DoctorN is an all-in-one browser extension for Torn. Using the official API, it not only replaces City Watch, but packs a ton of features for optimizing your day-to-day game experience.
Features
Player status at a glance
All kinds of customizable notifications
Travel Hub, keeping track of item stocks and prices in other countries
City Finds highlighter
Torn Stats integration: see your stat graphs on the gym, player comparisons on profiles and export your OC results directly from Torn
Quick crimes feature, speeding up your daily criminal needs
Jail enhancements: quick busts, max level and max time filters
Bounty enhancements: availability and level filters
Effective battle stats on the homepage: keeping an eye on those stat modifiers
Incredible chat highlighter
Hide users' threads and posts in the forums
Left-aligned Torn, giving you extra space for your chats
Hide useless sidebar icons
Hide level upgrade messages for level holding
Copy forum posts conveniently formatted for Discord
Powerful and smart address-bar shortcuts: type "doc" and press tab in the omnibox to access them (Chrome-only)
Easter Eggs alerts to help you during the competition
DoctorN is an all-in-one browser extension for Torn. Using the official API, it not only replaces City Watch, but packs a ton of features for optimizing your day-to-day game experience.
Features
User bars at a glance, directly on your browser
Player status on a dashboard, one click away
Customizable notifications
Travel Hub, keeping track of item stocks and prices in other countries
City Finds highlighter
Torn Stats integration: see your stat graphs on the gym, player comparisons on profiles, export your OC results and spies directly from Torn
Quick crimes
Quick items
Quick links
Jail enhancements: quick busts, quick bails and max score (time*level) filters
Bounty enhancements: availability and level filters
Effective battle stats on the homepage: keeping an eye on those stat modifiers
Incredible chat highlighter
Quickly autocomplete your friends' names in the chat by pressing tab
Hide users' threads and posts in the forums
Copy forum posts conveniently formatted for Discord
Left-aligned Torn, giving you extra space for your chats
Hide useless sidebar icons
Hide useless sidebar links
Alternatively, hide the sidebar's Areas section entirely, since you can add everything you need as Quick Links
Level holding mode: hide everything related to level upgrades
Powerful and smart address bar shortcuts: type "doc" and press tab in your browser's address bar to access them
Easter Eggs alerts to help you during the competition
DoctorN is an all-in-one browser extension for Torn. Using the official API, it not only replaces City Watch, but packs a ton of features for optimizing your day-to-day game experience.
Features
Player status at a glance
All kinds of customizable notifications
Travel Hub, keeping track of item stocks and prices in other countries
City Finds highlighter
Torn Stats integration: see your stat graphs on the gym, player comparisons on profiles and export your OC results directly from Torn
Quick crimes feature, speeding up your daily criminal needs
Jail enhancements: quick busts, max level and max time filters
Bounty enhancements: availability and level filters
Effective battle stats on the homepage: keeping an eye on those stat modifiers
Incredible chat highlighter
Hide users' threads and posts in the forums
Left-aligned Torn, giving you extra space for your chats
Hide useless sidebar icons
Hide level upgrade messages for level holding
Copy forum posts conveniently formatted for Discord
Powerful and smart address-bar shortcuts: type "doc" and press tab in the omnibox to access them (Chrome-only)
Easter Eggs alerts to help you during the competition
Installation
DoctorN was unfortunately discontinued. Due to the amount of bugs piling up, it has now been unpublished from extension stores.
You keep saying you'll communicate better with the community and then you go and remove a page that you know is being used that way because it was always there, without any notice? We all knew it was supposed to be temporary. We all knew most factions were using it. To rip it apart all of a sudden is just a dick move.
Some players (me included) are sad because I'm no longer maintaining DoctorN, but time and time again you've pushed me not to support this game anymore, idealistically. You keep taking positions that are extremely hard to live with.
As I was working on Doc, I've came across quite a few bugs and exploits over the years. I started reporting them with care and details, but each time I had less and less motivation to try being on the good side, because you almost seemed bothered to be receiving these. Meanwhile, people who actually intentionally use illegal scripts have at most gotten a slap on the hand.
