Remember you can trust Discord with your driver’s license for verification, I’m sure they won’t accidentally store them in a plain text open API call or anything.

    • shininghero@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      If I’m reading it right, it’s kinda like how that one guy “hacked” 70,000 robot vacuums. Bad scope limits.
      Game uses token to do the rich presence stuff, and instead of just getting a confirmation back, it gets everything.

        • Quetzalcutlass@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Not necessarily. Developers choose what permissions their authorization token has when they register it with Discord. In this case the game asked for an auth token with all permissions, so the game connects to Discord with the same access levels as your actual login.

          • DreamButt@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Yeah that’s what the person before me said. I’m saying that the fact it’s possible at all is a horrible violation of privacy

  • CosmoNova@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    Lmao. A game accidentally receiving your Discord DMs and credentials if you sent a crash report just because game devs integrated basic Discord functionality is insane. But kind of what you have to expect from Discord and why I’ll never enable Discord integration.

  • chirospasm@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    Issue seems to be with Discord’s SDK, not Embark. Good on Embark responding quickly by patching something Discord should be responsible for, though.

    • poke@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      Well… They quickly patched it when it went public. It was reported to them a month ago.