Hacker News new | ask | show | jobs
by scottdevries 1181 days ago
We use Discord as a Slack alternative, and have for a couple years. It's perfect for a remote company, especially if you also run chat/messaging for customers and users.
4 comments

How do you deal with security?

- No SSO

- No way to enforce MFA, restrict logins to trusted devices and IPs, etc...

- No message / audit logs

I like discord for personal use, no way I would use it professionally

There's no way to enforce MFA? How do you figure?

Give new users a very short window, or not able to use until their hardware key, phone enclave, etc is registered for MFA.

You could even go as far as to send pre-registered hardware keys by mail, or have them picked up from HQ upon hire.

Certainly would have solved some of the recent "who actually works in infra at Twitter" debacle, now that I'm thinking about it.

That's how you get people to use MFA, but AFAIK there's no feature in Discord to a) federate with a directory like AD or b) force users on a server to only be able to sign in with a hw key
How do you know folks are using their hw keys to log in discord?
Discord UI is so complicated, I feel old, im always clicking the wrong buttons. Im sure you get used to it soon, and probably more powerful once you do.
Discord lacks a lot of work specific features
I know the upsides, but what do you lose if you switch from Slack to Discord?
Your sanity. Discord is insanely cluttered. It's made for people who aren't trying to get any work done.