I've reported 2 XSS exploits, multiple private data leaks, including posts from private forums such as the Committee and Staff Room and real-time sidebar notifications from anyone in Torn. Now, I didn't report them to get anything in return. However, after all that not to be taken seriously is heartbreaking. To express myself vulnerably in that conversation I linked on top and be mostly ignored feels extremely disrespectful.
Stewie has been basically running Bugs and Issues for years. How do you treat him? It annoyed me so much that I felt the need to create this suggestion, which gathered 100+ upvotes in a few hours. The community appreciates him enough. Yet you can't even post a "Sorry, you can't be staff but I really appreciate all the help and work you put into the game all these years."
I don't know why I keep thinking things will get better. You just double down on legit players in order to "catch" malicious ones: see the 403s. I can't use SFAKs anymore because it's attacking the server... But if someone were to DDoS with rotating IPs, that'd be okay, right? You keep prioritizing a war against bad people while smacking everyone else on the head.
Consider this my resignation from the Committee. Thanks.
Stewie is the most active and helpful person on Bugs and Issues. Not only that, he's also on top of Q&A.
Both users and staff themselves appreciate Stewie's help, since his timely, informational and accurate posts just speed up the process in general.
Giving him staff permissions over B&I would lessen the burden on the current staff and remove one further step, speeding up the process even more.
He's already applied to be a staff member about 2 years ago but never got a reply... I mean... If you ever received help from him, please R+ this and let's make this happen.
Not even gonna ask for your thoughts on this one. Let's just get it done.
If you think this is not how a staff suggestion should be brought up, think of it as a feedback request for the unanswered application from 2016. He deserves at least that after so much effort spent on helping B&I for years without recognition.
I'm not asking for a public answer -- you could talk to him directly and just tell us so here, Ched. Although a public thank you doesn't seem out of place.
ps. While Stewie didn't ask me to create this thread, I know he would like to be staff - he even posted so here.
Hey, folks. I'm looking for a faction for my wife and I to call home.
We're old schoolers but have been getting quite active lately, so a lively faction with a balanced training/warring schedule where we could train hard and commit to a healthy participation would be ideal.
If you've been here long enough (hi grandpa), it's possible you've seen the work I've put into creating tools for the game in the past. Lately, I've been itching to get back into that side of the hobby. While these days I need some work/life balance and can't promise the world, I'm interested in a faction that's looking to put the effort and vision in innovative tooling but needs help achieving all that.
Overall, we're looking for a chill place with folks that will have fun and laugh together but will focus on elevating the game when needed.
ps. I'm currently in SSL but honestly this move would be the perfect occasion to go free.
It'd be helpful if you had at least one interesting use-case to explain the need. "Because it's the modern way to do it" falls short of being convincing, imo, even though I'm a huge IPv6 proponent, currently on an IPv6-native residential connection.
You're clearly not saying because there were no bans, mugbots should have also not be banned.
Are you saying other scripts users should have been banned, otherwise the rules are not being followed?
Or because in some cases rules are not enforced it's fine to experiment with how much you can tread the line?
I bet my account there are still bot networks running that haven't been found and rules weren't enforced. Does that also make it a grey area?
I don't get it. The rules are still there covering the same cases, TT even removed the non-compliant features. Should all rules be enforced with the same exact sentencing regardless of severity? What's the grey area point that I'm missing?
The thing what matters is that the rules were written in a way that was up for interpretation and then when a ruling was made, the severity of the punishment along with the consistency is just a bit off.
Up for interpretation if they have a master class in technical pedanticism. No regular well-meaning person would've read the rules as they were written and figure "if I open enough windows, I don't even need an API since that's a normal way to play the game" was a reasonable interpretation—you'd have to be intentionally looking for loopholes and then argue since they were loopholes you can't be punished for it.
I cannot trust anyone with enough technical understanding who doesn't immediately think "yeah, they knew exactly what they were doing." If your defense is "no one straight up said it was illegal" you've already lost the argument. It's funny how somehow everyone involved tried to clear the scripts with staff. Every faction runs every script through staff, right? It's not like they could somehow sense these ones were particularly illegal to begin with and were hoping to get an OK because it wasn't technically explicitly written in the rules, surely...
ps. It was already written in the rules. "Pages you're currently viewing = monitors filled with tiny windows" is the kind of pushing you'd do when you're loophole hunting. There's only a technical difference between that and just blatantly opening extra background connections.
