“We are providing guidance to developers” – Discord promises a fix and “additional protections” following discovery of Arc Raiders bug that stored users’ private messages


Discord has responded to a recent data security issue that arose with Arc Raiders’ Discord Integration, which was storing user’s private Discord messages locally on their PCs.

While this has now thankfully been hotfixed by the developers at Embark Studios, A Discord spokesperson told Eurogamer the following: “We recently became aware of an issue impacting some Arc Raiders players involving debugging features intended for developers building and testing Social SDK (software development kit) game integrations.

“This resulted in some players’ Discord information from the game being stored locally on their device, and viewing it would require access to the device or the files themselves. Embark has released a hotfix for the issue and we are providing guidance to developers and updating the Discord Social SDK with additional protections.”

It is worth noting Timothy Meadows, who first published a his findings on this bug, argued that log files – where these messages were stored – could have potentially been included in bug reports or accessed by other apps with access to files on the machine.

According to Discord, the company became aware of the problem on the 4th March, and worked with Embark Studios to address the problem. Embark Studios then moved to quickly fix the problem via a hotfix.

On Discord’s part, the company is releasing updates to the Social SDK and updating developer guidance to help prevent similar issues going forward and is communicating directly with partners who have existing or in-development integrations.

The problem was caused by the debug logging capabilities in the Discord Social SDK, which can generate additional local logs when developers enable high logging levels while testing or troubleshooting integrations. Eurogamer understands this only affected users who linked their Discord account to the Embark Integration.

In Meadow’s original blog post on the matter, he recommended those who enabled Discord integration with Arc Raiders to change their Discord password immediately and disable said integration. With the bug now fixed and new guardrails in place, one hopes this sort of Discord Integration security concern is gone for good.



Source link

  • Related Posts

    Pokémon Go ‘Pokémon 30th Anniversary: All Out’ event guide

    Pokémon Go’s “Pokémon 30th Anniversary” is here and you know what that means: it’s time to celebrate the Kanto region again. This event runs from March 3-9, with the event…

    Slay The Spire 2's Next-Level Co-Op Makes It An Early GOTY Contender

    If you have friends to play with, Slay the Spire 2 is an incredible step forward for roguelike deckbuilders. Source link

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Iran is not Venezuela, despite Trump’s hopes of repeating ‘regime capture’ strategy | US-Israel war on Iran

    Iran is not Venezuela, despite Trump’s hopes of repeating ‘regime capture’ strategy | US-Israel war on Iran

    These 2 Apps Help Me Make Sense of My 100K Screenshots

    These 2 Apps Help Me Make Sense of My 100K Screenshots

    Pokémon Go ‘Pokémon 30th Anniversary: All Out’ event guide

    Pokémon Go ‘Pokémon 30th Anniversary: All Out’ event guide

    8 Spring Nail Art Trends That Will Dominate This Season

    8 Spring Nail Art Trends That Will Dominate This Season

    Here’s the latest.

    Americans pay the price of inequality

    Americans pay the price of inequality