Skip to content
TORNLIFE More

Yikes

Started by Jabajaba [2499335] on in General Discussion.

156 replies · 8.3k views · thread synced · 4 days ago · View on torn.com

Posts archived: 157 / 157 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Varides [2176530]
And it is exactly all the stuff you've been mentioning as to why I ahve yet to reset my API after the log activity change, and will just let this go, because I can't control it otherwise, outside Proxima's suggestion for yet another third party app.
__-___-___-__ [1921241]
TornStats.

TornTools + a few extensions I wrote myself, need to update them both on my desktop as well as my phone.

Then there are the tools I wrote for my faction for things like chain reports, etc.
marsey99 [1404499]
Let's be honest, it was only a matter of time. Tac made itself a prime target for anybody looking to exploit the API by being a list of wealthy players who are able to pay for the service.

Really do wonder where this falls in the rules. Is there anything about exploiting a 3rd party site to farm data the user has willingly given away?
Beerstein [1322136]
I don't think that's very effective unless you are actively monitoring the pulls.

What would work better as I mentioned is if a community member created a secondary key(s) from yours and fed through them as well as had permission selections, so basically a 3rd party filter where you can say "I don't want this being shared" or "I only want this being shared" not dissimilar to phone permissions for different access levels. I mean it'd be a great addition to torn itself, I just don't see the devs doing it.

On top of that, depending on who creates it, that person will still have full access, so there's always a level of trust somewhere.

Basically this suggestion through a 3rd party but also including permissions checkboxes for each, allowing/limiting what they have access to.
https://www.torn.com/forums.php#/p=threads&f=4&t=16123202

Obviously it'd be more ideal and secure if it were from Torn itself, but as Ched stated, they wont do it.

Mentions: [250R+] More API keys, increase account security

Pyrit [2111649]
While all of that is made simpler by the using the activity log, every example you listed is completely doable without it.

I think the complaints around the activity log in the api are a bit overstated. The abuse potential isn't all that much higher than before the update.
HD0G [2005521]
problem with bumping that suggestion R+ liking whatever.. is that ched has already responded that it would suck too much and bc they designed it from the ground up to be a single key system, my inference was they would need to build it from the ground up again - but i dunno. i didnt even know there was a control panel.. can you toggle specific data?

can you put in a single toggle for the log *without* some gigantic workload? maybe go find that part of the patch that published the log and unpublish it?
The_Skipper [1876106]
Can I just say here, anyone trusting third party tools or sites is kind of ridiculous. I use tornstats and IceBlueFire is a fine person and all. I talk to him in Discord and make suggestions to imrpove it. I think he means well. I think he is a nice person. I don't THINK he would abuse my keys, but if it were later found out that he was, would I be surprised? No. If you have played online games more than a day, you know people are scamming for access to your intel at all times.

I came to this game with a person in fed named Prehensile. I would have trusted Prehensile with just about anything, yet there he is in fed for running multiple accounts and cheating. Right?

Only reason I am even on tornstats is because it is required. If it were not, I would not even use that.

Those of you out there using optional stuff get what you deserve. Trusting ANYONE in a gaming community is foolish.

Two stories:

Story Number One: The unintentional harm.

In another game I was on a competitive team and one of my teamates had to be in an important meeting at the same time we had to do some strategic stuff. So that guy trusted one of our folks in charge to remote into his computer and control that account during the critical time (technically, that was cheating.... btw). The guy in leadership, who is genuinely a pretty good guy, thought it would be funny to leave the computer running on "meatspin" (for those of you who know what that is) and logged off. This would NORMALLY be kind of funny to many people, but unfortunately, the person's ex-wife showed up before he did to drop off their 5 year old daughter for her custody visit.... Not so funny...

Story Number Two: The intentional harm.

Same game, there was a popular war planning tool that tracked intel gathered, troop strength etc etc etc . Turns out the guys who developed it made sure that had full access to every report made to it. The tool was almost universally used, and most teams had no problems because they were so low value that the developers would never even bother with them, but the teams attempting to become competitive had a nasty surprise.


DO NOT TRUST PEOPLE.

NO

NOT EVEN THEN

ESPECIALLY NOT THEN

NO

JUST NO

NO

STOP IT

STOP TRUSTING PEOPLE!
Beerstein [1322136]
Well Ched won't code it, he should allow the user to do it with this specific case in mind. Alternatively, ched could do it themselves and instead of reworking the entire system, add another layer the same way modders were trying to do without touching any of the underlying system.

EIther way, there's no guarantee against abuse. TBH I don't even trust TornTools, I just use it because its a huge disadvantage for not using it.

So I use Tornstats because it's required by faction
Torntools because it has a lot of the functionality ched refuses to code.
And YATA, I think Tornstats uses it as well?

Do I trust them? No, I don't even know all the people in control of them let alone trust them. But I acknowledge that if they are using the information to damage me it's doing less damage than the gains from using them. So in this case it's I trust they're doing more good than bad for me personally.

Honestly, Id trust torntools more if it slipped in unintrusive ads, at least there'd be motive there for doing what they do. Without any clear benefits to them the only benefit is having your torn information. I realize it's resume material but you cant expect everything everyone codes to have pure motives.
marsey99 [1404499]
I'll take, things you say after sex, for £200 please :p


Edit

Unless it's 1st party and covered by the rules all that will happen is that then becomes the target for attack and the data is exploited from there. Any API proxy or tool would just be painting a target on its back.
Andyman [471591]
Bank investments are public now?

There's a foolproof way to tell if a player dropped a dirty bomb?

The auction house is do-able, albeit a ballache to gather the data for, as you noted.

PI rentals much more complicated since listings can (and are) regularly removed and relisted.
Pyrit [2111649]
I assumed you were talking about the activity log, since it was mentioned a couple of times in this thread.
You do of course need access to someone's api key for all of the things you listed.
My point simply was that whether a key has logs unlocked (which is triggered by a key reset) doesn't significantly increase the abuse potential if someone were to try to use it against you.

Mentions: Patch list #190 : 27/04/2021