And it is exactly all the stuff you've been mentioning as to why I ahve yet to reset my API after the log activity change, and will just let this go, because I can't control it otherwise, outside Proxima's suggestion for yet another third party app.
Yikes
Started by Jabajaba [2499335] on in General Discussion.
Posts archived: 157 / 157 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
TornStats.
TornTools + a few extensions I wrote myself, need to update them both on my desktop as well as my phone.
Then there are the tools I wrote for my faction for things like chain reports, etc.
TornTools + a few extensions I wrote myself, need to update them both on my desktop as well as my phone.
Then there are the tools I wrote for my faction for things like chain reports, etc.
I think he meant Nobody. I was going to ask him if he was surprised, but he's offline.
[image: gyazo.com]
[image: gyazo.com]
Oh no, my chain target income!
this ^^^
My reaction when an external website (aside from Tornstats) asks for my API key :
[image: media1.tenor.com]
My reaction when an external website (aside from Tornstats) asks for my API key :
[image: media1.tenor.com]
Perhaps we could introduce multiple api keys per user now?
If only there was a suggestion thread and someone could post the link (again)
also insert NordVPN ad here
also insert NordVPN ad here
https://www.torn.com/forums.php#/p=threads&f=4&t=16123202
oh look, it’s almost at 250 upvotes at which point it will be kicked up the chain for careful consideration
oh look, it’s almost at 250 upvotes at which point it will be kicked up the chain for careful consideration
Let's be honest, it was only a matter of time. Tac made itself a prime target for anybody looking to exploit the API by being a list of wealthy players who are able to pay for the service.
Really do wonder where this falls in the rules. Is there anything about exploiting a 3rd party site to farm data the user has willingly given away?
Really do wonder where this falls in the rules. Is there anything about exploiting a 3rd party site to farm data the user has willingly given away?
I don't think that's very effective unless you are actively monitoring the pulls.
What would work better as I mentioned is if a community member created a secondary key(s) from yours and fed through them as well as had permission selections, so basically a 3rd party filter where you can say "I don't want this being shared" or "I only want this being shared" not dissimilar to phone permissions for different access levels. I mean it'd be a great addition to torn itself, I just don't see the devs doing it.
On top of that, depending on who creates it, that person will still have full access, so there's always a level of trust somewhere.
Basically this suggestion through a 3rd party but also including permissions checkboxes for each, allowing/limiting what they have access to.
https://www.torn.com/forums.php#/p=threads&f=4&t=16123202
Obviously it'd be more ideal and secure if it were from Torn itself, but as Ched stated, they wont do it.
What would work better as I mentioned is if a community member created a secondary key(s) from yours and fed through them as well as had permission selections, so basically a 3rd party filter where you can say "I don't want this being shared" or "I only want this being shared" not dissimilar to phone permissions for different access levels. I mean it'd be a great addition to torn itself, I just don't see the devs doing it.
On top of that, depending on who creates it, that person will still have full access, so there's always a level of trust somewhere.
Basically this suggestion through a 3rd party but also including permissions checkboxes for each, allowing/limiting what they have access to.
https://www.torn.com/forums.php#/p=threads&f=4&t=16123202
Obviously it'd be more ideal and secure if it were from Torn itself, but as Ched stated, they wont do it.
Content reclaimed.
While all of that is made simpler by the using the activity log, every example you listed is completely doable without it.
I think the complaints around the activity log in the api are a bit overstated. The abuse potential isn't all that much higher than before the update.
I think the complaints around the activity log in the api are a bit overstated. The abuse potential isn't all that much higher than before the update.
problem with bumping that suggestion R+ liking whatever.. is that ched has already responded that it would suck too much and bc they designed it from the ground up to be a single key system, my inference was they would need to build it from the ground up again - but i dunno. i didnt even know there was a control panel.. can you toggle specific data?
can you put in a single toggle for the log *without* some gigantic workload? maybe go find that part of the patch that published the log and unpublish it?
can you put in a single toggle for the log *without* some gigantic workload? maybe go find that part of the patch that published the log and unpublish it?
Beat you by over a minute, suck it bitch!
Api proxy has been done before but didn’t work out because of IP based rate limits.
Can I just say here, anyone trusting third party tools or sites is kind of ridiculous. I use tornstats and IceBlueFire is a fine person and all. I talk to him in Discord and make suggestions to imrpove it. I think he means well. I think he is a nice person. I don't THINK he would abuse my keys, but if it were later found out that he was, would I be surprised? No. If you have played online games more than a day, you know people are scamming for access to your intel at all times.
I came to this game with a person in fed named Prehensile. I would have trusted Prehensile with just about anything, yet there he is in fed for running multiple accounts and cheating. Right?
Only reason I am even on tornstats is because it is required. If it were not, I would not even use that.
Those of you out there using optional stuff get what you deserve. Trusting ANYONE in a gaming community is foolish.
Two stories:
Story Number One: The unintentional harm.
In another game I was on a competitive team and one of my teamates had to be in an important meeting at the same time we had to do some strategic stuff. So that guy trusted one of our folks in charge to remote into his computer and control that account during the critical time (technically, that was cheating.... btw). The guy in leadership, who is genuinely a pretty good guy, thought it would be funny to leave the computer running on "meatspin" (for those of you who know what that is) and logged off. This would NORMALLY be kind of funny to many people, but unfortunately, the person's ex-wife showed up before he did to drop off their 5 year old daughter for her custody visit.... Not so funny...
