Skip to content
TORNLIFE More

Yikes

Started by Jabajaba [2499335] on in General Discussion.

156 replies · 8.3k views · thread synced · 5 days ago · View on torn.com

Posts archived: 157 / 157 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Viracocha [1772040]
Just checked my API list of recent requests. A bunch 9 days ago. Not an IP I've had assigned to me by my ISP.

actually it turns out I have too many internet connections compared to brain cells. oi vey
Mephiles [2087524]
Just jumping in here to let you guys know that TornTools doesn't collect your API keys like TAC or TornStats does.

Those services require you to enter your API key on their webpage (their servers) but TT API key is entered in the browser extension and stays on your own computer.

As always, TT is open-source if you have any concerns :)
Mud [1740734]
Right, and the catch-22 with the TAC impacted players is they are being told to reset their API key, which has the side effect of unleashing the additional log data.
Vulture [2169837]
I appreciate the team taking action in regards to security. Not knowing the details, I feel like an issue like this could have been pretty easily ignored to some extent.

That said, in my experience, security is something that isn't taken seriously enough, so to see actions like this makes me a happier player.

Hope you're having a good hump day.
CRLF [2095076]
They can only check your activity log if you refreshed your key after the release of logs.

I have no intention of refreshing my key.

This was discussed in the forums a month ago. If release of the events log becomes enough of a concern for people, then I suppose some sort of alternate key may be required. As it stands, providing two separate keys was deemed too confusing for many players.

There is no easy answer. Here is the thread for the earlier discussion:

https://www.torn.com/forums.php#/p=threads&f=63&t=16221376&b=0&a=0&start=0&to=21398630

Mentions: User logs via the API

__-___-___-__ [1921241]
I still use TornTorns, and give it my key, but still... Yes, it's entered into the browser extension but that doesn't preclude it sometime in the future sending that key off to a server. Yes, being open source is helpful, but doesn't preclude you from shipping a modified version to users.

Not saying you would do that.
__-___-___-__ [1921241]
I do think it's fair, and I've worked in this space for a long time. Please reconsider the security model of the API system. I'm happy to jump onto a sub-committee or whatever, and I'm sure a bunch of other experienced people are too, to advise & recommend options here.

The current security model means this was essentially inevitable, and will happen again. Given Torn itself has had exploits and a bug bounty program, you acknowledge security issues are bound to happen. Having a security model that makes a compromise of a 3rd party tool have access to all data, especially now with logs access that lets you see anon bounties, anons messages, anon cash, etc, is incredibly short sighted.
nex [2054500]
The "easy answer" is to add permissions/exclusions to what a third party can do with your API key.

The activity log should be default excluded, no matter how many times you reset your API key. Exposing the activity log to the API was naive at best. Like you said, most users are not at all careful with their API keys, because most users don't know how much info they expose when they submit it to a third party site or using it for a third party script.

Configurable/multiple API keys have been suggested numerous times, because many people foresaw this exact thing happening. None of those people are surprised now, I guarantee you that.
cookdandbombd [2450557] Reporter
Bogie wrote:
I have also spoken with Manuito since TornPDA utilizes features from TAC - However there is no risk to anyone who just uses TornPDA on its own, no data was shared from PDA to TAC, only information given directly to TAC is the concern at this time.

Glad I had another read through the thread, as this was a concern. TAC always seemed a bit sus to me; why should you specifically need an API key to use it, rather than just typing your stats in? Partly to make sure people who haven't paid their pixel money can't use it, I guess?

Regardless, I'm relieved I just stuck with good old Duke missions.
Kamikaze-Tool [2035028] Committee Committee
I 100% paid for TAC for my faction because it was a committee member and they can't scam. Would not have trusted the thing otherwise.
Bumfluff [969606] Wiki Contributor
For those who are not very aware of what the activity log reveals, do not worry about it sharing your IP or other personal information - it is hidden.

For example:

log": {
"tCGLNxBOC20CuHOQXTEa": {
"log": 101,
"title": "Successful login",
"timestamp": 1625078817,
"data": {
"ip_address": "hidden"}
DedeSiregar [2430598]
I always thought chaining should be the time to revenge people who f**ked us or our friends over anyway so I never used it.
Andyman [471591]
Keep in mind, after the API reset, anyone who has access to your API key also has access to your event log and by extension your cash on hand in a verified manner that trends could be built from.

Got an event showing your bank investment is up? So does the individual with your API key. !stalk green dot

Got an event saying someone won the auction for the Pocket Shotgun you put up for $140m? So does the individual with your API key. !set reminder 24hrs "cashier's check cashed"

Got an event showing 3 noobs rented the 3 private islands you put up for 15 days each at $13.5m before you went to bed? So does the individual with your API key. Time to mug!

Ever drop an anonymous dirty bomb and never want that information exposed for fear of retaliation? Guess what kind of dirt the individual with your API key has on you!?

You get the idea!

TornStats (run solely by longtime trusted staff member IceBlueFire) is the only site I recommend putting your API in... Ched basically sanctioned this site by footing some of the bill a while back.