The 10 Most Common Discord Security Risks and How to Avoid Them

The 10 Most Common Discord Security Risks and How to Avoid Them

6. Bots given permissions they don’t need

Very few bots need admin access to be able to do everything you need them to do. In general, you should only ever give admin rights to admins – your most trusted team members. While rare, bots can get hacked or used for malicious purposes, and if they have admin access to your server, they can access a lot of valuable information and security details.

7. Low verification level on safety setup

Discord gives you different verifications levels, which prevent new users from posting immediately until certain conditions are met. Low requires a user to have a valid email address associated with their Discord account, medium requires a valid email address and to have been registered for at least 5 minutes, high for at least 10 minutes and highest requires a phone number to be associated with the account. Most public-facing Discord servers should be set to high or highest, though highest enforces a phone linked to the account which may prevent some genuine users from joining.

8. Unvetted moderators

Moderators have a lot of power over your community, both with permissions and as representatives of your server. It can be tempting to hand moderation powers to the people who want them most/who appear to be the most active, but vetting candidates, working out who has good judgment and who knows what. Consider setting up a Google Form and seeing who applies, but check people’s posts, their backgrounds, make sure they don’t have any warnings, choose your mods carefully. Or talk to us about our moderator solutions.

9. Lack of/Low explicit media content filter

Discord can automatically scan posts for NSFW or explicit content. In most public Discords, there’s no reason to turn this off or set any lower than high. It’s unintrusive and false positives are comparatively rare.

10. No anti-raid bot

Malicious users can create bots to raid a server, without any protection in place this can lead to phishing scams, abuse and other security risks. Discord has implemented automatic raid protection, but it’s still in beta. Beemo is a bot that’s easy to install that helps prevent these raids automatically. There’s virtually no reason not to install it!

If you would like to discuss your Discord server settings, book an audit, or need help
with moderating and engaging your server, get in touch with our Player Support team below!

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *