3 ms·
If Discord.io was using OAuth then this would largely be a non-issue as those tokens could be invalidated or revoked, by Discord, trivially. And they wouldn't h
by predictabl3 3y ago
If Discord.io was using OAuth then this would largely be a non-issue as those tokens could be invalidated or revoked, by Discord, trivially. And they wouldn't have any password data, hashed or otherwise.
Granted, I don't use discord.io , so maybe I'm missing something.
- AgentK20 3y agoTo quote the article: > Salted and hashed passwords (mainly concerning users prior to 2018 when Discord.io began exclusively using Discord for logins) So it sounds like they used to have their own accounts before integrating via Discord OAuth, and some users may be affected by this. Unsure if they didn't delete users' hashed PWs once they migrated to the OAuth flow or something like that.
- explaininjs 3y agoBased on the screenshot it would seem they do have hashed passwords, specifically it looks like bcrypt hashes with a cost factor of 8. Not sure why the cost would be so low, or indeed why the hashes are available at all.