11 ms·
Let's Reverse Engineer Discord
- mmastrac 7y agoYikes > We tested this malformed audio packet dispatch at various points during a voice call and consistently watched all malformed audio packets dropped by the server, which means that Discord servers are actively decrypting and inspecting all audio/video communications in real-time and not just some.
- senectus1 7y agofuck. Is it really too much to ask for/expect a modicum of decency with these services?
- nightfly 7y agoWhen you are paying $0.00 for the service? And in this case they are dropping malformed data, which could easily protect their users from malware that exploits weaknesses in the media codecs.
- znfi 7y agoI find this notion that you should be absolved of all responsibilities just because you give it away for free to be completely wrong. They should still be transparent about what they are doing. This notion also does not translate very well to things which are not related to IT. I use a very large number of things in my daily life which I am not paying for but I still expect them to work and be safe. Or would be it be fine if I take an elevator and it falls down and kills me? Or whoops, I got a free candy which turned out to contain toxins. I guess I didn't pay for the service so why do I have some expectations for it to work or be safe?
- ip26 7y agoIf we're going to wander off into metaphor, this seems more analogous to a doorman refusing to allow you to bring your 800lb gorilla (sneakily dressed as your child) onto the elevator.
- znfi 7y agoI guess I could have been more clear. I was not primarily discussing this particular case of what Discord is doing. Instead of I was against the notion that I cannot have any expectations because something is free. If you want to argue that Discords measure in this case are fair then I'm fine with that, but just something like "STFU the service is free" is not enough when it comes to these companies with massive impact on society, IMO at least. Edit: After thinking about this a bit more, I guess the point is that if they are just dropping (potentially) malicious data, or in your case not letting a gorilla through the door. This does not have anything to do with the service being free as far as I can see, they can be argued for independently. Instead I see people defending questionable behavior by pointing out that the service is free. And the point I tried to make originally was that I would like to at least be informed about the questionable behavior, so I have a chance to take this extra "cost" into account when I select a product.
- kiba 7y agoI don't think people are defending the service just because it's free. We simply cannot expect something to be had for free without making money to support the service. Unfortunately, one way to monentize the service is to sell user data.
- saagarjha 7y agoI think a better one would be the postman unsealing and re-sealing your mail.
- swish_bob 7y agoIt's (mostly) a broadcast service. Them metaphor in this case, it's the radio station boosting your signal ...
- BlueTemplar 7y agoDid they ever claim that they wouldn't listen to and exploit your communications for profit? Hmm, what does the GDPR say about this, already?
- nemothekid 7y agoHow is Discord not being transparent here? They never claimed they were E2E encrypted, and the WebRTC spec doesn’t support one to many encrypted streams. It doesn’t seem fair to burn Discord at the stake for a feature they never claimed to provide.
- mbesto 7y ago> Or would be it be fine if I take an elevator and it falls down and kills me? Or whoops, I got a free candy which turned out to contain toxins. I Those things are paid for by someone who is expressively giving you rights to those goods/services. Just because Method Gaming is paying for their discord server so you can enjoy your free service, doesn't mean they are necessarily aware that you are using their paid-for server resources. OTOH, if I am renting an apartment from a building (which I pay for) and someone comes to visit me in the elevator, I expect that the elevator cost I pay for through my rent is safe enough for you travel in. > guess I didn't pay for the service so why do I have some expectations for it to work or be safe? Safe != privacy. The issue is not necessarily security (although there is an implication there as well), but more so it's privacy.
- Dylan16807 7y agoLots of people are paying $5 or $10 a month.
- ackshually 7y agoIt's not a free service if the service provider is selling personal data.
- deleted 7y ago[deleted]
- tsukurimashou 7y agonothing is "free" if you're not paying with money for some service you're paying with something else
- latchkey 7y agoI don't understand why Discord doesn't just work on a copy of the stream and send the original through. Would have prevented anyone from ever knowing.
- neskiredk 7y agoand lowered latency drastically.
