Hi all,
I haven't used Discord in a while, but it became so that now I have to use it for communication with certain people getting support for some services that I use. What I'm doing currently is:
- using a separate randomised e-mail address only for the Discord account
- using a randomly generated username
- no profile picture
- tweaking the settings as best I can for privacy
Other than these points, I'm also being wary of talking about anything personal on Discord. Would you add anything so I can be even safer when using Discord?
Discord doesn't have encryption and, according to the terms of service, can read your messages. If you care about privacy, I definitely would not recommend using it for private conversations, especially after recent rumors about adding ads. I think they won't lose the opportunity to use your DMs for it
In that situation, I would also:
- Only use it through a browser (with fingerprinting protection), never a Discord app.
- Dedicate a browser installation, or at least a user profile, to Discord alone.
- Only use it over a VPN connection dedicated to Discord, or Tor if it works.
- Have an alternative channel (maybe Matrix?) ready and waiting for contacts who might be willing to switch.
Depends a lot on your threat model, of course, but here's what I do:
- use a temporary (but recoverable) email
- use smspool or similar to verify my phone for less than a dollar
- run Discord in a hardened Firefox profile (hardened browser settings + uBlock)
- turn everything relevant off in Discord settings just in case
- don't share PII in conversation
- use a VPN (or Tor)
Using a hardened browser and not giving them your real phone are likely the most effective steps, everything else is either less relevant or overkill. As I said, depends a lot on your threat model and on your requirements (some things may be unachievable if you're forced to use Discord by your employer, for example).
I've found that being consistent with what you choose to share is the most difficult thing. Conversations can get personal, and as you get closer to those random nicknames there's the constant urge to share mundane stuff about your daily lives like weather, holidays, and such that will all add up.
Yeah I feel you. It's often hard to be fully alert of what you're sharing all the time. I have slip ups but it's usually fine, I'm only mega careful regarding things that could give away the city/town/village I live in, and where I work. If I ever really want to talk about it, I will use a different (often temporary) alias.
No way when this https://lifehacker.com/tech/discord-data-sold-to-ai-and-law-enforcement and this https://spy.pet/ exist
I'll give you the most extreme solutions I can think of, and let you decide how much of each you want to enact.
First and foremost: use a secure and privacy friendly OS—Qubes on a burner pc or GrapheneOS on a burner phone—with secure and privacy-friendly networking—use DNS-over-HTTPS, or self-host as much of the infrastructure as you can, consider a VPN, keep the device on an isolated VLAN—use a secure/private web browser like LibreWolf.
General rules of online interaction apply for maintaining privacy within the servers: e.g. don't talk specifics about your location, your age, your physical appearance, your childhood, your employer, etc.
As with most modern apps, the web app is necessarily less intrusive than the installable binary. Use the web app when you can, and limit your usage to only when you can use the web app on a computer and network you own—privacy enforcing habits are more important than all the software stopgaps in the world.
If you absolutely must use a binary, consider breaking Discord's TOS and using a modified front-end: I know some people who use Aliucord for Android, and I just this moment learned about GoofCord for desktop
don't install/run any software without verifying the integrity of the developers/distributors and binaries yourself, or building from source and verifying the code
It's better to have Discord stealing your browsing data to sell you shit than have some random github malware rootkitting your phone.