f**k i wish i read that.... -_-
Yikes
Started by Jabajaba [2499335] on in General Discussion.
Posts archived: 157 / 157 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Lol what about them we call "scammer" lmao
Just jumping in here to let you guys know that TornTools doesn't collect your API keys like TAC or TornStats does.
Those services require you to enter your API key on their webpage (their servers) but TT API key is entered in the browser extension and stays on your own computer.
As always, TT is open-source if you have any concerns :)
Those services require you to enter your API key on their webpage (their servers) but TT API key is entered in the browser extension and stays on your own computer.
As always, TT is open-source if you have any concerns :)
more api, less third party add ons...
>.<
>.<
Right, and the catch-22 with the TAC impacted players is they are being told to reset their API key, which has the side effect of unleashing the additional log data.
I appreciate the team taking action in regards to security. Not knowing the details, I feel like an issue like this could have been pretty easily ignored to some extent.
That said, in my experience, security is something that isn't taken seriously enough, so to see actions like this makes me a happier player.
Hope you're having a good hump day.
That said, in my experience, security is something that isn't taken seriously enough, so to see actions like this makes me a happier player.
Hope you're having a good hump day.
They can only check your activity log if you refreshed your key after the release of logs.
I have no intention of refreshing my key.
This was discussed in the forums a month ago. If release of the events log becomes enough of a concern for people, then I suppose some sort of alternate key may be required. As it stands, providing two separate keys was deemed too confusing for many players.
There is no easy answer. Here is the thread for the earlier discussion:
https://www.torn.com/forums.php#/p=threads&f=63&t=16221376&b=0&a=0&start=0&to=21398630
I have no intention of refreshing my key.
This was discussed in the forums a month ago. If release of the events log becomes enough of a concern for people, then I suppose some sort of alternate key may be required. As it stands, providing two separate keys was deemed too confusing for many players.
There is no easy answer. Here is the thread for the earlier discussion:
https://www.torn.com/forums.php#/p=threads&f=63&t=16221376&b=0&a=0&start=0&to=21398630
Mentions: User logs via the API
I still use TornTorns, and give it my key, but still... Yes, it's entered into the browser extension but that doesn't preclude it sometime in the future sending that key off to a server. Yes, being open source is helpful, but doesn't preclude you from shipping a modified version to users.
Not saying you would do that.
Not saying you would do that.
Wow... this REALLY did not age well.... from the link I posted above:
[image: gyazo.com]
Right, Fr00t... most users are not at all careful with their API keys....
[image: gyazo.com]
Right, Fr00t... most users are not at all careful with their API keys....
I do think it's fair, and I've worked in this space for a long time. Please reconsider the security model of the API system. I'm happy to jump onto a sub-committee or whatever, and I'm sure a bunch of other experienced people are too, to advise & recommend options here.
The current security model means this was essentially inevitable, and will happen again. Given Torn itself has had exploits and a bug bounty program, you acknowledge security issues are bound to happen. Having a security model that makes a compromise of a 3rd party tool have access to all data, especially now with logs access that lets you see anon bounties, anons messages, anon cash, etc, is incredibly short sighted.
The current security model means this was essentially inevitable, and will happen again. Given Torn itself has had exploits and a bug bounty program, you acknowledge security issues are bound to happen. Having a security model that makes a compromise of a 3rd party tool have access to all data, especially now with logs access that lets you see anon bounties, anons messages, anon cash, etc, is incredibly short sighted.
The "easy answer" is to add permissions/exclusions to what a third party can do with your API key.
The activity log should be default excluded, no matter how many times you reset your API key. Exposing the activity log to the API was naive at best. Like you said, most users are not at all careful with their API keys, because most users don't know how much info they expose when they submit it to a third party site or using it for a third party script.
Configurable/multiple API keys have been suggested numerous times, because many people foresaw this exact thing happening. None of those people are surprised now, I guarantee you that.
The activity log should be default excluded, no matter how many times you reset your API key. Exposing the activity log to the API was naive at best. Like you said, most users are not at all careful with their API keys, because most users don't know how much info they expose when they submit it to a third party site or using it for a third party script.
Configurable/multiple API keys have been suggested numerous times, because many people foresaw this exact thing happening. None of those people are surprised now, I guarantee you that.
Bogie wrote:
I have also spoken with Manuito since TornPDA utilizes features from TAC - However there is no risk to anyone who just uses TornPDA on its own, no data was shared from PDA to TAC, only information given directly to TAC is the concern at this time.
Glad I had another read through the thread, as this was a concern. TAC always seemed a bit sus to me; why should you specifically need an API key to use it, rather than just typing your stats in? Partly to make sure people who haven't paid their pixel money can't use it, I guess?
Regardless, I'm relieved I just stuck with good old Duke missions.
I 100% paid for TAC for my faction because it was a committee member and they can't scam. Would not have trusted the thing otherwise.
For those who are not very aware of what the activity log reveals, do not worry about it sharing your IP or other personal information - it is hidden.
For example:
log": {
"tCGLNxBOC20CuHOQXTEa": {
"log": 101,
"title": "Successful login",
"timestamp": 1625078817,
"data": {
"ip_address": "hidden"}
For example:
log": {
"tCGLNxBOC20CuHOQXTEa": {
"log": 101,
"title": "Successful login",
"timestamp": 1625078817,
"data": {
"ip_address": "hidden"}
FreeTheHomieFr00t
Tac is a great tool for chaining I hope everything resolves well.
Tac is a great tool for chaining I hope everything resolves well.
Considering Ill be chain watching this week, I guess I should start double checking my backup target list.
From a concerned citizen... it seems the player info may have been re-purposed....
[image: gyazo.com]
[image: gyazo.com]
I always thought chaining should be the time to revenge people who f**ked us or our friends over anyway so I never used it.
Keep in mind, after the API reset, anyone who has access to your API key also has access to your event log and by extension your cash on hand in a verified manner that trends could be built from.
Got an event showing your bank investment is up? So does the individual with your API key. !stalk green dot
Got an event saying someone won the auction for the Pocket Shotgun you put up for $140m? So does the individual with your API key. !set reminder 24hrs "cashier's check cashed"
Got an event showing 3 noobs rented the 3 private islands you put up for 15 days each at $13.5m before you went to bed? So does the individual with your API key. Time to mug!
Ever drop an anonymous dirty bomb and never want that information exposed for fear of retaliation? Guess what kind of dirt the individual with your API key has on you!?
You get the idea!
TornStats (run solely by longtime trusted staff member IceBlueFire) is the only site I recommend putting your API in... Ched basically sanctioned this site by footing some of the bill a while back.
Got an event showing your bank investment is up? So does the individual with your API key. !stalk green dot
Got an event saying someone won the auction for the Pocket Shotgun you put up for $140m? So does the individual with your API key. !set reminder 24hrs "cashier's check cashed"
Got an event showing 3 noobs rented the 3 private islands you put up for 15 days each at $13.5m before you went to bed? So does the individual with your API key. Time to mug!
Ever drop an anonymous dirty bomb and never want that information exposed for fear of retaliation? Guess what kind of dirt the individual with your API key has on you!?
You get the idea!
TornStats (run solely by longtime trusted staff member IceBlueFire) is the only site I recommend putting your API in... Ched basically sanctioned this site by footing some of the bill a while back.