- unlinked_dll 7y agoCould be transcoding for people with different bandwidths on the same chat
- beefhash 7y agoI'm not sure what drives you to expect privacy from a communications platform fueled with venture capital money. I wouldn't be surprised they're trying to do at least two things: 1. Applying a censor to voice depending on server/user DM configuration. I know they've got some kind of OCR that tries to identify and block offensive words contained in images, such as the N word, when people are not friends and at least one side hasn't changed the “safe direct messaging” option down to “I live on the edge”. 2. Store records at least temporarily for law enforcement. And the obvious other things are keeping for post-processing and derive user interests for advertising, or batching and forwarding the information to intelligence agencies. It's hard to tell, realy.
- orliesaurus 7y agoThe problem is... There still isn't a clear business model for discord, the advantages of having premium (nitro) are almost non-existing. That's not an excuse for privacy, I know... They tried to create a small competitor to Steam's game marketplace but it didn't work out. They're back to the drawing table. Honestly, that's actually really good for free users, like myself, because we can simply use discord's wide array of functionalities for free: Seamless audio and video sharing, wide extensibility of the platform through APIs and bots, simple file-sharing, chat persistency, mobile clients + web client, ability to pick server location, codecs, moderation tools...and the best feature in my opinion...their amazing changelogs popups. Honestly security wise it might not be very clear, as per this article, where they stand today, I am still super stoked about every other aspect.
- 14 7y agoBut how can you remain super stoked by features of a service that may be decrypting your communication in real time? Does that sour the whole thing for you? If they can decrypt our communications I would think the 3 letter agencies would want to get access to it as well.
- throwaway8879 7y agoThis is actually a good indicator for understanding the issue of privacy/surveillance. There are enough hackers and engineers who care little about being spied, despite understanding some of the inner workings of how the spying is done - as long as the benefits of a free service outweigh the slight privacy-violating annoyances. Now try to understand why the average person cares even less.
- moooo99 7y agoI don't think this is a reliable indicator. When you take a look at the target market of discord, it becomes pretty clear why no one really cares about the data being decrypted. The main audiences for discord are gamers and massive open communities. The first group is unlikely to discuss any sensitive topic via discord and it's not unlikely that a lot of discord users even stream their sessions publicly. The majority of conversations are likely to be game-related and not of private nature. For the huge open communities, encryption doesn't help to improve privacy when everyone can join anyways. If you want to grow a big and healthy community where everyone can join, the 3-letter agencies might as well join the voice channel rather than being the mitm. I haven't met anyone who is using discord as an alternative for WhatsApp, Telegram, etc., from my experience, discord is mainly used for on-topic discussions rather than private communications. And as other comments suggest, there are legitimate reasons why discord might want to decrypt the communications on their end. Plus, I have never seen any claims by discord to be p2p encrypted.
- gfodor 7y agoThis is common and necessary for WebRTC SFUs, which perhaps is why Discord does it to support the least common denominator of their web browser based clients. Edit: Yep, I thought I remembered reading this. Their voice servers are WebRTC SFUs. So this is basically state-of-the-art when it comes to voice over WebRTC. End to end encryption in WebRTC is not possible if you are using a SFU. https://blog.discordapp.com/how-discord-handles-two-and-half-million-concurrent-voice-users-using-webrtc-ce01c3187429 https://blog.discordapp.com/how-discord-handles-two-and-half...
- jhgg 7y agoThis transport mode is also publicly documented here: https://discordapp.com/developers/docs/topics/voice-connections https://discordapp.com/developers/docs/topics/voice-connecti...
- ghjnut 7y agoDidn't know what an SFU was. https://webrtcglossary.com/sfu/ https://webrtcglossary.com/sfu/
- sequence7 7y agoFor convenience: > SFU stands for Selective Forwarding Unit. > At times, the term is used to describe a type of video routing device, while at other times it will be used to indicate the support of routing technology and not a specific device. > An SFU is capable of receiving multiple media streams and then decide which of these media streams should be sent to which participants.
- jeltz 7y agoWhy don't SFUs support end-to-end encryption? Is it just a missing feature in the WebRTC protocol or am I missing some fundamental reason?
- tpetry 7y agoYes its simply missing in the WebRTC spec. webRTC defines end-to-end encryption between two peers. But if you want to transmit data to many peers you need a server which is doing the fanout so the encryption is client1<->server and server<->client2. This is true for all WebRTC implementations/services. They all state having end-to-end encryption but dont tell you that it means something different in WebRTC contexts. PERC will solve this one day, but its sadly just a draft: https://webrtcglossary.com/perc/ https://webrtcglossary.com/perc/
- coenhyde 7y agoI don't think Discord makes any claims that the audio is P2P encrypted. There are legitimate reasons why Discord might be dropping malformed packets, apart from an indication that they are spying on you (they may be doing that too). 1) to improve audio quality. 2) to help prevent RCE attacks on the destination client. 3) re-encoding at lower bitrates for low bandwidth clients. I don't really see the issue here unless Discord claimed they do not decrypt the audio.
- franga2000 7y ago3) is most certainly at play here, as Discord allows clients to set their preferred bitrate (RX&TX), which would not be possible in multi-party calls without re-encoding.
- FractalParadigm 7y agoCould they not just drop the quality of the whole call down to the lowest bandwidth allowed by a user? I feel that would reduce a computational burden on Discord's end, while allowing the lowest client-to-client latency
- PudgePacket 7y agoThey could, but if you have 4 people in a call and 3 can receive high bandwidth audio, lowering it just for the 1 person with low bandwidth is the best user experience. Otherwise people with good networks who have their call quality dragged down will just think Discords voice chat is bad.
- duskwuff 7y agoKeep in mind that a major use case for Discord is open voice chats (e.g, for gaming groups), not just organized person-to-person calls. Having the quality for a whole chat drop just because someone joined from a mobile phone would be a really disappointing user experience.
- ollien 7y ago
- Teknoman117 7y agoI'm fairly certain that this is the default behavior of WebRTC SFUs? (all that I've seen at least) (SFU = Selective Forwarding Unit) Unless Discord claimed they were P2P encrypted this shouldn't be a witch hunt. It's the default behavior for most WebRTC systems. The clients establish (encrypted) connections to the SFU(s). The SFU then reads incoming data and forwards it to whichever other clients are supposed to be receiving it. However, they maintain state per client and possibly do things like transcoding audio and video if the receiving client can't handle the source quality.
- Animats 7y agoDiscord privacy policy: In an ongoing effort to better understand and serve the users of the Services, we may conduct research on our customer demographics, interests and behavior based on the information collected. This research may be compiled and analyzed on an aggregate basis, and we may share this aggregate data with our affiliates, agents and business partners. We may also disclose aggregated user statistics in order to describe our services to current and prospective business partners, and to other third parties for other lawful purposes. For example, they could do sentiment analysis on corporate chat, track it over time, and see which companies show patterns indicating trouble. Then they could short the stock, buy put options, or suggest to their "current and prospective business partners" that low-ball acquisition offer would be appropriate.
- mapcars 7y agoIs discord known to be used in corporate sector? I think so far it's dominated by Slack and Discord is mostly used by games/communities.
- duskwuff 7y agoI'm sure there are some businesses using Discord, but they aren't the target audience. The branding and feature set of Discord all make it very clear that it's targeted at PC gamers.
- uncle_j 7y agoThere are a lot of smaller open source projects that are using Discord instead of IRC. I am a member of Reshade, C# OpenTK and general programming servers.
- rawfan 7y agoI actually know many opensource projects that moved from the clunkyness of Slack to Discord. In all fairness, though, the recent releases of Slack made it pretty snappy.
- jokoon 7y agoWasn't skype originally P2P? I wish there was a simple windows voip client that was doing p2p voip. I often experience cuts with skype and discord, I think their servers can have a hard time handling low latency properly.
- F3nd0 7y agoYou could try Jami. It’s fully distributed and improves over Skype and Discord by respecting its users’ freedom. Calls should work fine with it, but text messaging outside of them can be unreliable. https://jami.net/ https://jami.net/
- olah_1 7y agoJami is missing group text conversations. It's a major work-in-progress.
- csunbird 7y agoIt was and because of that a lot of people were hacked, since skype could be used to run remote code by leveraging a couple of bugs existed in skype application. That is one of two reasons why Microsoft switched to server-client model instead of p2p connection. Other being having control of the service and with call and message history makes more money of course.
- superkuh 7y agoThat is an interesting perception of history. What it looked like legally was p2p was working great and skype was massively rising in popularity. But the US federal government could not stand encrypted peer to peer communications. So they told their good friends over at eBay to buy the company. eBay messed it up and only bought the license for the name and not the actual code and p2p backend. Things continued working well for a while. But the feds still weren't happy. So they had their other friends at Microsoft actually purchase the technology and then immediately destroy it and switch to a centralized model. You can read the story at: https://arstechnica.com/information-technology/2018/09/skypes-secrets/4/ https://arstechnica.com/information-technology/2018/09/skype... >For the second time, Zennström and Friis cashed in on selling Skype. That's because, instead of giving eBay the critical base technology that kept Skype going (the P2P system known as "Global Index"), Zennström's and Friis's company Joltid still owned it—they simply licensed it to Skype. The whole situation devolved into threats of litigation until a 2009 settlement gave Zennström and Friis a chunk of Skype ownership, which made them even more money when Microsoft bought the company.
- deleted 7y ago[deleted]
- bgitarts 7y agoJust because invalid encrypted data is being dropped doesn't automatically mean the server is decrypting the data. It's possible to verify an encrypted message is valid without seeing it's content.
- Mandatum 7y agoIt's not possible to validate a message without decrypting it. You can verify a signed message, if that's what you mean? This proves parsing or filtering is happening on Discord's end to the decrypted message.
- 867-5309 7y agothey pretty much claim ownership for anything and everything you submit to them. they need it in some useable format, which "encrypted" is not. what they use their data for is not our concern, since we no longer own it from their ToS: "Any data, text, graphics, photographs and their selection and arrangement, and any other materials uploaded to the Service by you is “Your Content.”" "By uploading, distributing, transmitting or otherwise using Your Content with the Service, you grant to us a perpetual, nonexclusive, transferable, royalty-free, sublicensable, and worldwide license to use, host, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform, and display Your Content in connection with operating and providing the Service"
- atesti 7y agoThe article links to https://github.com/tenable/DiscordClient https://github.com/tenable/DiscordClient but this has been deleted. Does someone have a mirror?
- Fabricio20 7y agoNot sure if this is the same as what was on the link you sent, but you can take a look at the Discord Data Mining project [0]. [0] https://github.com/DJScias/Discord-Datamining https://github.com/DJScias/Discord-Datamining
- ihuman 7y agoI'm confused. The link in your comment leads to a live repo.
- atesti 7y agoIt's working for me, too. When I wrote my comment, there was just a 404. Maybe it was restored?
- thrower123 7y agoI keep reading this title, and thinking that it's going to propose a final solution to the vim vs emacs debate, or tabs vs spaces, or one of the other fonts of engineer discord.
- Arathorn 7y agofwiw, the approach we're looking at in Matrix is to have E2E-encrypted SFUs, as per https://github.com/matrix-org/matrix-doc/blob/matthew/msc2359/proposals/2359-e2ee-voip-conferencing.md https://github.com/matrix-org/matrix-doc/blob/matthew/msc235...
- ryukafalz 7y agoThis is exciting! I like Jitsi in general, but I would much prefer native conferencing. Do you know if there are plans to support Discord-style persistent voice rooms?