Skip to content
TORNLIFE More

Fedded Archives

Started by CRLF [2095076] on in General Discussion.

39,779 replies · 794k views · thread synced · View on torn.com

Posts archived: 39,780 / 39,780 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

__-___-___-__ [1921241]
I hope fr00t doesn't become a scape goat for a security issue the Torn API using community has warned about, and requested to fixed, for a long time.

Assuming this was TAC having a vuln that exposed API keys and not fr00t sharing keys with people, then this issue really lands on Torn not fr00t.

Even Torn itself has had vulnerabilities, and will do in the future (fed Duke!). I've privately let IceBlueFire know about an issue a TornStats feature that was promptly fixed - I wasn't even looking, who knows what exists there, security is *hard*. I don't think they'd fed IBF for a technical security issue in TornStats.
nex [2054500]
That would be a convenient scapegoat, wouldn't it?

Doesn't matter if fr00t leaked those API keys willingly or TAC had a vulnerability. The potential (and, now, very real) impact of activity logs being accessed by anyone with your API key was a humongous oversight. An oversight that could've been prevented, easily, but was ignored.

We can only speculate as to how many people have been mugged for millions or billions of their hard earned Torn cash because someone could follow their every bazaar sale, stock sale or vault withdrawal.
cookdandbombd [2450557] Reporter
It's a very worrying situation, as if he is guilty, then - yes - it's very easy for him to go, "ohhh, someone hacked my server though; okay I f**ked up some security stuff, but it wasn't my fault that it escalated after that."

Way too easy to claim plausible deniability, and given he's being investigated for other things, the #FreeFroot campaign by his fac mates looks premature to say the least.
nex [2054500]
His guilt is the least of my worries, really. There's no way to check how many people were mugged because someone had their API key and saw that they had tons of money on hand. Those people won't get their money back, fr00t being in fed or not.

Seems to me it would've been easier to prevent this from happening in the first place, but oh well.
CRLF [2095076]
Yes, prevented by not exposing cash on hand via the events log.

It's a pity no one pointed that out a couple months ago, when we discussed the impact of logs through the API.

I guess the same users who are not savvy enough to figure out two API keys are supposed to be brilliant enough to detect when their API key has been hijacked by a rogue app.

Yup, sounds legit to me.
nex [2054500]
Or just making the activity log strictly opt-in, since it's both absolutely shit-full of exploitable data and not actually useful for 99% of the scripts/third party sites that asks for API keys.

The fact that it was included in the API without a (default) option to opt-out is beyond mind boggling. This was absolutely guaranteed to happen.
CRLF [2095076]
Nah, not at all.

It's just like removing stock sales from the plane at the exact same time you roll out a major stock change that would drive players to move money out of Caymans.

The results were totally unforeseeable, and no one pointed out in advance exactly what would happen.

Honestly, I'm not sure why anyone bothers to ask the player base for their opinion when that opinion is ignored.

Sometimes it feels like the decision was made in advance and player "opinion" is merely sought to confirm a foregone conclusion. No matter the question, you can usually find a couple people to provide the answer you want to hear, so you can just go with that.
Absinthian [2263711] Committee Committee
Am I understanding this correctly? I had never changed my API, but I did now because of the notification. Now due to that I am more vulnerable to attacks and such?!?!
__-___-___-__ [1921241]
You are not more vulnerable to attacks, if you define it as the chance of someone getting access and misusing your key. For example, there really isn't a change in the risk of being mugged because that's available even before.

What has changed is the scope of data someone could get access to IF they get their hands on it. Since most actions end up in the activity log, they can potentially learn more now. Some would already be in your event logs, although that history is far more limited than the activity logs.

The most interesting ones at first glance that someone who gets access to your can could see now that they couldn't before are:
GreekPoser [2527893]
"For example, there really isn't a change in the risk of being mugged because that's available even before."

Excuse me if I'm wrong but I think the log will let the mugger check everytime you get money in a win in blackjack or other pvm casino games that don't have events. That's something the old api didn't granted info directly about your money flow I think.