Hello all.
Unfortunately we received indication that TAC (Tornattackcentral) had a vulnerability resulting in the potential for API keys to be exposed. Whilst we do not believe there was any serious leak here this is a precautionary measure we have taken to ensure users are made aware.
If you received an event it means that your key had the potential to be exposed, if not then there was no risk - however if you feel unsafe please do reset your key.
I am in the process of speaking with Fr00t about this currently as there were some other concerns that needed to be raised with him regarding this site and their own personal activity that I cannot disclose at this time, however this has no major impact on anyone else at this time.
I have also spoken with Manuito since TornPDA utilizes features from TAC - However there is no risk to anyone who just uses TornPDA on its own, no data was shared from PDA to TAC, only information given directly to TAC is the concern at this time.
Rest assured no personal information related to Torn is at risk.
This is an excellent time to highlight that these third party sites and scripts can come with risk, and to give your API key out only to areas you can trust - Unfortunately however issues like this can and will come up from time to time - Creators are however required to comply with a certain level of security to keep information given to them on faith secure as detailed in the
API documentation.
The API exists as a feature to ensure there is no risk of losing your secure and important Torn data, but do bear in mind it can carry a lot of information about your gameplay - it is sensible to limit how much you give this out.
Thank you everyone.