惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
B
Blog RSS Feed
A
About on SuperTechFans
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 司徒正美
D
Docker
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
H
Help Net Security
WordPress大学
WordPress大学
MyScale Blog
MyScale Blog
博客园 - Franky
人人都是产品经理
人人都是产品经理
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Discord adds end-to-end encryption to voice and video cal...
Pierluigi Pa · 2026-05-21 · via Security Affairs

Discord now enables end-to-end encryption by default for all voice and video calls, making conversations inaccessible even to the platform itself.

No announcement fanfare, no opt-in required, no settings to dig through. Discord flipped a switch on Monday and end-to-end encryption is now the default for every voice and video call on the platform. If you used Discord to call someone today, that conversation was encrypted in a way that even Discord cannot access.

“End-to-end Encryption is now standard for every voice and video call on Discord, outside of stage channels. No opt-in required.” announced Discord.

That is a bigger deal than it might sound, especially right now.

The timing is notable. Earlier this month, Meta quietly removed end-to-end encryption from Instagram’s direct messaging feature, a step backward that drew criticism but not much sustained attention. TikTok also confirmed it would not be adding end-to-end encryption to direct messages. Two of the largest social platforms in the world are moving away from private communications, while Discord moves toward it. The contrast is hard to miss.

Discord has been building toward this for a while. The company launched end-to-end encrypted voice and video calling back in 2024, initially as an opt-in feature.

“It’s been quite a journey since then. In September 2024, Stephen Birarda introduced the DAVE protocol: an open, audited end-to-end encryption protocol for audio and video. We began migrating calls on desktop and mobile and started proving that E2EE could operate at Discord’s scale without compromising the experience people expect from us.” reads the announcement. “In 2025, Clément Brisset extended DAVE to every remaining platform, including web browsers, gaming consoles, support for Discord bots/apps, and our Social SDK, helping close the gaps that had kept some calls from being fully encrypted. And at the beginning of March 2026, we completed that migration. “

Monday’s change simply made it the default for everyone, automatically, with no action needed on the user’s side. Stage channels are the only exception, those are designed for broadcast-style communication where the expectation of privacy is different.

Discord said its DAVE encryption protocol was designed to support voice and video calls across diverse devices like PCs, phones, consoles, and browsers with minimal latency. The protocol and implementation are open-source, externally audited by Trail of Bits, and covered by a bug bounty program. Discord also worked with Mozilla to fix a Firefox issue affecting encrypted calls, aiming for a seamless transition for users.

“As of early March 2026, every voice and video call on Discord, whether in DMs, group DMs, voice channels, or Go Live streams, is end-to-end encrypted by default. To complete that migration, we required all clients to support DAVE before joining a call.” continues the announcement. “We are now in the process of removing the client code that supports unencrypted fallback. After that is done, it will not be possible to fall back to unencrypted connections.”

For a platform with hundreds of millions of users, many of them younger people using Discord as their primary way to hang out with friends online, this is a meaningful baseline privacy upgrade that most of them will never have to think about. It just works, in the background, on every call.

The broader context here is worth sitting with for a moment. End-to-end encryption for messaging and calling has been a live debate for years, caught between genuine privacy advocates, law enforcement agencies that argue it hampers investigations, and platform companies navigating both. Discord has landed clearly on one side of that debate, at least for voice and video, and has done it in the most user-friendly way possible: by making it the default rather than something you have to seek out in a settings menu.

It is unclear whether Discord extends the same protection to text messages. For now, the voice and video change alone puts it ahead of most mainstream social platforms on this specific privacy dimension, at a moment when several of those platforms are going in the opposite direction.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, end-to-end encryption)