Live data from Hacker News

Guess I'm Done with Discord

wowana.me

101–110 of 121 posts

Re: Guess I'm Done with Discord

#101
Why the insistence on Tor? Just use a normal VPN. Tor exit nodes are limited in number, and the same IP probably ends up being used by thousands of people... I assume a lot of them use it for nefarious reasons so you just end up in the same bucket. To some extent VPN providers can get hit by this too, but it's easy to just switch outbound IPs (for most of them). And if you want more than that, get a cheap VPS and install OpenVPN on it (you get your own unique exit IP address) - pay with bitcoin for the privacy aspect, also a good place to install an ad-filter, a secure DNS proxy (DOH) and so on.

I also don't understand the 2FA point, that says nothing about your accounts' intentions.

The account history is an interesting point... if you have a long-standing history with no reports of inappropriate actions, they should factor that in somehow into their algos.

Re: Guess I'm Done with Discord

#102
post #15

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Anal_retentiveness

Not at all, the author uses Tor to anonymize their location and probably system footprint. If you read the response the only "acceptable" phone number is a mobile phone. It de-anonymizes you because mobile providers hand out this sort of information for cash. The only reason for the phone number request, based on the requirements of what kind of phone numbers are acceptable (no VOIP, no landlines) is that they want t…

My comment was linking to a page explaining the term anal-retentiveness, which the parent poster clearly isn’t aware of, and is apparently flagged so no one can see it; what are you talking about?

Re: Guess I'm Done with Discord

#103
post #52

Earlier quoted context omitted.

You do this with every privacy-conscious, freethinking person who comments on this site?

The amount of flak you are getting from a supposedly informed audience is discouraging to me. The fact you value your privacy has turned you into a pedo in some people's views. Stick to your guns - discord has the right to be just another data-mining operation and you have the right to draw a line and say, no more.

>The fact you value your privacy has turned you into a pedo in some people's views.

No, it wasn't that. It's https://wowana.me/blog/the-grey-area-of-paedophilia.xht probably.

Re: Guess I'm Done with Discord

#104

Why the insistence on Tor? Just use a normal VPN. Tor exit nodes are limited in number, and the same IP probably ends up being used by thousands of people... I assume a lot of them use it for nefarious reasons so you just end up in the same bucket. To some extent VPN providers can get hit by this too, but it's easy to just switch outbound IPs (for most of them). And if you want more than that, get a cheap VPS and ins…

>Why the insistence on Tor?

Short answer: I'm a privacy activist. That should be a valid enough reason for this context.

>I also don't understand the 2FA point, that says nothing about your accounts' intentions.

No, but it shows my account is secured from intruders, which means reCAPTCHA is just an additional nuisance to me, the legitimate account holder.

>The account history is an interesting point

Yeah, and they just glance right over it. It doesn't mean anything for my case that I've been an active user with this account for almost two years (I had a previous account for a bit and then left Discord because I was not in any communities worth sticking around for). Never have I done anything wrong on Discord's platform; haven't uploaded any lolis or evaded any bans (I believe I was only banned from one guild, even). They just don't seem to want me as a user, and that's fine.

Re: Guess I'm Done with Discord

#105
post #10

Point 2 in particular rings true. ...If you can't filter out your core user base with 2FA (!!!) from bullshit like recaptch then you've got real problems

2FA is account security, not proof of being a good human user. TOTP is a very simple algorithm (python impl: https://github.com/pyauth/pyotp) that can be easily automated. After all, your phone telling you the code to type in has automated it.

Re: Guess I'm Done with Discord

#106
post #95

Hey. I work at Discord - and actually, this system is a thing I work on - and code my team wrote caused your account to be locked. If my team is doing a good job, you won't notice us. If we're doing a bad job, you might get some spam, or your account may be blocked for false positives. Discord gets a lot of spam. We've disabled, and/or challenged millions of accounts for trying to use our platform for unsolicited spa…

>Malicious actors constantly attempt to brute-force logins on our system - generally from public password dumps or other leaks. A lot of these brute-force attempts come from TOR, and other public proxies. In order to avoid information disclosure, we always captcha logins from these kinds of IPs, regardless of whether or not an account exists with the e-mail in question, whether the login credentials are correct, or there is 2fa enabled on the account. So, the "captchas" you notice are not really specific to your account, but rather, the origin of the login. Using TOR is not a crime, you are right - but - it's also our responsibility to our users to make it reasonably hard for their accounts to get compromised on our platform (even if they don't employ the best security practices - and reuse their passwords across the internet.)

Solution: add a checkbox "disable account security measures", so a user who doesn't want CAPTCHAs when logging into their account doesn't see them. It would have a warning so any user selecting it would know what they're doing.

Re: Guess I'm Done with Discord

#107

Discord's phone verification is awful. They are using some super old database of what provider is associated with your phone number. I ported a Google Voice number to Verizon and they said I can't use it for phone verification because it's Grand Central, a company that went out of business before Discord even came into existence. I pay them $99 a year, and their customer service treated me like shit for this. What do…

That's Twilio's database, not Discord's. Maybe it's fair to be upset at Discord for using Twilio if Twilio can't keep their database up to date, but I don't think there are that many alternatives to Twilio.

