Live data from Hacker News

Guess I'm Done with Discord

wowana.me

61–70 of 121 posts

Re: Guess I'm Done with Discord

#61
Discord's phone verification is awful. They are using some super old database of what provider is associated with your phone number. I ported a Google Voice number to Verizon and they said I can't use it for phone verification because it's Grand Central, a company that went out of business before Discord even came into existence.

I pay them $99 a year, and their customer service treated me like shit for this. What do I care if someone hacks my account and destroys the large community that I moderate? That's their problem, not mine. But I doubt they care.

Re: Guess I'm Done with Discord

#62
post #2

This is a typical response from service companies in the Internet age. They don't care about truth, or what actually happened, the algorithm says you're bad then you're bad. There's no human to appeal to, no human oversight of if their algorithm is right or wrong. They use another algorithm to check it, which tells them that you must be a bad actor. I've had my own issues with Lyft that are similar. Banned from using…

my friend got instantly banned from stockx before even confirming the order,, these algos run amok

Re: Guess I'm Done with Discord

#63

A private company has the right to choose where its traffic comes from, nothing surprising here. There are legitimate reasons to block TOR traffic, and even if there where none, they'd still have the right to block anyone of their users. There are plenty of alternatives, simply remember not to choose one ran by a private company again.

Luckily I never had all my eggs in Discord's basket, and thankfully so. I will remember this, and I know they are welcome to discriminate against Tor or any other traffic, but that just means they opt for lazy solutions and don't care about false positives. I host websites and online services (at a much smaller scale than Discord, at that) and I know how people use Tor to abuse services. But, I also know that there's a comparable number of incidents coming from traditional ISPs, hosting ranges, dynamic home IP addresses, public proxies... you name it. This is extremely apparent in the form of E-mail SPAM.

I just believe that placing bans or flags on IP addresses is not the answer, and I will work on my own software and services with this ideology in mind. Ironically, Discord did have what I believe to be a stellar answer to guild moderation: invite links. They allowed a whitelisting model for private guilds, as well as varied forms of controlled access for more-public guilds. I'd like to see this kind of control everywhere.

Re: Guess I'm Done with Discord

#64
post #2

This is a typical response from service companies in the Internet age. They don't care about truth, or what actually happened, the algorithm says you're bad then you're bad. There's no human to appeal to, no human oversight of if their algorithm is right or wrong. They use another algorithm to check it, which tells them that you must be a bad actor. I've had my own issues with Lyft that are similar. Banned from using…

To be fair, I don't think humans have any way of verifying that you're trustworthy. Anyone can send email from your email address. Anyone can fake a driver's license. Anyone can get a phone number that meets their criteria. Knowing who someone is on the Internet is nearly impossible. Knowing whether or not to trust someone once you know who they are is nearly impossible.

There is no system of human corporation trust in the real world. The best we have, maybe, is some record of how often you pay bills on time.

Tech companies kind of have to have these automated bans, because it's easy to create new identities on the Internet and the government doesn't care that you're defrauding a tech company. If you defraud a bank, the government pays the full cost of prosecuting and incarcerating you. If you spam Discord... nobody cares. It's Discord's problem, not the taxpayers' problem. So they really have no choice here. The world sucks. Get a helmet.

Having said that, banning people with a valid authentication token because of their IP address is simply the wrong algorithm. I can see why you might rate limit authentication attempts over Tor... but if you get your username/password right on the first attempt and provide the correct second factor... you should probably rate limit that valid session with a per-session rate limit key, rather than a per network endpoint key. (The era of IP address based rate limiting dies with IPv6 anyway, so they'll need a better plan someday.)

Re: Guess I'm Done with Discord

#65
post #16

1)You're not a paying user 2)You use proxies/tor which probably makes your concerns the concerns of 0.01% of the user-base. Why should a company whose primary motive is to be profitable go so far out of their way for you, a non-paying client whose concerns represent basically none of the legitimate user-base?

