Skip to content
TORNLIFE More

Warning: userscript wall-battlestats updated

Started by pobk [3171827] on in Tools & Userscripts.

15 replies · 458 views · thread synced · 4 days ago · View on torn.com
About this thread

Posts archived: 16 / 16 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
16
Discussion span
→
People posting
8
Likes on archived posts
68
Authority score
38 / 100
Historical score
22 / 100
Story score
42 / 100
Engagement score
71 / 100

Most-liked replies

pobk [3171827]

Hey all,

 

The userscript wall-battlestats has been updated, but the developers have broken the greasyfork rules and minified/obfuscated the original code. It's now called TORN War Helper, too.

 

The new code has a massive base64-encoded blob in the middle of it and I cannot be arsed to review it.

 

This script now breaks the GreasyFork site rules that state that the code must be readable by users.

 

In its current form, the code shouldn't be trusted and should not be used until it's updated and people can review it. (and the developers explain why there's a massive base64 encoded blob in the middle of the script?)

Omanpx [1906686]

Using an online decoder (don't want to decode it on my PC), looks like it's a spinner?

 

See below:

 

Edit: that doesn't change the fact the code is unreadable and still most likely breaks the rules of greasyfork btw. Just probably not a major security risk.

finally [2060206]

You can check older version on greasyfork, includes the sourcemap.

 

I am trying to add sourcemap back, but when I tried it first, it broke PDA.

pobk [3171827]

Frankly, the base64 blob wasn't the main concern. It was the obfuscation. The blob just made it sus af.

 

If it hadn't been obfuscated (and broke the GreasyFork rules) it wouldn't have pinged my radar.

 

You really shouldn't be obfuscating your user scripts. If you don't understand why, stop writing scripts.

seintz [2460991]

oh I understand why and that's the exact reason why I will continue to obfuscate them.

 

you seem to be the one that do not understand why scripts are obfuscated.

 

you know you can politely ask why it's obfuscated instead of going around throwing random and unfounded accusations?

 

 

pobk [3171827]

Oh, go on then. I'll bite... Why should scripts be obfuscated?

 

Erm, I have to ask, do you know what unfounded means? Or random for that matter...

 

Here's a random unfounded accusation: the moon is made of cheese and the Apollo astonauts were just screwing pumpkins in their capsule. For the entire trip.

seintz [2460991]

you said it yourself that you haven't bothered checking the script so how do you know it's malicious? do you have any proof? no so that's an unfounded accusation imo

 

main reason why I obfuscate my script is to make it harder for other to steal my work

 

second reason is to make them more lightweight, especially if you build them with a framework that adds its stuff (like webpack)

which means better performance given how bad is torn coded on how slow it is to compute it (in some browser more than other)

 

third, if you are so careful to check every script (as you should) it means you have some understanding and even if minified you can understand 90% of what it does, you can clearly see if there's something shady or not since all requests to storage API are untouched (or any call to any of the DOM API)

 

the fact that greasyfork doesn't want minified code it's just their policy, just like chrome is closing all manifest V2 extensions because they decided that way

 

I'm not saying it doesn't make it suspicious but if you asked the owner why he minified it (like I did) he would have told you his reasons (he also told you  he is working on a solution but you decided to ignore him)

pobk [3171827]

The script used to be readable. People could review it and judge whether to trust it. The latest update replaced that with deliberate obfuscation. That is not cosmetic, it breaks the trust chain.

 

You claimed obfuscation is needed to stop copying, but the code was open for months. Either copying was never a concern, or you chose to hide it only after people started trusting it. Either way, that weakens your argument.

 

Security is not about proving malice. When previously transparent code becomes opaque, you treat it as untrusted. Not malicious, just untrusted. The burden is not on users to prove it is safe. It is on you to make it auditable.

 

Userscripts run with access to the DOM, API tokens, storage, cookies, and external calls. The only safety control we have is the ability to read the code. Remove that, and the trust is gone.

 

Minified code can still be reviewed. Obfuscated code is designed to block review. When you remove auditability, you lose the right to complain that people do not trust it.

 

About sourcemaps, they do not restore trust. They are optional, can be changed at any time, and are not bound to the deployed script. You are asking us to trust that the sourcemap is genuine, current, and complete. That takes us right back to blind trust.

 

If you choose to keep your code closed or obfuscated, that is your call. But that also means it sits outside the trust model of user scripts. People will avoid installing it. That is not hostility. That is caution.

tiksan [2383326]

To be fair, it's licensed under GPLv3. You can just request the original, human-readable source code and build scripts from whoever owns.

pobk [3171827]

Given the response "because I don't want people to copy my work", I doubt you'll get that.

 

Not to mention, what you might get has features removed.

Omanpx [1906686]

Why would you need to make your code "harder to steal" for a free script, posted publicly on the forums? Sure, might make sense for a paid-for script that you plan on reselling, but makes no sense for something public that you expect people to install en-masse.

Tux [2571279]

It seems with the hosting change they've deleted the code (for all versions?) from Greasy Fork so I was only able to find version 6.9.3 of the old script that I've re-hosted here: https://github.com/n8rade/torn-scripts/blob/main/wall-battlestats.user.js

 

I made no changes to this version and don't intend to make any changes to it either. I had to make minor changes to make it so that it doesn't automatically update, but I don't intend to maintain this. This should be allowed under the license they included with the script, GNU GPLv3.

 

If anyone knows how to get all of the older versions that were contained within Greasy Fork I would personally appreciate being educated!