This is an archived community post.

This post is no longer open for new replies - but we'd still love to hear from you! Share your feedback with our team via our Feedback Form.

Need help getting started? Check out this article for step-by-step instructions on submitting feedback through the form.

How we can fix QR code security risk.

댓글

댓글 1개

  • blackwolfwoof

    The purpose of the QR code login is giving a fast and easy way to log in on other devices with your phone, without having to input your password, email and optionally 2fa code. 
    I personally think when you haven't used the feature in a while it gives you a popup explaining what can go wrong when you scan QR codes that didn't come from discord.com.
    That way new users or users who didn't use it in a while or have no idea what it is for will get a warning they cannot click away for lets say 15 seconds or without typing "i understand".
    If only people with 2FA should be allowed to use it and then asking for a 2FA code kinda defeats the purpose of the fast QR code login we have now and still doesn't tell the user not to input the code since it can potentially be phishing.

    0