Discord file links will expire after a day to fight malware (www.theverge.com)
from kalkulat@lemmy.world to selfhosted@lemmy.world on 05 Nov 2023 23:37
https://lemmy.world/post/7849757

“Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.”

#selfhosted

threaded - newest

dandroid@dandroid.app on 06 Nov 2023 00:23 next collapse

I wonder if McAfee changing their name to Trellix to escape how much the general public hates them will work better than Comcast rebranding as Xfinity.

[deleted] on 06 Nov 2023 00:46 next collapse

.

dandroid@dandroid.app on 06 Nov 2023 04:13 collapse

Idk, but this issue was discovered by “Trellix” which is McAfee.

SheeEttin@lemmy.world on 06 Nov 2023 00:47 next collapse

The general public doesn’t hate McAfee that much, so I’d bet it’ll work. Heck, I work in IT and I didn’t even know about the rebrand (mostly because I engage with McAfee as little as possible).

TonyTonyChopper@mander.xyz on 06 Nov 2023 05:05 collapse

probably about as well as Twitter becoming “X, formerly known as Twitter”

scrubbles@poptalk.scrubbles.tech on 06 Nov 2023 05:43 collapse

Yeah let’s keep that going here. From here on our whenever I see Trelix I will say “Trelix, the brand fomally known as McAfee.”

Jumuta@sh.itjust.works on 06 Nov 2023 14:50 next collapse

or just call them mcafee, twitter, facebook, etc

scrubbles@poptalk.scrubbles.tech on 06 Nov 2023 16:30 collapse

Yes, but I like this because it ingrains in people’s heads that when they hear Trelix they should think McAfee, to make that connection. Like with Xfinity, they don’t want that connection made, they want people thinking “Oh I don’t have that crappy Comcast service, I have Xfinity”. I’ll be saying it this way to show people that they’re the same thing

Jumuta@sh.itjust.works on 07 Nov 2023 02:06 collapse

fair point, maybe I’ll do that from now on

theolodger@feddit.uk on 07 Nov 2023 14:15 collapse

Or Evri, the brand formerly known as Hermes

justaveg@lemmy.world on 06 Nov 2023 00:28 next collapse

lol@ this. My bet what is actually happening: cost cutting or future nitro feature.

NegativeInf@lemmy.world on 06 Nov 2023 01:07 next collapse

Trying to keep those classified documents on the DL for home grown radical terror.

Chewy7324@discuss.tchncs.de on 06 Nov 2023 01:16 next collapse

It’s an annoying change for anyone using discord to share files outside of it’s closed platform but doesn’t affect most people.

I wonder whether bridges for matrix have to be fixed or if they’re already editing messages bridged to matrix to the new url.

deadcade@lemmy.deadca.de on 06 Nov 2023 01:38 collapse

Depends on how it’s implemented. Anyone using a “media proxy” will see their discord bridged media probably fail to load (outside of possible caches) after a day. Anyone who has their bridge configured to reupload discord media to their homeserver should see no change.

cybersandwich@lemmy.world on 06 Nov 2023 02:37 collapse

What is this bridge you speak of? I’m intrigued. Does matrix have a functionality that lets you run a mirror of a discord channel?

NorthWestWind@lemmy.world on 06 Nov 2023 03:11 next collapse

Yes, but you have to selfhost your own instance. Big servers don’t have that, and the ones that have probably require payment.

Rootiest@lemmy.world on 07 Nov 2023 08:49 collapse

Yes, but you have to selfhost your own instance.

You don’t.

Here is a free bridge bot that will do it for you

bitwolf@lemmy.one on 06 Nov 2023 14:29 next collapse

Yes exactly. The bridge logs into the discord server as a user. Then it mirrors all chats from your user in matrix to the discord.

Oh matrix, every user on the connected server gets a user whose name is their snowflake. Those virtual users post into the matrix server whatever their respective discord users posts.

uis@lemmy.world on 07 Nov 2023 02:21 collapse

One of these four.

ndguardian@lemmy.world on 06 Nov 2023 01:38 next collapse

Honestly, I’m okay with this at least until they fix the fact that all shared files are accessible without authentication. Granted, you still had to get the link before downloading an uploaded file, but the fact that there was no authentication required to download a file uploaded to Discord was pretty surprising.

kalkulat@lemmy.world on 06 Nov 2023 09:02 next collapse

And a LOT risky

computergeek125@lemmy.world on 06 Nov 2023 14:00 next collapse

It’s probably also way cheaper to do it that way. As far as I could tell when I checked in on it some time ago, most of the content goes through a Cloudflare proxy straight to a GCP S3-compatible bucket.

uis@lemmy.world on 07 Nov 2023 02:19 next collapse

You still need to know magical numbers to download file.

LufyCZ@lemmy.world on 07 Nov 2023 18:37 collapse

What is a password? A string of characters. What is a link? A string of characters.

If you make it long enough, it’ll be impossible to guess one.

Your files are safe

paraphrand@lemmy.world on 06 Nov 2023 02:28 next collapse

I always thought it was a bad idea for people to treat Discord as a free CDN.

unique_hemp@discuss.tchncs.de on 06 Nov 2023 19:36 collapse

I mean it worked for long enough 🤷‍♂️

nephs@lemmy.world on 07 Nov 2023 09:30 collapse

If its going away now, it isn’t quite long enough…

possiblylinux127@lemmy.zip on 06 Nov 2023 03:00 next collapse

I don’t care what you say, Discord is terrible.

nik282000@lemmy.ca on 06 Nov 2023 06:01 collapse

It’s just like IRC but with privacy violations and ads!

uis@lemmy.world on 07 Nov 2023 02:17 next collapse

More like Mumble, but with privacy violations and ads

EngineerGaming@feddit.nl on 07 Nov 2023 10:46 collapse

And without an ability to host the network yourself!

KairuByte@lemmy.dbzer0.com on 06 Nov 2023 05:37 next collapse

This is… annoying. I get the intent for malware, but honestly it’s a BS reason. The content will just be uploaded elsewhere. But what this will do is drastically lower their storage cost under the guise of… not even user safety, more “slightly inconveniencing malware writers.”

LufyCZ@lemmy.world on 07 Nov 2023 18:34 collapse

Yes, it’ll be uploaded elsewhere. That’s the whole point.

Discord doesn’t want to host any of this data, they don’t want to be connected to criminal activity. It makes sense.

Also, while it might slightly lower their storage costs (if the hackers move elsewhere), if you send a file to someone, it’ll still stay on Discord’s servers. Only difference is the link to said file - it’ll only be valid for a day, and then you’ll have to use a new one (in a way that’s probably transparent to the user)

bear@slrpnk.net on 07 Nov 2023 21:16 collapse

The goal here is to make it difficult to link to things uploaded to discord from outside of discord. The malware reason is BS. If they wanted to curb malware it would be as easy as making it a nitro feature. What that doesn’t fix is all the people piggybacking on discord as a free CDN.

Discord isn’t even wrong for doing this. I just resent their dishonesty.

LufyCZ@lemmy.world on 07 Nov 2023 23:31 collapse

Not sure rolling it into Nitro would be worth the effort, I’d consider that quite complex personally

Flex@lemmy.world on 07 Nov 2023 15:33 collapse

Interesting news but I don’t really get how this is self-hosted?