The bazaar currently show the previous prices that things were added for, there doesn't seem to be an easy way to reuse that price though - you need to retype it.
Adding a little dollar icon like on some of the other price boxes might work, with two/four shortcut values: - Previous price (the one that was shown before you started typing) - Market value - Shop sell / Shop buy values (unlikely to be worth adding)
The quantity field can do with a similar shortcut. The weapons have the check-boxes, which is quite nice, iother itms can do with a button that allows you to go to these settings with a single click: - All (add everything that you have of an item) - One - All but one (If cycling)
(Alternatively, it can be a button cycling between them, but smaller direct buttons would be nice on the PC) (A cycling button can also have additional options, like half of the number of items, etc)
If both of these are implemented it should allow for filling in the fields to sell an item with two - four clicks, instead of two click and manual typing.
As an alternative to the suggestion here, I suggest that when you travel, you get a visa when you arrive at your destination and you get deported once you overstay it. (Say 3 days?) (Deportation should likely also prevent you to travel to the same destination again for a while...)
An option to extend the visa a limited number of times can help for active players that have a reason to spend more time abroad.
This should prevent the use of travel for indefinite protection from live in Torn....
It might also add some additional dynamics to play, if some (preferably new) destinations later get other visa requirements, such as education, a fee, etc... There is also potential to enhance visas via other game mechanics, like company/stock specials, items, etc...
(Initially visas granted on arrival seem to make sense, for some destinations it might be interesting to requiring that a visa is obtained before travel)
Edit: Went through the linked thread and noticed that metalkarmak [1901801] and 0ffline [1822187] suggested something similar...
Also, figuring out the optimal durations might be interesting, since it seems that travel might be useful for protection for a while if you are taking a temporary break from the game... (Durations similar to real-life tourist visas of 14-90 days unless extended might even make sense...)
Mounting /tmp noexec is a good idea - it breaks many off the shelf exploits. (It is not hard to bypass by an active attacker, but in many cases you are dealing with scripts
My other suggestions is that if a password (e.g. for the database) is going in a config file, it need to not be memorable, so use something like "pwgen -s 32 1" to generate one that is impossible to guess.
I'm currently posting this with TornTools enabled. (but I'm getting the same on PDA on my phone as well)
When joining races with an entry fee, I get a 504. This has occasionally potentially cost me some potential wins (accidentally joined a mudpit race with the wrong car and it started before I could change it)
Races without entry fees work fine.
The race joining works, but it is annoying, since the UI hangs until it gives the 504.
The race that I'm in currently had this issue, but all race joins with entry fees for the last few months had the issue.
Any chance of releasing the optimized version as an update? (I have been running it since with no updates and much better performance, both under tampermonkey and torn pda) (the domain permission wildcard was the issue that kept it from working on tampermonkey)
(i can release it as well, but I don't have the backend, so it will stay dependent on that)
The Google drive link is not much fun to install on tornpda, but it is doable.
(This one should not have the skipped submission issue on solving)
Summary of changes
IndexedDB connection reuse The original opened IndexedDB repeatedly for every read/write. v3 caches the opened DB connection so frequent dictionary, cache, and outbox operations are cheaper.
Fast exact-word lookups The original used array .includes() to check whether a completed word was already in the dictionary. v3 adds Set mirrors of the dictionary buckets, so exact checks use .has() while still keeping arrays for ordered suggestion scanning.
Avoid repeated completed-word processing The original rechecked completed rows on every scan. v3 remembers the last completed word seen for each row key, so the same solved word is not repeatedly checked against the dictionary or outbox every 800 ms.
Only refresh suggestions when the pattern changes The original scheduled suggestion recalculation every scan for every row with known characters. v3 compares the previous pattern with the current pattern and only recalculates suggestions when the visible pattern actually changes.
Safer panel cleanup for Torn’s virtual list Torn can reuse row DOM nodes. v3 is more careful when removing suggestion panels so an old delayed cleanup does not accidentally remove a panel belonging to a newly reused row.
Cleanup for all-unknown rows If a reused row goes back to all unknown characters, v3 removes any stale suggestion panel instead of leaving old suggestions attached to the row.
One-time refresh after dictionary load Because suggestions no longer refresh every scan, v3 explicitly refreshes existing panels once the dictionary finishes loading. This keeps the pattern-change optimisation while ensuring panels created during loading update when the dictionary becomes ready.
