Token Stealing Prevention

Bình luận

1 bình luận

  • PrincessLapis

    Alternately, they could send an email to your registered email and prevent logging in and/or spending money within the app until you've clicked that and logged in on the website or something. Or only let you spend money if you've marked that specific device as a trusted device, via either email or 2FA stuff. Which should be kept on the server, so they can double check against it before letting you spend money. Then people wouldn't end up with all these hackers who can spend their money just by stealing their tokens.

    It might also help if Discord had warnings within the app about this, too. A quick tutorial about common scams and phishing attempts, maybe? When you first sign in, or maybe after a couple of days. Or maybe something in the options that's labelled something like "Staying safe online". I dunno. In your profile settings? I'm sure they could figure something out.

    But honestly, I hear way too many stories about people getting hacked/having their token stolen in increasingly clever ways. Not everyone is tech savvy enough, nor socially adept enough, to realize when they're being led to do dangerous things, like clicking innocent-looking links from hacked friends or scanning QR codes.

    1

Vui lòng đăng nhập để lại bình luận.