Trust me when i say paying users of discord are treated equally as flippantly.

Re: Guess I'm Done with Discord

#66
post #40

Earlier quoted context omitted.

> Discord doesn't comply with the OpenSSL license. In what way? Have you reached out to Discord to make them aware? They seem fairly committed to open source from everything I've read.

The OpenSSL license for Discord's bundled versions of OpenSSL [0] has two conditions which are being violated. When they advertise the features of their client, or offer binaries of their client for download, they do not include the verbatim text, "This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. ( http://www.openssl.org/)" They know that they are violating this license;…

But that's not what the license says.. it says:

* 3. All advertising materials mentioning features or use of this software * must display the following acknowledgement: * "This product includes cryptographic software written by * Eric Young (eay@cryptsoft.com)"

I'm not a lawyer, but my interpretation of "this software" is OpenSSL, which wouldn't apply this clause to all advertising of discord features. It would be when they run advertisements that reference discord features that rely specifically on OpenSSL features. Which, isn't going to be that often, right?

> They know that they are violating this license; they don't care. They are free to clean up their act at any time.

Is this a known issue that's been brought up before? I've never heard of it, and would be interested to read up on it! I'm especially curious as to their response.

Re: Guess I'm Done with Discord

#67
post #2

This is a typical response from service companies in the Internet age. They don't care about truth, or what actually happened, the algorithm says you're bad then you're bad. There's no human to appeal to, no human oversight of if their algorithm is right or wrong. They use another algorithm to check it, which tells them that you must be a bad actor. I've had my own issues with Lyft that are similar. Banned from using…

Assuming you're willing to share, how did you get banned from Lyft without ever ordering a ride?

I have no idea how I was banned or for what reason. I signed up for an account, verified, added my credit card (amex platinum), and then could never order a ride. Opened a support case with them and they told me I was banned, they could not, would not provide any details as to why. No appeals allowed despite what their tos says and they stopped responding to the support case.

Black hole of the Internet age.

I really wish I knew what it was. I use Uber mostly without issue. Same email, phone and CC. Occasionally Uber does wacky things like block my account due to fraud, but they always manage to fix it. I've figured out with Uber it's always due to travel. For example I'll order rides in Peru and then 7 hours later I'll have rides in the US, and not to my house or in my home area. Still wish they had a phone number because it can take weeks for them to unblock my account.

Re: Guess I'm Done with Discord

#68
post #9

It's frustrating to be a power user in general with these sort of 'automated lockout detection' mechanisms. I've lost count of the number of times I've tried to log in to, I dunno, eBay or whatever, and computer says no, and I have to call some bloody line and speak to someone who hates their job and doesn't understand what I mean when I talk about IP addresses. I wish that these services had a way to check some box…

You think the right set of people will check that box? And that if they do get hacked they won't cost the company a ton of resources in support/lawsuits/etc?

I think the "check box" in this case should be the act of opting into 2FA. I've expressed this to Discord before when asking why they require reCAPTCHA upon login, even for an 2FA-enabled account like mine.

Re: Guess I'm Done with Discord

#69
post #6

I like that for privicy reasons they won't tell you why you were banned. Whose privicy? Does that just mean "our black box NN has banned you and we won't know or care why" ?

Their own privacy most likely. Don't want to reveal the techniques used to identify the accounts they ban, so the scammers can't learn from it.

Re: Guess I'm Done with Discord

#70
post #43
post #27

Earlier quoted context omitted.

> The customer is always right. This meme needs to go away. The customer is not always right, and it's deeply unhealthy for businesses to adopt this attitude. Even very customer centric businesses do not adopt this mantra.

I mean the statement has never been about infallibility or anything it just means “the customer’s feelings are always valid” but was coined before such language was common.

Some say it means "the customer's spending (or refusal to spend) is inarguable reality," without dragging the customer's feelings into the picture. Granted an angry customer is less likely to buy.
Post reply on HN