“Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.”

  • KairuByte@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    72
    arrow-down
    3
    ·
    11 months ago

    This is… annoying. I get the intent for malware, but honestly it’s a BS reason. The content will just be uploaded elsewhere. But what this will do is drastically lower their storage cost under the guise of… not even user safety, more “slightly inconveniencing malware writers.”

    • LufyCZ@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      11 months ago

      Yes, it’ll be uploaded elsewhere. That’s the whole point.

      Discord doesn’t want to host any of this data, they don’t want to be connected to criminal activity. It makes sense.

      Also, while it might slightly lower their storage costs (if the hackers move elsewhere), if you send a file to someone, it’ll still stay on Discord’s servers. Only difference is the link to said file - it’ll only be valid for a day, and then you’ll have to use a new one (in a way that’s probably transparent to the user)

  • justaveg@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    3
    ·
    11 months ago

    lol@ this. My bet what is actually happening: cost cutting or future nitro feature.

  • Chewy@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    9
    ·
    11 months ago

    It’s an annoying change for anyone using discord to share files outside of it’s closed platform but doesn’t affect most people.

    I wonder whether bridges for matrix have to be fixed or if they’re already editing messages bridged to matrix to the new url.

  • ndguardian@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    11 months ago

    Honestly, I’m okay with this at least until they fix the fact that all shared files are accessible without authentication. Granted, you still had to get the link before downloading an uploaded file, but the fact that there was no authentication required to download a file uploaded to Discord was pretty surprising.

    • computergeek125@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 months ago

      It’s probably also way cheaper to do it that way. As far as I could tell when I checked in on it some time ago, most of the content goes through a Cloudflare proxy straight to a GCP S3-compatible bucket.

    • uis@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      11 months ago

      You still need to know magical numbers to download file.

    • LufyCZ@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      11 months ago

      What is a password? A string of characters. What is a link? A string of characters.

      If you make it long enough, it’ll be impossible to guess one.

      Your files are safe