Skip to content
TORNLIFE More

Vulnerability Disclosure: Discord Impersonation

Started by tiksan [2383326] on in General Discussion.

79 replies · 4.69k views · thread synced · 3 days ago · View on torn.com

Posts archived: 80 / 80 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Pops [1025410]
no the devs know how to copy and paste information on various cloudflare guides to implement this - in reality they have no clue what they are doing

source: someone who has also copy pasted some many a guide

i mean torn don't even implement DNSSEC for torn.com and thats some real low hanging fruit to implement, i did it in like 30 minutes
Kasto [2151656]
Ita funny cause they put mandatory 2fa to accounts to prevent stupid people getting phised and now they are like "It's skill difference, get gud".
Pops [1025410]
i dont mind that, but when people who are security minded, and want to use the best security available (security which is currently enabled for admins so they've already implemented it all) the response we get from bogie and others in nicer terms is to piss off

the fact that i can't use my yubikey to do fido2 challenges and protect my torn account, when torn staff have this functionality closest for themselves is bullshit. why is account security merely the purview of staff? we all should have this
Pops [1025410]
yes and you confirmed exactly what i just said - are you and ched not staff?

you have functionality that is very easy to implement, the yubikey SDK can have you up and running in less than 10 minutes and you already have this functionaltiy. why is the security of my own account not something you wish to enable for a mere 10 minutes of dev time?

at that point, much like DNSSEC it becomes some ideological barrier and not one based in reality.
bogie [148747] Admin Staff
Torn accounts don't have yubikey access, not even mine or Ched's, the things that do are different systems, as I have already said. The fact that you think implementing such authentication and login changes is just "10 minutes of dev time" shows how shockingly uninformed you are.

We don't need to invest significant planning or development time in adding such a system when there's no realistic need for it just to satiate a single player's paranoia, when in reality 2FA apps will be more than sufficient.
Pops [1025410]
ok i understand what you are saying now, to paraphrase it - 'we have yubikey implementation on something else we didn't create so we have no clue how to do it, we clicked a few buttons and its up and running because someone else did the work - we don't know how to natively implement this in something we created ourselves'

then yes that would take more than 10 minutes, but probably not less than a day - moving fido2 auth from one endpoint to another genuinely does take less than 10 minutes if you know what you are doing and have already implemented it.
Chedburn [1] Admin Developer
That's right. This is my understanding of the issue...

This is certainly a vulnerability in the sense that it's 99.99% safe instead of 100% safe. Once receiving the validation link during this once-in-a-lifetime process, the player would need to actually avoid clicking it (because clicking it immediately makes it invalid), and instead copy it, and send it to someone else. And then wait for that someone else to then use that link without clicking it themselves. And after all of this, the only advantage is that someone can pretend to be you on discord.

As you can imagine this has never happened before, imo it'd be easier just phishing their Torn account details...

Indeed, the implementation isn't quite correct, but in order to fix it we'd need to divert resources to hiring someone to resolve it since it's outside of our scope. If the community decides this is a valid concern and we're wrong here, it's trivial to get the process started, it'll just mean taking time away from some other things that I would personally deem a higher priority.


Luckily, users don’t need to do much to avoid this vulnerability. As far as I can tell, currently you can just avoid following links to https://torn.com/discord.php that don’t originate from Discord... especially links to the account linking process that don’t come from Torn’s George Discord bot.

This doesn't sound correct to me. If this happens the other way around and the exploiter generates the link from discord and sends it to the player, the player still has to view the page and actually click a button to confirm the action.
Offertory [2487783]
Don’t click links that you can’t confirm what they do, just like with any other phishing link

Offtopic to Op's post, but in this case, why does Torn allow URL shorteners in Trade Chat and on forums, if the general advice is to not click links that you can't confirm. If that is Torn's position on unconfirmed URLs, they should disallow offsite linking in general, no?
HK-47 [2241904]
Well its not a code bug its a social engineering tool. The user has to click or do some kind of interaction.
You can put more doors in the way but all it takes is the user to open the window.

Just my opinion and no I am not going into the technical brief to say I know more then everyone.
bogie [148747] Admin Staff
We've considered this in the past and so far have deemed the benefits players gain from using those for their own convenience outweighs any potential risk under our existing analysis of it within Torn. Similar to what Ched said about OP's report, if this is something that people REALLY want we can reconsider it - but I don't think people would really want this?

Banning these would need to be achieved through manual moderation, we could filter URL shorteners but there are so many it seems impractical. I imagine players would quickly get the message should we moderate for it, but presently it just also seems impractical with little actual benefit and minimal risk. I'm yet to come across a scenario where URL shorteners have actually posed a risk within Torn anyway, and when used maliciously we can moderate accordingly for that.