The real solution is making game mechanics resistant to malicious actors through feature design (ie. making it technically and actually impossible to do unwanted things), not adding delays to APIs and monitoring non-API usage. Otherwise, this is a never-ending cat-and-mouse game that is ultimately bound to fail assuming determined attackers. The longer the API delays and the better your monitoring practices, the bigger the incentive to work on stealth group attacks or just even better bots.
This isn't even that hard and has been demonstrated multiple times by legitimate tools that can only operate due to network effects, like battle stat predictors and overseas stock levels. The power of multiple agents is that any global scraping limitation becomes non-existent, APIs be damned.
I fear a lot of the "we don't need to implement this QoL improvement" ends up with that answer because "there are already scripts that do this, should the players want it."
In a way, people who refuse to use any scripts will definitely be at a disadvantage here, but that's due to Torn's conscious choice of delegating basic functionality to third parties even if they become de facto standards in the player base.
It's a stupid rule that's now being "enforced" site-wide because people intentionally misread the existing rules to excuse their obviously illegal mug bots.
Quotes on enforced since you could listen to chat in untraceable ways, so there's literally no way to know how many people use something like this.
I'm worried we're focusing too much on the feddings. Yeah, if you know enough about the API and WebSockets to either create or use these scripts, you 100% knew what you were doing, yadda, yadda, nothing new.
We're not seeing discussions about actual solutions to the underlying problem. As it stands, I'm just waiting for distributed mug bots to start causing issues. Get a group of players, have each monitor a single page a couple of hours a day, aggregate the findings and end up with the same results. "Technically not against the rules" if we follow the logic of anyone involved, once again.
This whole trainwreck is why I've always held the belief that Torn should focus on using game design to side-step technical limitations when it gets too tough to enforce rules.
There's no way around the cat-and-mouse game they have to play with adversarial scripts: the more "observability and smarts" they add to bot hunter, the weirder the side corners scripters will take to avoid detection.
As sad as it is to say, I think sometimes it's worth it to literally design the game with these "enemies" in mind. The bad apples really do ruin the fun for everybody, but interesting features (like real-time updates with websockets) sometimes are just incompatible with the rules/gameplay. You either break the real-time aspect beyond usefulness, or you end up (even with the most effective counter measures) with really overpowered scripts that gives a huge advantage while still looking "human."
Perhaps it's time to take the loss and make the game a little worse to deal with the issue through design, for instance by making market/bazaar-mugging an explicit feature. eg. make all sales protected by default but give players ways to intentionally plan and execute buy mugs or stalkings, in a way that wouldn't be useful to be alerted by a bot about a random sale.
I meant what's causing it for you, personally. Perhaps you can identify what kind of behavior ends up putting you back onto captcha-land in order to report these corner cases.
--
The thing with signed software (and scripts) is that it works to verify things you're running on your machine. It's not possible to just flip the roles and have Torn's servers trust the users' device. The required proofs are wildly different: even a locked down Torn app with pre-approved signed scripts would be inherently untrustworthy from Torn's POV, because they have no real control over users' machines, and even if they did, they couldn't tell the difference between a real or a fake one.
I get how frustrating getting stuck with the bot hunter may be, but I have no reason to believe it's a broken system. Tens of thousands of players use probably thousands of scripts daily, so we'd have a lot more people complaining if the system was too restrictive. IMO, your best bet is probably trying to identify what's causing it and reporting your findings so bot hunter can be dialed a little.
Seems contradictory to claim there'll be a huge queue while simultaneously not being enough of an upside and the only sensible way to participate is not to go for the summon.
If there was a huge benefit to being a summoner then yeah, I'd agree the limit seems harsh as a bunch of people would be stuck forever going after it... But there isn't, so I don't see that much of an issue. The queue itself seems in line with it being a sacrifice that no one should take.
If you think bragging rights are enough of a reward, queue length should self-balance with bragging rights, no?
As I'm interested in the community tools aspect of Torn, I took a quick look at xedx's scripts to find out if this was a one-off or if there are any other scripts that are on the gray side of things. It was by no means a thorough inspection, and I didn't run any code so for all I know these scripts don't even work. They also might be old, and I have no evidence they were being "intentionally" distributed right now.
