Comment on Arc Raiders was accidentally recording Discord conversations into an unencrypted local game file
shininghero@pawb.social 1 day agoIf I’m reading it right, it’s kinda like how that one guy “hacked” 70,000 robot vacuums. Bad scope limits. Game uses token to do the rich presence stuff, and instead of just getting a confirmation back, it gets everything.
tdawg@lemmy.world 1 day ago
So in other words rich presence shares your conversations with game makers
Quetzalcutlass@lemmy.world 1 day ago
Not necessarily. You choose what permissions your token has when you register it with Discord. In this case the game asked for an auth token with all permissions, so the game connects to Discord with the same access levels as your actual login.
tdawg@lemmy.world 21 hours ago
Yeah that’s what the person before me said. I’m saying that the fact it’s possible at all is a horrible violation of privacy
Armok_the_bunny@lemmy.world 13 hours ago
There are legitimate reasons to ask for an “all permissions” token, such as setting up and using a third party client. A game is not one of the things that should be asking for that though.