Ultimately if someone intends to use these maliciously then there's little we can do to stop that in the moment considering there are just so many out there, short of designing a system that prevents linking to any non Torn link, but that feels like burning the house down just to kill a single spider. Additionally, anything that a URL shortener can be used maliciously for there are countless other means people could achieve the same thing anyway.

Again, the same applies, you can simply choose not to click those.
Azathoth [1677351] Wiki Contributor
I'm unsure why you'd post this, and whilst I don't like derailing threads, I at least wanted to say that the developers and everyone involved in the creation and maintenance of Torn obviously know what they're doing - just look around.

I think your arguments are coming from a place of ignorance when it comes to running a platform such as this one. Whilst things might be "easy" to implement and "low hanging fruit", when you're paying for people's time and running a business it's never just a case of "yeah it's easy, let's throw it in", whenever you implement something new onto a platform you've given the team yet another thing to support in the future which diverts time and money away from other priorities. You can see that the dev team is managed well and that they know what they are doing because they say no - which a lot of dev teams fail to do.

I think other than defending the team behind Torn a part of me wanted to reply to you because I come across people like you all of the time in support tickets, forums, Reddit, etc. and because I'm at work and represent the company I can't just tell them to f**k off, but hey you're here now representing all of those people so - f**k off.

I want you to take this as a learning experience as it seems like you do something in the world of development. Implementing features just to keep the loud ones happy is never worth it, I've been at companies that have turned down literal millions because the paying company said they would only renew their contract if X feature/change was implemented just for them, and we chose to say no.

In typical fashion though I have no doubt you're going to reply saying "yeah but seriously its like 5 minutes and you dont even need to do support for the future because its a standard and even if it changes its just like copy paste it from clouflare i did it in like 3 seconds yesterday whilst in the bath" but I do hope that at least sometime in the future it clicks with you and you see where I was coming from.
Pops [1025410]
i understand what you are saying, but yes it really is that easy. you seem to be attempting to obfuscate easy tasks into some manner of 'well you dont run x so you cant know y' when those variables don't change.

i've seen this argument placed by ched too, where he makes this erroneous claim that the best people who are capable to run torn are the ones who have been there for x number of years, when in reality those aren't the best minds in the world. its why consultancy services exist and why various places outsource.

anybody can slap locks on a db to avoid a race condition, but when that db performance tanks to shit and you see massive torn slowdowns, the solution isn't slapping more locks on it. its re-engineering what you are doing that causes those race conditions and fixing it.

please do let me know what you think it is at scale that renders torn staff completely unable to implement DNSSEC though - i'm all ears. don't obfuscate it to 'hurr durr infra @@@@@@ scale' tell me in specifics what is going to go wrong or what can go wrong with adding some txt to a dns entry to verify you are who you say you are

and tell me why it needs a committee of people to do this, how it requires several PHD's and a industrial portfolio of 3+ decades of experience to click a few buttons and copy / paste some .txt

i'd harbour the guess that it in fact does not require these things but im willing to be corrected.
Td3h [1785428]
So a user has to click on the link AND click the button? I mean, would be nice to be fixed some day. But definitely doesnt sound super urgent. I assume there are logs torn side that could be used to identify the person generating the link? If so we can do some phishing training and catch potential offenders should anyone actually try to do it.
Azathoth [1677351] Wiki Contributor
@CHINGADERA - That's fine with me, I was saying it more for my own sake as someone who gets random users chiming in on the software I work on.

i've seen this argument placed by ched too, where he makes this erroneous claim that the best people who are capable to run torn are the ones who have been there for x number of years, when in reality those aren't the best minds in the world. its why consultancy services exist and why various places outsource.

I do agree in a general sense that just because someone has worked somewhere for a long time it doesn't correlate with them actually being any more useful or productive that a newbie/contractor. However, I don't know the engineers at Torn or their experience so it's impossible for any of us to say that Ched is making erroneous claims. There's no doubt in my mind that having someone who's been around the infrastructure for years and has seen the reasons behind why things are the way they are is going to be worth their weight in gold to any company, and I can only guess that Torn has one or a few of these people on the team.

please do let me know what you think it is at scale that renders torn staff completely unable to implement DNSSEC though - i'm all ears. don't obfuscate it to 'hurr durr infra @@@@@@ scale' tell me in specifics what is going to go wrong or what can go wrong with adding some txt to a dns entry to verify you are who you say you are

Truthfully, I cannot answer this, however it's not like Torn is standing out in not using DNSSEC as neither are Google, GitHub, Outlook so I don't know why this is a big issue to you.
CoolguyRuler [2183404]
Just don't accept messages from sources you don't trust?

If someone was to walk up to you on the street and hand you a device with a big red button and told you to press it, would you? That's about how a random link looks like to me.