An unidentified individual has listed the data of 760,000 Discord.io users for sale on a darknet forum. This discovery was brought to light by the “Information Leaks” Telegram channel, associated with the Russian service for tracking vulnerabilities, data leaks, and monitoring fraudulent online resources.

For clarity, Discord.io is a third-party interface tailored for the widely-used Discord messenger. The offered database comprises details like email addresses, hashed passwords, and other user-specific data.

  • ivenoidea@lemmy.world
    link
    fedilink
    English
    arrow-up
    122
    arrow-down
    1
    ·
    edit-2
    1 year ago

    Discord.imo, for anyone unsure like me, seems to be unaffiliated with Discord itself and simply a website to find Discord servers to join. It’s offline now.

    Edit: Ah I see the article mentions that as well, it didn‘t load for me earlier.

    Might still be good to have that info here. The amount of upvotes makes it seem like a lot of people might think this is about Discord itself.

    • skilledtothegills@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      35
      ·
      1 year ago

      I’m actually curious where did they got the passwords from? Discord.io looks to be using Discord itself for authenticating users, but I myself have never used the service so I have no idea.

      • originalfrozenbanana@lemm.ee
        link
        fedilink
        English
        arrow-up
        22
        ·
        1 year ago

        Depending on how that authentication handshake is implemented secrets can be leaked. It could be a security flaw on Discord’s side that Discord.io has access to via SSO, or it could be that Discord.io stores username and password for some reason.

  • originalfrozenbanana@lemm.ee
    link
    fedilink
    English
    arrow-up
    24
    ·
    1 year ago

    The fact that the passwords are hashed is small comfort. It’s good for sure but potentially impacted users should still change their passwords and any accounts that share that password.

    Don’t share passwords but if you do and yours is compromised attackers can use it to try and access other services. If you reuse the credentials and Discord.io uses some bad practices (like not salting their hashes) then you’re at risk.

  • krayj@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 year ago

    I know what discord is - because I use it daily. But what is discord.io? The article doesn’t really say what the relationship between discord.io and discord is, but they are using the official Discord logo and official Discord name in the article photo. What is discord.io and what’s the use case for using it?

    • realbaconator@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      1 year ago

      They provide a functionary service for discord servers to have URL redirects pointed at themselves for invites. So less average users and more power users/ servers owners are taking the hit here.

  • Campa@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    1 year ago

    Now that you know, these central platforms put everything in one place, not just Discord.io; the same is true for Discord itself. Discord.io simply provided hackers with a quicker means to collect entry points to various communities.

    Blame can be attributed to centralized management, as all the invite links published on Discord.io allowed hackers to enter those communities and compromise members’ accounts one by one. This is because there was only one server for hackers to breach and gather personal information such as usernames, email addresses, IP addresses, and passwords.

    Fortunately, I left Discord a long time ago and migrated to another platforms, like Lemmy here, WireMin, Session. WireMin is kinda popular in Russia, anyone knows about it? It is complete decentralized, so totally avoid the dataleak issue.

    Dataleaks happens everyday, it is important chose what can be shared and what can’t be.