Story Number Two: The intentional harm.
Same game, there was a popular war planning tool that tracked intel gathered, troop strength etc etc etc . Turns out the guys who developed it made sure that had full access to every report made to it. The tool was almost universally used, and most teams had no problems because they were so low value that the developers would never even bother with them, but the teams attempting to become competitive had a nasty surprise.
DO NOT TRUST PEOPLE.
NO
NOT EVEN THEN
ESPECIALLY NOT THEN
NO
JUST NO
NO
STOP IT
STOP TRUSTING PEOPLE!
I came to this game with a person in fed named Prehensile. I would have trusted Prehensile with just about anything, yet there he is in fed for running multiple accounts and cheating. Right?
Only reason I am even on tornstats is because it is required. If it were not, I would not even use that.
Those of you out there using optional stuff get what you deserve. Trusting ANYONE in a gaming community is foolish.
Two stories:
Story Number One: The unintentional harm.
In another game I was on a competitive team and one of my teamates had to be in an important meeting at the same time we had to do some strategic stuff. So that guy trusted one of our folks in charge to remote into his computer and control that account during the critical time (technically, that was cheating.... btw). The guy in leadership, who is genuinely a pretty good guy, thought it would be funny to leave the computer running on "meatspin" (for those of you who know what that is) and logged off. This would NORMALLY be kind of funny to many people, but unfortunately, the person's ex-wife showed up before he did to drop off their 5 year old daughter for her custody visit.... Not so funny...
Story Number Two: The intentional harm.
Same game, there was a popular war planning tool that tracked intel gathered, troop strength etc etc etc . Turns out the guys who developed it made sure that had full access to every report made to it. The tool was almost universally used, and most teams had no problems because they were so low value that the developers would never even bother with them, but the teams attempting to become competitive had a nasty surprise.
DO NOT TRUST PEOPLE.
NO
NOT EVEN THEN
ESPECIALLY NOT THEN
NO
JUST NO
NO
STOP IT
STOP TRUSTING PEOPLE!
Well Ched won't code it, he should allow the user to do it with this specific case in mind. Alternatively, ched could do it themselves and instead of reworking the entire system, add another layer the same way modders were trying to do without touching any of the underlying system.
EIther way, there's no guarantee against abuse. TBH I don't even trust TornTools, I just use it because its a huge disadvantage for not using it.
So I use Tornstats because it's required by faction
Torntools because it has a lot of the functionality ched refuses to code.
And YATA, I think Tornstats uses it as well?
Do I trust them? No, I don't even know all the people in control of them let alone trust them. But I acknowledge that if they are using the information to damage me it's doing less damage than the gains from using them. So in this case it's I trust they're doing more good than bad for me personally.
Honestly, Id trust torntools more if it slipped in unintrusive ads, at least there'd be motive there for doing what they do. Without any clear benefits to them the only benefit is having your torn information. I realize it's resume material but you cant expect everything everyone codes to have pure motives.
EIther way, there's no guarantee against abuse. TBH I don't even trust TornTools, I just use it because its a huge disadvantage for not using it.
So I use Tornstats because it's required by faction
Torntools because it has a lot of the functionality ched refuses to code.
And YATA, I think Tornstats uses it as well?
Do I trust them? No, I don't even know all the people in control of them let alone trust them. But I acknowledge that if they are using the information to damage me it's doing less damage than the gains from using them. So in this case it's I trust they're doing more good than bad for me personally.
Honestly, Id trust torntools more if it slipped in unintrusive ads, at least there'd be motive there for doing what they do. Without any clear benefits to them the only benefit is having your torn information. I realize it's resume material but you cant expect everything everyone codes to have pure motives.
I'll take, things you say after sex, for £200 please :p
Edit
Unless it's 1st party and covered by the rules all that will happen is that then becomes the target for attack and the data is exploited from there. Any API proxy or tool would just be painting a target on its back.
Edit
Unless it's 1st party and covered by the rules all that will happen is that then becomes the target for attack and the data is exploited from there. Any API proxy or tool would just be painting a target on its back.
Bank investments are public now?
There's a foolproof way to tell if a player dropped a dirty bomb?
The auction house is do-able, albeit a ballache to gather the data for, as you noted.
PI rentals much more complicated since listings can (and are) regularly removed and relisted.
There's a foolproof way to tell if a player dropped a dirty bomb?
The auction house is do-able, albeit a ballache to gather the data for, as you noted.
PI rentals much more complicated since listings can (and are) regularly removed and relisted.
I assumed you were talking about the activity log, since it was mentioned a couple of times in this thread.
You do of course need access to someone's api key for all of the things you listed.
My point simply was that whether a key has logs unlocked (which is triggered by a key reset) doesn't significantly increase the abuse potential if someone were to try to use it against you.
You do of course need access to someone's api key for all of the things you listed.
My point simply was that whether a key has logs unlocked (which is triggered by a key reset) doesn't significantly increase the abuse potential if someone were to try to use it against you.
Mentions: Patch list #190 : 27/04/2021