Patreon Logo Support us on Patreon to keep GamingOnLinux alive. This ensures all of our main content remains free for everyone. Just good, fresh content! Alternatively, you can donate through PayPal Logo PayPal. You can also buy games using our partner links for GOG and Humble Store.
We use affiliate links to earn us some pennies. Learn more.

Here's a reminder that when you connect up various accounts - you may end up just increasing the risk of your private data going somewhere else. The issue concerns account connections between the chat app Discord and the extraction shooter ARC Raiders, with far more information being available and logged than it should have.

The issue was exposed by Timothy Meadows in a blog post, which has seen a correction on one part since originally posting, but still shows there was a clear issue. As summed up by Meadows:

During gameplay of Arc Raiders, private Discord Direct Message (DM) conversations between two users were found being written in plaintext to a local game log file. Additionally, a full Discord Bearer authentication token was found stored in the same log file. These findings represent serious privacy and security violations that affect all players using Discord integration with the game.

The ARC Raiders team posted an announcement in their own Discord about a recent game server issue, but also directly mentioned this too:

The team is also working on a hotfix to address an issue where the Discord SDK logged excessive user information. Rest assured that your private and/or personal data was not sent outside your machine and Embark has not (and will not) review or keep such information. We will disable the Discord SDK logging and are conducting a deeper audit to ensure no further issues. If you have questions or concerns, please contact our support team.

That hotfix is now live as of article publishing time.

This was quite likely not in any way intentional or malicious, but goes to show how easily a game could grab your information from Discord if you link accounts. While in this case Embark Studios claim nothing was sent outside of your machine - it's a big reminder of security and privacy issues that can arise. And, how Discord can give out a lot of information that you may think is private to potentially any service you link up with.

Article taken from GamingOnLinux.com.
5 Likes
About the author -
author picture
I am the owner of GamingOnLinux. After discovering Linux back in the days of Mandrake in 2003, I constantly checked on the progress of Linux until Ubuntu appeared on the scene and it helped me to really love it. You can reach me easily by emailing GamingOnLinux directly.
See more from me
All posts need to follow our rules. Please hit the Report Flag icon on any post that breaks the rules or contains illegal / harmful content. Readers can also email us for any issues or concerns.
10 comments

ROllerozxa 3 hours ago
extraction shooter
Turns out it was a data extraction shooter 😂
ScottCarammell 3 hours ago
Surprised they'd do something so blatant, but given they're willing to use AI-generated content for their game it's not super surprising they'd also be pro-surveillance. goes hand-in-hand really
AllyTheProtogen 3 hours ago
So they go the lazy, greedy, and unethical path by using AI for game content, and now are logging user messages. Phenominal. I'm honestly not surprised.
akselmo 3 hours ago
User Avatar
Private and Discord in same sentence. Heh.
Johnologue 3 hours ago
Too cheap and lazy for voices, why'd anyone expect cybersecurity? Maybe they "generated" that, too.
Cley_Faye 2 hours ago
It's funny how all of these "happy little accidents" are all… accidents. "Woops, we logged your auth token and private discussions, my bad." as in, why the hell was the game reading these in the first place, and at what point does an auth token is logged accidentally? Someone have to write a piece of code that says `log(thisSuperDuperSecretStuffThatShouldNeverGetCloseToALoggingFunction);` for this to happen.

Even in early development phase, we wrap logging of potential informations in a way that only expose minimal information, usually the presence and length of the content.

Either their dev are worst than an entry level junior intern, or there's some high level incompetence all around.
dpanter 2 hours ago
User Avatar
Rest assured
No. Never.
GustyGhost 1 hour ago
Glad to have never touched either of these things. It's like I have spidey sense for malware or something.
Ehvis 1 hour ago
User Avatar
  • Supporter Plus
Not a thing I'd ever be at risk from. Games would never be able to detect my discord and I'd certainly not give it. Just as discord would never be able to detect my game.
Jarmer 3 minutes ago
User Avatar
this SCREAMS of a vibe coded disaster. And if they are doing something so amateur as this bug, just IMAGINE what else is going on with this game that's not discovered / disclosed. Imagine how much WAS happening that got patched that will never get disclosed. Horrible devs.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon Logo Patreon. Plain Donations: PayPal Logo PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register