Skip to content
TORNLIFE More

HTTPS for everyone? Playing securely.

Started by quaffgiggle [2008372] on in Suggestions.

41 replies · 267 views · thread synced · 7 days ago · View on torn.com

Posts archived: 42 / 42 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Mauk [1494436]

"Completely kill the script community"?
"it is a major detriment to any script operating"?

That's simply not true, at all. Scripts work just fine under https with minimal changes-- in fact, the only reason they are needed is because scripters tend to write "http://" because that's what they use..
AshleyT [1432316]

You do realize how many security requests that would pertain?

Most scripts in Torn currently would cease to function if they go beyond a basic function because most request data from the site to operate, something you can't do on a whim if you have to go through a secure layer.
Mauk [1494436]

That's simply not how scripts work... They can and do make requests to https endpoints on a whim.
You aren't a developer, are you?
AshleyT [1432316]

I'm a Computer Student that only just finished Level 5. And in that capacity, I am trained in programming.

What I mean is that you need to specifically make those requests with the security tied to them, something you do not need without that secure layer, which doesn't create much slowdown on it's own but quickly adds up.

And if you don't add the additional security information to the script, the secure layer rejects it as a threat.
Mauk [1494436]

Okay, it appears you really, truly do believe that. Your usage of pretty but empty phrasing like "secure layer" and "rejects it as a threat" makes it clear you still have quite a lot to learn. I don't say this as an attack-- everyone's been there, and everyone should always be learning.

However, I feel obligated to point out that's factually incorrect. HTTPS simply doesn't affect scripts that way. Greasemonkey/tampermonkey scripts and browser extensions have access to https endpoints and it makes basically no difference for the developers. There are no specific security details to be manually added to requests. HTTPS would not, in any possible way, kill Torn's scripting community. Just use your normal AJAX/XMLHttpRequest calls to an https endpoint instead of an http one and it'll keep working.

Even CORS requests, which usually give people some trouble, are no-brainers in scripts.

And for standalone programs, https makes even less of a difference.

ps. I've helped multiple people with their Torn scripts and I have an extension with ~1,500 weekly (and over ~2k monthly) users. If you're having troubles getting your script to work because you think "you need to add the additional security information," feel free to message/chat me up and I'll gladly help you out.

Mentions: DoctorN v6.5.0 - Definitely not

Harley [258120] Wiki Contributor

How on earth would enforcing https kill the script community?! Both DoctorN and Tornstats , Torn's two most used scripts, function perfectly fine on https? It's not at all 'detriment to any script operating' if the programmer in question actually knows what they're doing.

Forced https is coming sooner rather than later. The reason ched removed it earlier was because Torn wasn't prepared for the change then, but I'm fairly sure ever since ched has been looking to change it again.


AshleyT [1432316]

Because, under the knowledge I have, those scrips pull data from torn, and would hit the secure layer of https, and without the proper identification, would be rejected.
Mauk [1494436]

I pretty much never downvote posts, but at this point you're just consciously spreading misinformation.

Under the knowledge you have, you know you've never touched userscripts. That much is clear.
AshleyT [1432316]

Then what does the secure layer of https even do if it doesn't prevent requests of information. I imagine the encryption would also need to be applied to all data sent and received, including user scripts.
AshleyT [1432316]

I just respond with equal dislikes. No more, no less.

If I responded with more I'd be just a jerk.

If I responded with less or none at all I'd just be ignoring you.

Regardless, I am not spreading false information, to my knowledge, but clearly he thinks I am, and appears to be some kind of expert that knows more than me.

Anything I said is correct to the information I have and was taught during my level 4-5 course, but it is not thorough in the slightest.
AshleyT [1432316]

No, level 2 is the top class in high school, and college teaches that level from introduction, 1 to 3. 4 through 8 are University level, with level's 7 and 8 not available unless if you have experience in the workplace of your chosen field already, 7 requires 5 years, 8 requires 10.
Grif [882958]

scotland but looking at it we have different numbers, but 4 would be our adv higher, so 6th year of highschool, or first year of college here(HNC) is 7 here but its 4 in england, 5 is hnd for you, and its 8 for us, which is the same as 2nd year of uni, (we do a 4 year honors)

so basically you are effectively going into a 3rd year uni level
Jeggy [1526723]

R+

Not using HTTPS means anyone that sniffs your network can read directly what you are doing on torn and get your login information easily.

I know it's not much to hide on torn, but I really don't see why anyone would argue against this suggestion. It's always better to use SSL unless maybe if the site doesn't get any user input of any kind.

And the argument that it'll break some scripts goes both ways, it's really annoying for my script that it's possible to use both as I use the LocalStorage and you can't share localstorage with HTTPS and HTTP.