Josh Fraser recently discovered that you can peep into the internal workings of any project that's using Discord because the Discord API leaks the name, description, members list, and activity data for every private channel on every server.
I find Discord's response a bit disturbing. Basically saying that for "technical reasons it has to be this way" doesn't feel like enough of a response. imo this is unacceptable...when I see the little lock icon I assume my data is relatively safe. Saying they may "possibly address" this is a little crazy to me.
Yeah, I agree! I'm wondering about other indie hackers opinions here. It's like they know that users are being misled about how secure their details really are, and they're okay with that. 😬
And here's a Vice write up from yesterday covering this topic as well. "Rampant spam, phishing attacks, scammers, and malware—Discord has a lot of challenges..."