Skip to content
TORNLIFE More

TornPal - Data Aggregation and Tools

Started by Glasnost [1844049] on in Tools & Userscripts.

154 replies · 5.76k views · thread synced · 8 days ago · View on torn.com

Posts archived: 155 / 155 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Anton [422812]

Yes, but I don't know who you are until today and the FF script wasn't made by you? So why are you allowed to take my api from a different script to use for this market shit without my permission? lol

 

I've just read the shit on your website, but I hadn't visited it until today so why did you have my api 2 days ago from a different source? 

Glasnost [1844049]

You are correct, I didn't make the FFScouter script. I make the backend and data services. So you are mad at something I have no involvement with, and that you didn't trust some other person correctly or read their documentation, if I am following this correctly? Then also get mad at me for not reading my terms of service in offering the service?

Anton [422812]

I'm mad you somehow have my limited access key doing shit for your website without my knowledge until someone asked if I  had used your site this afternoon, so I checked it out. I'm assuming I'm not the only one unknowingly allowing your site to scan everyone's bazaars and item market info for you to sell that data to premium members and some crappy free services via our api that we hadn't asked for? xD

Anton [422812]

Mugging was my business before markets 2.0, no wonder I can't find shit if people are using my api to snipe my deals from me lol

Anton [422812]

Plus the last 2 days I've been dealing with bot catcher shit, no wonder why if you're spamming my api on top of my own calls for other scritps!

Glasnost [1844049]

Again, let me reiterate. I cannot grab your key magically. You must provide it to a script or anything else you are using, or log into the website, for me to be able to know it. I do not make browser scripts.

 

So there are 3 possibilities:

  1. You didn't read their documentation on how the key was used and consequently it would be passed to my service (and therefore how I would use it, which I am clear about in a policy)
  2. Somebody has stolen your key and submitted it (in which case, make a report and I can provide information about it to staff since requests are logged)
  3. You logged into the website (which I can see you did log in for the first time today via the web interface).

 

In all 3 scenarios, you are talking to the wrong person. To stop key usage, you can disable or delete it.

 

The data collected is public information, it load balances between keys, and on average uses 0.67 requests per key per minute (so less than 1%). Feel free to delete it if not already done so. There is nothing nefarious about this, your private data remains private, and it is done in the knowledge of the admin and development teams too since I have repeatedly discussed it with them and sought approval.

 

Many of the keys were submitted during Halloween for this purpose. Many more signed up for the website, again with the policy linked in the sign-up box. I have not hidden this fact, and have openly discussed it in several Discords, forums and other places. How the use of a free API service, which uses less than 1% of an allowance, which is purely voluntary and can be disabled at any time, is remotely upsetting I am unsure. Of course I make a profit from the premium services, but most of what I do is public too. And those premium services? You can achieve the same thing using my also publicly available API.

 

As for the insults, neither necessary or appropriate.

Glasnost [1844049]

The bot, used in premium services, does not alert to item market deals. It is included on the website, but if you are interested in sniping item market deals, this is much slower than the item market itself and provides no advantage. Item market data is used to offer a comparison to current price trends, and will also later be offered publicly as an API service to help people identify price trends and history.

Anton [422812]

It may have interesting or cool feature, it's nothing really new or special at the moment.

 

My issue is that you had my limited api from another source, that I didn't authorise which the site says it's had for the last 2 days at least.

Glasnost [1844049]

From another source such as?

 

If you wish, you can make a report and I can provide IP addresses to the staff team on who submitted your key and I can let them evaluate the origin of it. However, my suspicion is as above, you've provided it somewhere and you haven't read something, which is very different from your implication of misusing it.

Anton [422812]

As in, I did not input any of my API into your website TornPal, until today when someone asked if I used something called TornPal, so I checked it out, saw it didn't have any crazy features and went to move on, until I then went to remove my API and saw my limited API was already in the system!

 

Active Key

Limited Key

jtxP************

Added on 2025-01-17 12:50:52

 

 

Active Key

Full Key

WRoG************

Added on 2025-01-19 16:53:40"

Anton [422812]

I downloaded the FF script from rDacted, and have used that script. That is where my API came from. That is where it would have come from. You are not rDacted. And the FF script never said anything about allowing you or TornPal access to use it for other usage. Therefore, for the website to have it, you have used it without my authorisation? 

Viciously_Grim [2752611]

The FF script has been transferred to Glasnost which is publicly announced in the FF script thread. The script had an update saying he's logging off and this info was also publicly provided in the Fedded Archives thread (I know this because I posted Glasnost's quote about rDacted's departure from a different thread). The handover also took some time and wasn't instant, and they've both been transparent about this throughout the transferrence process.

 

FF scouter announcement by Glasnost:

 

https://www.torn.com/forums.php#/p=threads&f=67&t=16422178&b=0&a=0&start=140&to=25564697

 

Torn pal thread first post with handover announcement:

 

https://www.torn.com/forums.php#/p=threads&f=67&t=16441589&b=0&a=0

Mentions: [Script] FF Scouter - fight difficulty indicator · TornPal - Data Aggregation and Tools

Allenone [2033011]

So the expectation here is to read forums constantly to know that one indirectly consents to having their API key used for other reasons than they originally agreed to?

They definitely could've handled it better by pushing an update to FF scouter that did a popup giving the option to remove their data and informing them of the new terms, forcing an option to be selected for functionality to continue.


by the logic of this, myself or any other script maker could go edit their post saying you now consent to x and it'd be fine? imagine if BSP did this. hundreds if not thousands of users and i guarantee 99% of them haven't revisited the thread after installing it and paying.

 

This isn't very ethical and borderline against scripting rules.

Glasnost [1844049]

If I may, you miss my point here. I didn't make the script, never have. I make an API endpoint, I publish how I use the data and when you delete/remove your API key, the data gets overwritten as it is updated with public information instead of using a private key.

 

I agree it may have been handled better in retrospect and I did request a banner was shown to advertise this, but as I use another implementation I am unsure of the process and whether this was automatic, but it was in the top of the script I am lead to understand which is visible when updating and installing (would be happy if anyone can correct/confirm this?)

Allenone [2033011]

You should've discarded all API keys from FF scouter and let people see their script is broken and re-enter their API key.

 

just because you inherit/take over a script doesn't mean the users agree to the way you're going to use their information.

fuck [2669774]
  1. Not everyone is terminally online like you and me
  2. Announcing something doesn't mean you automatically get the consent from users to be able to use their data
Lith [2137694]

I gotta say, the FF Scouter implementation in TornTools does NOT make clear your API would or could be used for any other purpose.

 

Nobody using that script, gave you their API key.  It really doesn't matter to a user if the backend of that script uses your services or not.  Unless someone hands you their key, you shouldn't be using it.  Full stop.

 

Hell, i've been given many keys for the discord bot I developed for my former faction.  When I decommissioned that bot, I deleted every single key.  Because they were given to me, for use of that bot for that faction.  I still work on it, but its no longer associated with the purpose people gave me the keys for originally.

 

Just because you've posted something in a forum about this, doesn't make this right.  I gotta agree, your use of keys like this I find highly unethical.

Glasnost [1844049]

Apologies if it wasn't clear, but this is what happened as far as I know. I can't disregard the keys from FFScouter, because it is an API and I didn't carry over the keys from FFScouter. The script was updated, by somebody else, to utilise my API endpoint, and this was announced as put previously. If I don't have your API key and I announce it publicly, I am unsure how I am expected to go around every individual manually and check this.