Hacker News new | ask | show | jobs
by numpad0 666 days ago
If I'm reading GP right: there is a QR code displayed prominently on Discord login screen, which is an image. Opening the link on a phone that is also logged into Discord skips everything and completes login process. That QR code can be sent to a victim under false pretense for account takeover?