此主题已被锁定
Kerry 2022 年 11 月 16 日 下午 1:32
2
Remove all Discord CDN links
The chat program Discord is a known dumping ground for malware and malicious bots, and is widely used for command and control of serious malware including credential stealers, ransomware, and other things. Some malware can even use Discord to crash other players' games.

Sophos, an anti-malware publisher and research group, reports that the greatest amount of malware they've found on the Discord Content Distribution Network is, quote: "credential and personal information theft, a wide variety of stealer malware as well as more versatile RATs."

This means software that steals bank account info and Steam account info.

So by allowing games that link with Discord to run on Steam, ValveCorp is inadvertently putting their users and all the games on this platform at serious risk of catastrophic loss.

I believe that these games should be sanctioned or heavily restricted in their capability to link with Discord, and all links that lead to a Discord server should be considered a direct link to malware.

Source: https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/

EDIT: I will not allow this thread to be derailed by any method. Attempts to bring up previous threads are obvious attempts to derail a thread and will be treated as such.

Each creator who makes a post that attempts to derail this thread will result in one singular chain of action:

Mute, block, report. You're not worthy of my time if you keep trying to derail the thread and troll me. You're not going to get a rise out of me.

EDIT: I'm sick and tired of some people (not naming names) being so stuck-up and closed-minded that they cannot admit that other people have different experiences.

The technically-impossible happens all the time. Just because YOU haven't seen it happen, doesn't mean weird crap doesn't happen!
最后由 Kerry 编辑于; 2022 年 11 月 17 日 下午 4:44
< >
正在显示第 16 - 30 条,共 599 条留言
Kerry 2022 年 11 月 16 日 下午 1:48 
引用自 KittenGrindr
引用自 Kerry Freeman

That depends on the game. As I said before, malware can hook into Discord and that can be used to crash multiplayer games.


Evidence of this happening without the user initiating needs to be shown.

Did you read the source I linked in the Original Post?
d3str0y3r 2022 年 11 月 16 日 下午 1:48 
引用自 KittenGrindr
引用自 Kerry Freeman

That depends on the game. As I said before, malware can hook into Discord and that can be used to crash multiplayer games.


Evidence of this happening without the user initiating needs to be shown.
I am going to say right now that evidence of this doesn't exist. The CDN the malware is hosted on has no direct connection to the Discord client so unless someone clicked a link with malware this wouldn't be possible.
Kerry 2022 年 11 月 16 日 下午 1:48 
引用自 Frostbringer
引用自 Kerry Freeman

Did I say banned? No, I said heavily restricted or sanctioned. Limited in scope of control.

Could you please list a few games on Steam that require a link to Discord to play?

None "require" it, but quite a few use it for their communications.
Boblin the Goblin 2022 年 11 月 16 日 下午 1:49 
引用自 Kerry Freeman
引用自 AmsterdamHeavy

Now explain how you were blameless in those events, please.

Of course. When I was on Discord, a hacker stole my authentication token to my Discord without my knowledge, and used it to take over my account. They then used it while I watched and attempted to fight back, to no avail.

They used it to post obscene, lewd messages to other people and post messages of crude nature. Images that are banned on most sites, such as pornography and others, were splattered across every server I was in like grafitti on a wall. All would have been traced back to me, had i stayed.

No links were clicked.


So you are saying that you never in any time opened, clicked, or downloaded anything suspicious? You're saying that you were just randomly picked and hacked without any previous interaction with anything suspicious?
Kerry 2022 年 11 月 16 日 下午 1:50 
引用自 d3str0y3r
引用自 KittenGrindr


Evidence of this happening without the user initiating needs to be shown.
I am going to say right now that evidence of this doesn't exist. The CDN the malware is hosted on has no direct connection to the Discord client so unless someone clicked a link with malware this wouldn't be possible.

Ah, but it does. Read the link I posted in my Original Post.

There are fraudulent clickers hosted on Discord. You don't need to click any links - Discord will do that for you.
Kerry 2022 年 11 月 16 日 下午 1:50 
引用自 KittenGrindr
引用自 Kerry Freeman

Of course. When I was on Discord, a hacker stole my authentication token to my Discord without my knowledge, and used it to take over my account. They then used it while I watched and attempted to fight back, to no avail.

They used it to post obscene, lewd messages to other people and post messages of crude nature. Images that are banned on most sites, such as pornography and others, were splattered across every server I was in like grafitti on a wall. All would have been traced back to me, had i stayed.

No links were clicked.


So you are saying that you never in any time opened, clicked, or downloaded anything suspicious? You're saying that you were just randomly picked and hacked without any previous interaction with anything suspicious?

Yes, that's exactly what I'm saying.
Boblin the Goblin 2022 年 11 月 16 日 下午 1:51 
引用自 Kerry Freeman
引用自 Frostbringer

Could you please list a few games on Steam that require a link to Discord to play?

None "require" it, but quite a few use it for their communications.


So you want Steam to say devs can't or heavily limit the use Discord for communication or their community? Considering you just said using Discord isn't required.

Which means that you have to choose to use Discord as a means to interact with the devs or the game's community.
Kerry 2022 年 11 月 16 日 下午 1:53 
引用自 KittenGrindr
引用自 Kerry Freeman

None "require" it, but quite a few use it for their communications.


So you want Steam to say devs can't or heavily limit the use Discord for communication or their community? Considering you just said using Discord isn't required.

Which means that you have to choose to use Discord as a means to interact with the devs or the game's community.

I want Steam to protect users' accounts.

Some game devs make Discord their primary or ONLY means of communication with the community. They don't come on the Steam Forums at all, except the bare minimum. And they don't interact with the community when they do so.

Any game that uses Discord as a primary, or only, means of interaction for things like customer service and assistance is putting their users' accounts at risk.
最后由 Kerry 编辑于; 2022 年 11 月 16 日 下午 1:56
Boblin the Goblin 2022 年 11 月 16 日 下午 1:56 
引用自 Kerry Freeman
引用自 d3str0y3r
I am going to say right now that evidence of this doesn't exist. The CDN the malware is hosted on has no direct connection to the Discord client so unless someone clicked a link with malware this wouldn't be possible.

Ah, but it does. Read the link I posted in my Original Post.

There are fraudulent clickers hosted on Discord. You don't need to click any links - Discord will do that for you.


You mean the part where they explain that it's links or files which would mean the user has to click or download them to become compromised?

One of the primary ways we’ve observed malware being deployed from Discord’s CDN is through social engineering—using chat channels or private messages to post files or external links with deceiving descriptions as a lure to get others to download and execute them. We found many files whose names suggested they served some function for gamers, and some in fact were: game cheats, game “enhancements” that claimed to be able to unlock paid content, license key generators and bypasses. But while some were actually what was advertised, the vast majority of them were in fact hacks of another kind—intended for one form or another of credential theft.
Brian9824 2022 年 11 月 16 日 下午 1:56 
引用自 Kerry Freeman
引用自 KittenGrindr


So you want Steam to say devs can't or heavily limit the use Discord for communication or their community? Considering you just said using Discord isn't required.

Which means that you have to choose to use Discord as a means to interact with the devs or the game's community.

I want Steam to protect users' accounts. Any game that uses Discord as a primary, or only, means of interaction for things like customer service and assistance is putting their account at risk.

No more then any game that uses a forum as the internet can be used to do everything discord can. Accounts aren't hijacked on discord without user interaction, same as steam accounts.

People get tricked via social engineering to compromise their account then blame others rather then learn from their mistakes
最后由 Brian9824 编辑于; 2022 年 11 月 16 日 下午 1:56
Kerry 2022 年 11 月 16 日 下午 1:59 
引用自 KittenGrindr
引用自 Kerry Freeman

Ah, but it does. Read the link I posted in my Original Post.

There are fraudulent clickers hosted on Discord. You don't need to click any links - Discord will do that for you.


You mean the part where they explain that it's links or files which would mean the user has to click or download them to become compromised?

One of the primary ways we’ve observed malware being deployed from Discord’s CDN is through social engineering—using chat channels or private messages to post files or external links with deceiving descriptions as a lure to get others to download and execute them. We found many files whose names suggested they served some function for gamers, and some in fact were: game cheats, game “enhancements” that claimed to be able to unlock paid content, license key generators and bypasses. But while some were actually what was advertised, the vast majority of them were in fact hacks of another kind—intended for one form or another of credential theft.


引用自 brian9824
引用自 Kerry Freeman

I want Steam to protect users' accounts. Any game that uses Discord as a primary, or only, means of interaction for things like customer service and assistance is putting their account at risk.

No more then any game that uses a forum as the internet can be used to do everything discord can. Accounts aren't hijacked on discord without user interaction, same as steam accounts.

Incorrect, both of you.

article Among those remaining available just prior to publication were an app that performs fraudulent ad-clicking

You don't need to initiate anything. Discord will click those nasty links FOR you.
最后由 Kerry 编辑于; 2022 年 11 月 16 日 下午 1:59
Satoru 2022 年 11 月 16 日 下午 1:59 
By this logic steam should get rid of from its own platform

1) Discussions
2) Groups
3) Chat
4) Comments
5) Reviews

Since all of these are venues for phishing attacks
d3str0y3r 2022 年 11 月 16 日 下午 2:00 
引用自 KittenGrindr
引用自 Kerry Freeman

Ah, but it does. Read the link I posted in my Original Post.

There are fraudulent clickers hosted on Discord. You don't need to click any links - Discord will do that for you.


You mean the part where they explain that it's links or files which would mean the user has to click or download them to become compromised?

One of the primary ways we’ve observed malware being deployed from Discord’s CDN is through social engineering—using chat channels or private messages to post files or external links with deceiving descriptions as a lure to get others to download and execute them. We found many files whose names suggested they served some function for gamers, and some in fact were: game cheats, game “enhancements” that claimed to be able to unlock paid content, license key generators and bypasses. But while some were actually what was advertised, the vast majority of them were in fact hacks of another kind—intended for one form or another of credential theft.

Clearly OP doesn't not understand what they are reading. At no point does it say anything about "fraudulent clickers". All the malware this article is talking about has to be clicked by the user.
Kerry 2022 年 11 月 16 日 下午 2:00 
引用自 Satoru
By this logic steam should get rid of from its own platform

1) Discussions
2) Groups
3) Chat
4) Comments
5) Reviews

Since all of these are venues for phishing attacks

All of these are regulated by Steam and scanned for links to malware.
Boblin the Goblin 2022 年 11 月 16 日 下午 2:00 
引用自 Kerry Freeman
引用自 KittenGrindr


So you want Steam to say devs can't or heavily limit the use Discord for communication or their community? Considering you just said using Discord isn't required.

Which means that you have to choose to use Discord as a means to interact with the devs or the game's community.

I want Steam to protect users' accounts. Any game that uses Discord as a primary, or only, means of interaction for things like customer service and assistance is putting their users' accounts at risk.

Some game devs make Discord their primary or ONLY means of communication with the community. They don't come on the Steam Forums at all, except the bare minimum. And they don't interact with the community when they do so.


Again, you are responsible for protecting your account, not Steam.

The simple use of Discord is not the issue. If you read the article you linked, it says nothing about Discord itself being the problem. The article is about others using Discord for distribution of malicious content. If this makes Discord itself the problem, then any outside service should be met with the same scrutiny. Actually, it doesn't even need to be outside since Steam's own chat has been used to hijack accounts as well.

So, unless you want Steam to also restrict their own chat or label it as malware, there is nothing to be done.
< >
正在显示第 16 - 30 条,共 599 条留言
每页显示数: 1530 50

发帖日期: 2022 年 11 月 16 日 下午 1:32
回复数: 599