: Activity adding the newest one |
||
| Line 108: | Line 108: | ||
In March 2026, Timothy Meadows, a computer engineer discovered a privacy and security vulnerability that involved Discord's [[wikipedia:Software_development_kit|software developer kit (SDK)]] and integrations with the [[wikipedia:Arc_Raiders|Arc Raiders]] game.<ref>{{Cite web |last=Meadows |first=Timothy |date=3 Mar 2026 |title=Arc Raiders - Discord SDK Data Exposure |url=https://timothymeadows.com/arc-raiders-discord-sdk-data-exposure/ |url-status=live |archive-url=https://archive.is/pktbu |archive-date=2026-03-06 |access-date=8 Mar 2026 |website=timothymeadows.com}}</ref> This vulnerability affected the users with their Discord account linked with the game, allowing the software to log and store locally Discord private conversations, user credentials and other user information in an unencrypted log file. If the Arc Raiders game crashes, this file could be sent to the game developers. Embark Studios disabled the SDK integration after the incident was announced. <ref>{{Cite web |last=Klotz |first=Aaron |date=Mar 2026 |title=Arc Raiders was accidentally recording Discord conversations into an unencrypted local game file — vulnerability in SDK could log messages and credentials in plaintext |url=https://www.tomshardware.com/video-games/pc-gaming/arc-raiders-was-accidentally-recording-discord-conversations-into-an-unencrypted-local-game-file-vulnerability-in-sdk-could-log-messages-and-credentials-in-plaintext |url-status=live |archive-url=https://archive.is/kWBIf |archive-date=2026-03-07 |access-date=8 Mar 2026 |website=Tom's Hardware}}</ref> <ref>{{Cite web |last=Marnell |first=Blair |date=6 Mar 2026 |title=Arc Raiders Was Recording Private Discord DMs |url=https://www.gamespot.com/articles/arc-raiders-was-recording-private-discord-dms/1100-6538629/|url-status=live |archive-url=https://archive.is/2ZQ1M |archive-date=2026-03-08 |access-date=8 Mar 2026 |website=Gamespot}}</ref> | In March 2026, Timothy Meadows, a computer engineer discovered a privacy and security vulnerability that involved Discord's [[wikipedia:Software_development_kit|software developer kit (SDK)]] and integrations with the [[wikipedia:Arc_Raiders|Arc Raiders]] game.<ref>{{Cite web |last=Meadows |first=Timothy |date=3 Mar 2026 |title=Arc Raiders - Discord SDK Data Exposure |url=https://timothymeadows.com/arc-raiders-discord-sdk-data-exposure/ |url-status=live |archive-url=https://archive.is/pktbu |archive-date=2026-03-06 |access-date=8 Mar 2026 |website=timothymeadows.com}}</ref> This vulnerability affected the users with their Discord account linked with the game, allowing the software to log and store locally Discord private conversations, user credentials and other user information in an unencrypted log file. If the Arc Raiders game crashes, this file could be sent to the game developers. Embark Studios disabled the SDK integration after the incident was announced. <ref>{{Cite web |last=Klotz |first=Aaron |date=Mar 2026 |title=Arc Raiders was accidentally recording Discord conversations into an unencrypted local game file — vulnerability in SDK could log messages and credentials in plaintext |url=https://www.tomshardware.com/video-games/pc-gaming/arc-raiders-was-accidentally-recording-discord-conversations-into-an-unencrypted-local-game-file-vulnerability-in-sdk-could-log-messages-and-credentials-in-plaintext |url-status=live |archive-url=https://archive.is/kWBIf |archive-date=2026-03-07 |access-date=8 Mar 2026 |website=Tom's Hardware}}</ref> <ref>{{Cite web |last=Marnell |first=Blair |date=6 Mar 2026 |title=Arc Raiders Was Recording Private Discord DMs |url=https://www.gamespot.com/articles/arc-raiders-was-recording-private-discord-dms/1100-6538629/|url-status=live |archive-url=https://archive.is/2ZQ1M |archive-date=2026-03-08 |access-date=8 Mar 2026 |website=Gamespot}}</ref> | ||
Before the incident was known, when an user linked their Discord account, a pop-up claimed that Arc Raiders "cannot read users' messages". {{Citation needed}} | Before the incident was known, when an user linked their Discord account, a pop-up claimed that Arc Raiders "cannot read users' messages". {{Citation needed}} | ||
=== Discord's Protection of Sexual Predators and Pedophiles (March 2024 - Present) === | |||
In March 2024, Discord sees pedophiles as a protected class; they don't even care about your children. Anyone who takes action against them will be hit with the [https://discord.com/safety/hateful-conduct-policy-explainer hateful conduct policy] first offence on discord for going after pedophiles will be shown in the image on the right. | |||
==Solution to delete an account without agreeing to the updated ToS== | ==Solution to delete an account without agreeing to the updated ToS== | ||