If one was to loose their api key to someone, and not know/not change their api key, what can someone do? Is there malicious stuff that people can do with the "general" one?
Note - I did not loose mine, just curious
Started by Alpha_male_69 [3351707] on in Questions & Answers.
Posts archived: 7 / 7 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Counted by TornLife from the archived posts.
If one was to loose their api key to someone, and not know/not change their api key, what can someone do? Is there malicious stuff that people can do with the "general" one?
Note - I did not loose mine, just curious
Torn's scripting rules prohibit users from using other people's API keys in a malicious manner or without explicit authorization. If someone were to ignore the rules though, the API is read-only so someone with your API key can't make any changes to your Torn account. The most they'd be able to do is stuff like figuring out how much money you have on hand and mugging you when you have a lot on hand. Luckily, API rules would result in the person being perma fedded for API abuse.
Thanks!
If you're ever concerned about the use of a certain key, you can always delete that key and generate a new one.
And on the same page you can also check how your key was used, what was accessed.
It's not just direct malicious intent (like mugging you) you should be worried about. They can use it for other purposes you did not agree with. That is feddable offense too for them.
IE you gave your former leaders api key to track your energy usage. Then they could use it for mug bot or any other bots. If they did, you can write the admin about that too. Why?
Because the ppl they mug can be the people you care about. And secondly you never agreed you api key is being used for other agenda. This is a breach of trust too.
Hence always check your api ping and delete any old ones
There is also a chance you can fall prey to a #MagnoMasterclass too 💰