Suggestion matching made simpler v3 uses a direct wildcard matcher where * means “any character,” instead of relying on regex construction. This keeps matching behavior straightforward and avoids unnecessary regex work.
What stayed the same
The script still uses the same Torn page match, same dictionary sources, same Cloudflare submit/sync flow, same settings keys, same UI options, same word length range, same exclusion tracking, and the same 800 ms scan interval.
This script works well, but it does slow down the browser to a crawl when there are lots of completed or semi-completed passwords (I tend to brute-force until overheating and then collect most of the rewards when my Herbal Releaf stock perk comes up.
Some things that might help: Not suggesting until there are open boxes (that can probably be an option, since those suggestions that disappear if some of the random letters are filled in, can sometimes be useful). Saving the cracked passwords somewhere in the browser and whether they were submitted (to quickly get them loaded without a request). Possibly running the fetches less parallel (I did not look at the logic)
Edit: Some ChatGPT (Pro) suggestions: (there are much longer ones as well, but this summary seems interesting) (this is mainly for my case where there are often 50 + cracked / partially cracked entries:
If you want the smallest set of changes with the biggest payoff, do these first:
Reuse one Worker instead of creating one Worker per suggestion.
Skip schedulePanelUpdate() when panel.dataset.pattern === pat.
Cache IndexedDB connection.
Convert dictionary membership checks from arrays to Sets.
Track completed rows so you do not re-check completed words every scan.
The most important one is probably this tiny change:
Right now, even unchanged rows can keep triggering suggestion recalculation. With many cracked entries visible, that becomes very noticeable.
(That is around line 954. With my testing, that makes loading on a page with 26 cracked entries almost instant) (I can send the complete set of suggestions if you are interested) (My own Javascript is extremely basic)
Edit2: That mod does not help lots of partially solved ones and it seems to mess with the submission of completed words.
Another note: An option to refresh all data on the https://torn.report/data page would be useful. (mainly to allow stuff to update before figuring out which reports I want to look at)
{"6550":{"log":6550,"title":"Company special gain loan time","timestamp":1774237523,"category":"Company","data":{"special_used":80,"job_points_used":25,"job_points":343},"params":{"color":"green"}}}
I'm currently posting this with TornTools enabled. (but I'm getting the same on PDA on my phone as well)
When joining races with an entry fee, I get a 504. This has occasionally potentially cost me some potential wins (accidentally joined a mudpit race with the wrong car and it started before I could change it)
Races without entry fees work fine.
The race joining works, but it is annoying, since the UI hangs until it gives the 504.
The race that I'm in currently had this issue, but all race joins with entry fees for the last few months had the issue.
It seems that the attackers got in through postgresql. (by guessing a password)
SSH is fine if password auth is disabled or you have good passwords (but you mostly don't know if your users actually have good passwords, so you should require key auth)
OpenSSH has a great record in terms of pre-auth security. OpenBSD that develops it and enables it by default had two remotely exploitable security holes in their entire history (since 1995), the last one was in 2007. (That one was not in OpenSSH, the first one from 2002 was though)
Linux distributions sometimes mess it up though with their patches. (The LZMA backdoor that got pulled in because distros patched in systemd notification, Debian's insecure keys, etc)
If you expose it, you do want ssh-gaurd or fail2ban to block attackers quickly and harden it as much as possible to limit the risk, but an OpenSSH without password authentication is unlikely to be exploited. (Other SSH implementations are often a lot worse (e.g. dropbear) and the distros messing it up can sometimes bite)
The thing that TornW3b did really well in this case is to request API keys with minimal access (the custom ones had LESS access than public IIRC). That significantly reduced the impact of the issue on users.
Mounting /tmp noexec is a good idea - it breaks many off the shelf exploits. (It is not hard to bypass by an active attacker, but in many cases you are dealing with scripts
My other suggestions is that if a password (e.g. for the database) is going in a config file, it need to not be memorable, so use something like "pwgen -s 32 1" to generate one that is impossible to guess.
On https://wiki.torn.com/wiki/Organized_Crime_2.0#Elaborate_Campaigns "Clinical Precision" and "Stacking the Deck" are listed as Elaborate, while we get them without having elaborate scenarios unlocked. ("Stacking the Deck" and other multi-step scenarios might make sense to list separately, since the won't spawn from any of the buttons)