this post was submitted on 14 Aug 2023
370 points (97.9% liked)

Technology

55763 readers
2806 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

An unidentified individual has listed the data of 760,000 Discord.io users for sale on a darknet forum. This discovery was brought to light by the "Information Leaks" Telegram channel, associated with the Russian service for tracking vulnerabilities, data leaks, and monitoring fraudulent online resources.

For clarity, Discord.io is a third-party interface tailored for the widely-used Discord messenger. The offered database comprises details like email addresses, hashed passwords, and other user-specific data.

all 13 comments
sorted by: hot top controversial new old
[–] ivenoidea 124 points 10 months ago* (last edited 10 months ago) (2 children)

Discord.imo, for anyone unsure like me, seems to be unaffiliated with Discord itself and simply a website to find Discord servers to join. It’s offline now.

Edit: Ah I see the article mentions that as well, it didn‘t load for me earlier.

Might still be good to have that info here. The amount of upvotes makes it seem like a lot of people might think this is about Discord itself.

[–] skilledtothegills 35 points 10 months ago (1 children)

I'm actually curious where did they got the passwords from? Discord.io looks to be using Discord itself for authenticating users, but I myself have never used the service so I have no idea.

[–] [email protected] 23 points 10 months ago (1 children)

Depending on how that authentication handshake is implemented secrets can be leaked. It could be a security flaw on Discord’s side that Discord.io has access to via SSO, or it could be that Discord.io stores username and password for some reason.

[–] [email protected] 2 points 10 months ago* (last edited 10 months ago)

Yeah but there's a big difference between tokens that can easily be revoked and what could be potentially plain-text passwords.

edit: Okay, so it sounds like they had their own account system back in 2018 separate from Discord. That makes more sense.

[–] realbaconator 9 points 10 months ago

At first glance that’s what it looks like, but it’s good that your comment is the top for clarity.

[–] [email protected] 25 points 10 months ago

The fact that the passwords are hashed is small comfort. It’s good for sure but potentially impacted users should still change their passwords and any accounts that share that password.

Don’t share passwords but if you do and yours is compromised attackers can use it to try and access other services. If you reuse the credentials and Discord.io uses some bad practices (like not salting their hashes) then you’re at risk.

[–] [email protected] 17 points 10 months ago (1 children)

I know what discord is - because I use it daily. But what is discord.io? The article doesn't really say what the relationship between discord.io and discord is, but they are using the official Discord logo and official Discord name in the article photo. What is discord.io and what's the use case for using it?

[–] realbaconator 18 points 10 months ago

They provide a functionary service for discord servers to have URL redirects pointed at themselves for invites. So less average users and more power users/ servers owners are taking the hit here.

[–] skilledtothegills 15 points 10 months ago

The breach has now been confirmed by the Discord.io team and the article has been updated to reflect this.

[–] yuki2501 12 points 10 months ago (1 children)

Oh shit my conversations in the tentacle hentai discord! 😱

[–] sbexpert 9 points 10 months ago

Oh shit, you got a link?