Skip to content

2FA can be easily bypassed with user token itself, also token isn't stored securely #4227

Discussion options

You must be logged in to vote

This discussion board is for API suggestions and feedback, and this post doesn't really fall under API talk, so it's now locked.

To OP's point, as far as I'm aware the only way to extract a token is to compromise the machine with Discord installed. Unfortunately, once an attacker's code is running with user privileges, it follows that they can do anything you can do. Discord continues to take steps to limit the spread of malicious software and to mitigate the impact of stolen tokens.

Replies: 7 comments 14 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@Zoddo
Comment options

@NovaFox161
Comment options

@braindigitalis
Comment options

@NovaFox161
Comment options

@Zabbb
Comment options

Comment options

You must be logged in to vote
8 replies
@TwilightZebby
Comment options

@isaackogan
Comment options

@renhiyama
Comment options

@NovaFox161
Comment options

@renhiyama
Comment options

Comment options

You must be logged in to vote
1 reply
@renhiyama
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by typpo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
10 participants