Re: Guess I'm Done with Discord

#108
post #95

Hey. I work at Discord - and actually, this system is a thing I work on - and code my team wrote caused your account to be locked. If my team is doing a good job, you won't notice us. If we're doing a bad job, you might get some spam, or your account may be blocked for false positives. Discord gets a lot of spam. We've disabled, and/or challenged millions of accounts for trying to use our platform for unsolicited spa…

>Malicious actors constantly attempt to brute-force logins on our system - generally from public password dumps or other leaks. A lot of these brute-force attempts come from TOR, and other public proxies. In order to avoid information disclosure, we always captcha logins from these kinds of IPs, regardless of whether or not an account exists with the e-mail in question, whether the login credentials are correct, or t…

No, I don't believe that adding the ability to reduce the security of your account is necessarily a good idea.

Re: Guess I'm Done with Discord

#109
post #95

Hey. I work at Discord - and actually, this system is a thing I work on - and code my team wrote caused your account to be locked. If my team is doing a good job, you won't notice us. If we're doing a bad job, you might get some spam, or your account may be blocked for false positives. Discord gets a lot of spam. We've disabled, and/or challenged millions of accounts for trying to use our platform for unsolicited spa…

First of all, thank you for the reply. Yes, my ticket was fairly … to the point and I did not make an effort to be polite, but Discord's support team does perform a good job in terms of timely and complete responses. As I said, starting the account deactivation/deletion process over E-mail was not a hassle (compare that to Twitter, eh…) and I have even been able to start a transfer of my own guild over to a trusted member, so the guild does not die with my absence. But with the current route Discord is taking, I cannot wish it as a company the best of luck. I'll respond to some of your points.

>anti-spam

My impression would be that an aged account with a good reputation would be held to much less scrutiny than a new account, regardless of my method of accessing the service.

>regardless of whether […] there is 2fa enabled on the account

Clue me in on this one because I do not understand how a bot surfing for accounts would be able to guess this code in a configured number of attempts. Many login forms have a number of tries before the account is temporarily locked and the user is notified of a potential breach. This is no substitute for a good password, but it's one additional safeguard, and it's one that doesn't depend on a nonfree CAPTCHA service. I'm trying to de-Google lately and I've been pretty successful; one of the few services I use anymore is GDrive and that's only because I have unlimited storage and GPG at my disposal. Discord isn't owned by Google, so my decision to abandon Google's services shouldn't have weighed in on my decision for third-party services.

>it's also our responsibility […] (even if they don't employ the best security practices[…].)

I understand, but there's a line one has to draw for things like this. I'm not a fan of password requirements but employing a minimum password length (if Discord doesn't already do so) would be a good start. As a public service provider, I understand the issue with compromised accounts, and how they can be used for spam and harassment, but I still believe there are smarter ways to go about this than punishing people for using the wrong IP address to log in.

>hostile toward FOSS

>we have tried to give back to open source software

That doesn't really mean much when Discord openly detests third-party FOSS clients and will not make its server available at least in a similar capacity to GitHub's self-hosted solution (I don't think GitHub is appreciative of FOSS either, and they prefer to capitalise from the walled garden they've created rather than truly express the libre ethic, but hosting servers has been a long-requested feature especially from established communities who don't wish to rely on Discord's infra).

>and privacy

>we've stated that we don't sell your data

I'm a cryptoanarchist. If an organisation has my IP address, they have my IP address. If they have my phone number, they have my phone number. Discord may have my intentions at heart, its servers may be kept updated and secure from most threats, but Discord is a high-profile platform now, and we're all no stranger to hackers leaking database information from a zero-day or some other oversight. I cannot trust words and policies, I can only fully trust audited code and myself. So, no, in this light Discord does not appreciate the concern for privacy if it does not make exceptions for verifying accounts by other, more private means.

I wish I could give an answer on how to moderate a platform without negatively impacting people, but to reuse your words, there isn't an answer that satisfies everyone, and there will always be shortcomings for any solution, whether it's a setup cost or a long-term conditioning of users to create better passwords. In fact, I talked about passwords specifically in another blog post [1] so I can only hope they are eventually phased out for something less prone to user error. Despite what we're stuck with, I do genuinely believe Discord could tune their spam and login mechanisms such that false positives are kept to a minimum.

[1] https://wowana.me/blog/are-passwords-the-right-solution.xht

Re: Guess I'm Done with Discord

#110

It's frustrating to be a power user in general with these sort of 'automated lockout detection' mechanisms. I've lost count of the number of times I've tried to log in to, I dunno, eBay or whatever, and computer says no, and I have to call some bloody line and speak to someone who hates their job and doesn't understand what I mean when I talk about IP addresses. I wish that these services had a way to check some box…

You have to remember that even if you don't care about your account getting hacked, hacked accounts are a nuisance for other users of the platform as well.
Post reply on HN