Skip to content

Conversation

@DicksonWu654
Copy link
Collaborator

@DicksonWu654 DicksonWu654 commented Dec 17, 2025

Frameworks PR Checklist

Integrating w3os discord guide into frameworks

This is from #305. @NFTDreww suggested we merge discord first into frameworks, then work on the other ones. This has alreayd been approved by NFT Drew

  • Describe your changes, substitute this text with the information
  • If you are touching an existing piece of content, tag current contributors from the attribution list
  • If there is a steward for that framework, ask the steward to review it
  • If you're modifying the general outline, make sure to update it in the vocs.config.ts adding the dev: true parameter
  • If you need feedback for your content from the wider community, share the PR in our Discord
  • Review changes to ensure there are no typos, see instructions below

…utor details

- Enhanced the Discord management documentation with a new summary section outlining key security measures.
- Introduced a comprehensive account security checklist for individuals and team members.
- Updated contributor information to include Auditware, reflecting their role and contributions.
- Streamlined content for clarity and improved organization of security measures and guidelines.
@vercel
Copy link

vercel bot commented Dec 17, 2025

@DicksonWu654 is attempting to deploy a commit to the Security Alliance Team on Vercel.

A member of the Team first needs to authorize it.

@vercel
Copy link

vercel bot commented Dec 17, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
frameworks Ready Ready Preview, Comment Dec 17, 2025 11:31am

@scode2277 scode2277 added the content:add This issue or PR adds content or suggests to label Dec 17, 2025
- Moderator
- Verified
- My Account:
- [ ] Ensure **2FA** is enabled (authenticator app and/or security key)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- [ ] User Settings > My Account: Ensure **2FA** is enabled (authenticator app and/or security key), Remove a phone number if you have one added to your account, and after 2FA is setup select **View Backup Codes**, and note down your backup codes offline

- Verified
- My Account:
- [ ] Ensure **2FA** is enabled (authenticator app and/or security key)
- [ ] Ensure **SMS Backup Authentication** is **disabled**
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- [ ] User Settings > My Account: Ensure **SMS Backup Authentication** is **disabled**

- [ ] Ensure **2FA** is enabled (authenticator app and/or security key)
- [ ] Ensure **SMS Backup Authentication** is **disabled**
- Privacy & Safety:
- [ ] Allow direct messages from server members > **Disabled**
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- [ ] User Settings > Content & Social > Social Permissions: Allow DMs from other server members > **Disabled**

- [ ] Ensure **SMS Backup Authentication** is **disabled**
- Privacy & Safety:
- [ ] Allow direct messages from server members > **Disabled**
- [ ] Select **Keep Me Safe** for direct messages (encourages moderators and community members to adopt the same setting to minimize phishing DMs)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- [ ] User Settings > Content & Social > Direct Message Spam: Select **Filter all** to filter all DMs for spam (encourages moderators and community members to adopt the same setting to minimize phishing DMs)

- [ ] Allow direct messages from server members > **Disabled**
- [ ] Select **Keep Me Safe** for direct messages (encourages moderators and community members to adopt the same setting to minimize phishing DMs)
- Authorized Apps:
- [ ] Review and **Deauthorize** any unnecessary apps
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

- [ ] User Settings > Authorized Apps: Review and **Deauthorize** any unnecessary apps

- Review bot permissions after each significant update to avoid newly introduced vulnerabilities.
Beyond enabling in Safety Setup:
- Require users to react to a message or post an introduction — this helps filter out bots and spam accounts from joining
- Implement a verification bot like Wick
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Implement a verification bot like Wick that does in-channel captcha for users to join the server

- Ensure admin/mod roles have "View Audit Log" permission
- Create a private logging channel visible only to admins/mods
- Use a logging bot like Logger or Dyno to send detailed logs
- Audit logs can be output [to a private channel](https://help.mee6.xyz/support/solutions/articles/101000475709-how-to-use-audit-logs-to-track-your-members-actions) for easier monitoring
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd remove this, MEE6 is not recommended due to multiple security incidents in the past


Set up custom rules to prevent other users from joining using the same username and PFP (profile picture) to impersonate
you or other important members of the server. A popular bot in this category is Wick Bot.
Set up custom rules to prevent other users from joining using the same username and PFP (profile picture) to impersonate you or other important members of the server. A popular bot in this category is Wick Bot.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wick's anti-impersonation bot is okey, I would suggest we replace with hashbot here (hashbot.com)


c) **Use the Cold Account for Critical Actions**
**Security:**
- In **User Settings > Privacy & Safety**, deselect any quick login or QR scan options — this prevents attackers from using QR phishing tactics to hijack this high-privilege account
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discord removed this.

### Additional Recommendations

f) **Backup Systems**
- Set up [account leveling](https://mee6.xyz/en/tutorials/how-to-use-levels-plugin-on-your-discord-server) for new members for gradually enabling permissions
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would remove MEE6 due to previous security concerns.

@mattaereal mattaereal requested a review from NFTDreww December 17, 2025 23:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content:add This issue or PR adds content or suggests to

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants