• mateomaui@reddthat.com
    link
    fedilink
    English
    arrow-up
    82
    ·
    edit-2
    11 months ago

    Maybe the dipshits who host the updated GoXLR firmware and software solely on Discord will finally take the advice to put it somewhere where it actually makes sense, like on their own fucking website where it should be.

    • Chloyster [she/her]@beehaw.org
      link
      fedilink
      arrow-up
      9
      ·
      11 months ago

      Unfortunately seems like this won’t help that, if they expect you to be on the server to get the files. The article says the links will be auto refreshed daily, so it’s only the links shared outside the server that won’t work after a day :(

      • mateomaui@reddthat.com
        link
        fedilink
        English
        arrow-up
        7
        ·
        11 months ago

        FUCK. You’re probably right. It’s such a ridiculous thing they make us go through just to get updated installers. Last I checked they don’t even make it obvious what the commands are to get the download links, you have to ask for them in chat and wait for someone to eventually reply back with them. It’s so annoying, they could just put the installers on the website next to the outdated one that’s been there forever.

        • Chloyster [she/her]@beehaw.org
          link
          fedilink
          arrow-up
          4
          ·
          11 months ago

          I feel the same way. I end up being in 30 or so different Pokemon ROM hack servers just to get the patch files for the games. Very frustrating to have to do that when there are websites dedicated to hosting these files

  • RocketBoots@programming.dev
    link
    fedilink
    arrow-up
    21
    ·
    edit-2
    11 months ago

    This is a very sensible change. It’s an open secret that discord has been leveraged by hackers for quite some time. You can even search Github and find examples where exfiltration of data is done via discord. Discord is not a file host and should not be used as such. I’m just glad they’re doing it in such a way to minimize the impact on users and devs.

    • i_am_not_a_robot@discuss.tchncs.de
      link
      fedilink
      arrow-up
      2
      ·
      11 months ago

      I don’t know how much of a difference it will make.

      It’s easy to host files. Even if the malware “author” is clueless and just buying a customizable malware, either they’ll figure out how to host files or file hosting will be provided along with the service they’re buying.

      It may not stop Discord from being the file host either. Malware distributing bot accounts could keep copying a new link to the file, or could upload a new version of the file on demand.

      Discord can’t expire webhooks the same way so webhooks will continue to be used for exfiltration. Pointing out that it’s used for exfiltration as if it were related seems like bad reporting. It’s a difficult problem because if they did break webhooks it’d only make things more difficult for legitimate users. These malware packages usually hijack the user’s Discord installation and could send out the information as the user without using webhooks.

  • AutoTL;DR@lemmings.worldB
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 months ago

    🤖 I’m a bot that provides automatic summaries for articles:

    Click here to see the summary

    The company told Bleeping Computer that doing so will help the company fight malware spreading on its platform since that gives it more ability to “restrict access to flagged content.”

    According to the article, Discord says the change won’t affect anyone sharing content on the platform, as links within the client will be refreshed automatically.

    However, links shared outside of Discord won’t work a day after they’re regenerated.

    The company said that it will share more “in coming weeks” with developers, who “may see minimal impact.”

    As Bleeping Computer notes, cybersecurity company Trellix reported it had “found around 10,000” malware samples distributed online that were stored on Discord’s content delivery network (CDN).

    Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.


    Saved 18% of original text.

  • totallynotfbi@lemm.ee
    link
    fedilink
    arrow-up
    4
    ·
    11 months ago

    I’ve looked around malware link scrapers (ex. URLhaus) before, and I recall seeing that a large portion of the malware links were hosted on Discord, especially trojans. Although it will break a lot of legitimate shared files, I respect them for fixing this security issue