-
Notifications
You must be signed in to change notification settings - Fork 48
Integrating w3os discord guide into frameworks #321
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: develop
Are you sure you want to change the base?
Integrating w3os discord guide into frameworks #321
Conversation
…utor details - Enhanced the Discord management documentation with a new summary section outlining key security measures. - Introduced a comprehensive account security checklist for individuals and team members. - Updated contributor information to include Auditware, reflecting their role and contributions. - Streamlined content for clarity and improved organization of security measures and guidelines.
|
@DicksonWu654 is attempting to deploy a commit to the Security Alliance Team on Vercel. A member of the Team first needs to authorize it. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
| - Moderator | ||
| - Verified | ||
| - My Account: | ||
| - [ ] Ensure **2FA** is enabled (authenticator app and/or security key) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ] User Settings > My Account: Ensure **2FA** is enabled (authenticator app and/or security key), Remove a phone number if you have one added to your account, and after 2FA is setup select **View Backup Codes**, and note down your backup codes offline
| - Verified | ||
| - My Account: | ||
| - [ ] Ensure **2FA** is enabled (authenticator app and/or security key) | ||
| - [ ] Ensure **SMS Backup Authentication** is **disabled** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ] User Settings > My Account: Ensure **SMS Backup Authentication** is **disabled**
| - [ ] Ensure **2FA** is enabled (authenticator app and/or security key) | ||
| - [ ] Ensure **SMS Backup Authentication** is **disabled** | ||
| - Privacy & Safety: | ||
| - [ ] Allow direct messages from server members > **Disabled** |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ] User Settings > Content & Social > Social Permissions: Allow DMs from other server members > **Disabled**
| - [ ] Ensure **SMS Backup Authentication** is **disabled** | ||
| - Privacy & Safety: | ||
| - [ ] Allow direct messages from server members > **Disabled** | ||
| - [ ] Select **Keep Me Safe** for direct messages (encourages moderators and community members to adopt the same setting to minimize phishing DMs) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ] User Settings > Content & Social > Direct Message Spam: Select **Filter all** to filter all DMs for spam (encourages moderators and community members to adopt the same setting to minimize phishing DMs)
| - [ ] Allow direct messages from server members > **Disabled** | ||
| - [ ] Select **Keep Me Safe** for direct messages (encourages moderators and community members to adopt the same setting to minimize phishing DMs) | ||
| - Authorized Apps: | ||
| - [ ] Review and **Deauthorize** any unnecessary apps |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ] User Settings > Authorized Apps: Review and **Deauthorize** any unnecessary apps
| - Review bot permissions after each significant update to avoid newly introduced vulnerabilities. | ||
| Beyond enabling in Safety Setup: | ||
| - Require users to react to a message or post an introduction — this helps filter out bots and spam accounts from joining | ||
| - Implement a verification bot like Wick |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Implement a verification bot like Wick that does in-channel captcha for users to join the server
| - Ensure admin/mod roles have "View Audit Log" permission | ||
| - Create a private logging channel visible only to admins/mods | ||
| - Use a logging bot like Logger or Dyno to send detailed logs | ||
| - Audit logs can be output [to a private channel](https://help.mee6.xyz/support/solutions/articles/101000475709-how-to-use-audit-logs-to-track-your-members-actions) for easier monitoring |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd remove this, MEE6 is not recommended due to multiple security incidents in the past
|
|
||
| Set up custom rules to prevent other users from joining using the same username and PFP (profile picture) to impersonate | ||
| you or other important members of the server. A popular bot in this category is Wick Bot. | ||
| Set up custom rules to prevent other users from joining using the same username and PFP (profile picture) to impersonate you or other important members of the server. A popular bot in this category is Wick Bot. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Wick's anti-impersonation bot is okey, I would suggest we replace with hashbot here (hashbot.com)
|
|
||
| c) **Use the Cold Account for Critical Actions** | ||
| **Security:** | ||
| - In **User Settings > Privacy & Safety**, deselect any quick login or QR scan options — this prevents attackers from using QR phishing tactics to hijack this high-privilege account |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Discord removed this.
| ### Additional Recommendations | ||
|
|
||
| f) **Backup Systems** | ||
| - Set up [account leveling](https://mee6.xyz/en/tutorials/how-to-use-levels-plugin-on-your-discord-server) for new members for gradually enabling permissions |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would remove MEE6 due to previous security concerns.
Frameworks PR Checklist
Integrating w3os discord guide into frameworks
This is from #305. @NFTDreww suggested we merge discord first into frameworks, then work on the other ones. This has alreayd been approved by NFT Drew
vocs.config.tsadding thedev: trueparameter