- cross-posted to:
- technology@beehaw.org
- cross-posted to:
- technology@beehaw.org
“Attackers, Trellix wrote, use the platform’s webhooks to pull data from victims’ computers and drop it into Discord channels run by the attackers.”
I always thought it was a bad idea for people to treat Discord as a free CDN.
I mean it worked for long enough 🤷♂️
If its going away now, it isn’t quite long enough…
This is… annoying. I get the intent for malware, but honestly it’s a BS reason. The content will just be uploaded elsewhere. But what this will do is drastically lower their storage cost under the guise of… not even user safety, more “slightly inconveniencing malware writers.”
I wonder if McAfee changing their name to Trellix to escape how much the general public hates them will work better than Comcast rebranding as Xfinity.
The general public doesn’t hate McAfee that much, so I’d bet it’ll work. Heck, I work in IT and I didn’t even know about the rebrand (mostly because I engage with McAfee as little as possible).
probably about as well as Twitter becoming “X, formerly known as Twitter”
Yeah let’s keep that going here. From here on our whenever I see Trelix I will say “Trelix, the brand fomally known as McAfee.”
or just call them mcafee, twitter, facebook, etc
Yes, but I like this because it ingrains in people’s heads that when they hear Trelix they should think McAfee, to make that connection. Like with Xfinity, they don’t want that connection made, they want people thinking “Oh I don’t have that crappy Comcast service, I have Xfinity”. I’ll be saying it this way to show people that they’re the same thing
fair point, maybe I’ll do that from now on
Or Evri, the brand formerly known as Hermes
I thought it was just their enterprise division that changed their name?
Idk, but this issue was discovered by “Trellix” which is McAfee.
lol@ this. My bet what is actually happening: cost cutting or future nitro feature.
I don’t care what you say, Discord is terrible.
It’s just like IRC but with privacy violations and ads!
More like Mumble, but with privacy violations and ads
And without an ability to host the network yourself!
It’s an annoying change for anyone using discord to share files outside of it’s closed platform but doesn’t affect most people.
I wonder whether bridges for matrix have to be fixed or if they’re already editing messages bridged to matrix to the new url.
Depends on how it’s implemented. Anyone using a “media proxy” will see their discord bridged media probably fail to load (outside of possible caches) after a day. Anyone who has their bridge configured to reupload discord media to their homeserver should see no change.
Honestly, I’m okay with this at least until they fix the fact that all shared files are accessible without authentication. Granted, you still had to get the link before downloading an uploaded file, but the fact that there was no authentication required to download a file uploaded to Discord was pretty surprising.
It’s probably also way cheaper to do it that way. As far as I could tell when I checked in on it some time ago, most of the content goes through a Cloudflare proxy straight to a GCP S3-compatible bucket.
You still need to know magical numbers to download file.
And a LOT risky
Trying to keep those classified documents on the DL for home grown radical terror.