Regardless, they're still publicly available on their Github. Doing a quick search through his library for a couple of iffy terms and lightly reading around them yielded the following potentially problematic scripts:
ArmorySearch: multiple automatic non-api requests (loads all pages) BigAls: automatic non-api request from different pages (queries the shoplifting crime every 30 seconds) BurglaryHelper: automatically clicks confirmation button EnableAttackBtn: multiple automatic non-api requests (getting user status) FastUserLists: multiple automatic non-api requests (loading all pages) FindUniques: multiple automatic non-api requests from different pages (queries crimes on every page load) JewelryStore: automatic non-api request from different pages (queries the shoplifting crime every 30 seconds) NeedleRoller: automatic non-api request (get inventory's temp items) QuickItemsHelper: multiple automatic non-api calls (get all inventory's categories) QuickRefill: non-api request from different pages (adds quick nerve refill from crime and jail pages)
Texas Holdem Score: auto click (also labeled "God Mode (prob illegal)") TideLevel: automatic non-api request from different pages (queries the tide every 15 seconds)
There are others with suspicious terms that could still be looked into, I just gave up. My personal thoughts:
I cannot be convinced they didn't know.
There's no way to know if this is LLM based for sure... It just doesn't look like it. If it was, they were still heavily instructed and edited so that all scripts follow the same patterns and style (something you wouldn't get out of the box).
Some of these could be migrated to use API methods and still work, so maybe they're just old.
Regardless, they appear to have good knowledge around the legality of automation in Torn. eg. their self-reported conversation with bogie:
If that's enough to justify a perm fed, I don't know, but it doesn't look good.
I thought the implication of the section "Things TornPal Does Not Do" was that it does, in fact, sell public data. It spells out it doesn't sell private data, meaning they do sell public data. Which, I mean, you're free to believe is fair use, but that's the matter is question: is it actually, or are users being deceived?
As much as I've always trusted Glasnost and 100% agree this situation (and especially the public witch hunt) is a little ridiculous, bro really didn't help himself with the rules question. :P
Glas, that you'd consider knowingly facilitating a mugbot if it wasn't against the rules and then come out saying "it's public data so anyone can do it and I'm technically protected by some clause or whatsoever on a ToS" is just playing dumb, no other way to frame it. No one that smart would ever think something worth paying for provides no advantage over the alternatives—and in this case, that advantage is hinging exactly on the keys willingly provided by your users (knowingly or not).
What I'm reading is that while you're banking billions on these tools, you're still considering fringier ways to make even more money off "public data" in the most imperceptible way possible in order to keep appearances with the community, because people would dislike the idea that it benefited dubious activities. That you're not doing it yet is laudable, but it seems the question has now shifted into if selling public data is legal to begin with.
Yes, technically anyone can do it, even mugbot creators themselves. Practically, they'd need to first create a massive user base to provide them with a bunch of API keys in order to be able to do the same. And that's what you would provide–it's not really the public data. This is not in any way blurry: if a service offers a rate-limited API and someone uses thousands of accounts to sell a rate-limit-free API on top of said API, it's blatantly clear they would be profiting off, essentially, stolen data. This might be technically similar but effectively completely different from using thousands of accounts to provide a proper service on top of API.
And while I'm not up-to-date on TornPal's sign up process, if it was not readily disclosed, yeah, as a TornPal user I'd be annoyed to find out you're fine skirting the trust you've gotten from providing awesome free and paid tools. Personally, I already knew you made money on the data and I'm fine with it—but I didn't know you were this brazen in regard to calling it "public data" and intentionally ignoring the differences in massive dataset access to absolve your mind.
This is not some shocking new concept. People are not comfortable being part of something they don't believe in, even if their help is fungible. The data would still be there if player A hadn't given out their key. And it'd still be there if 100% of TornPal users were different people altogether. But if player A would rather not use TornPal's tools in order not to help a specific private tool (be it a third-party mugbot or a personal tool only used by you), they'd be in their right to knowingly not participate. Making this clearer has always been where TornPal gets into drama.
I have tremendous respect for the work that you do, and I know how hard making tools for Torn is. But like I privately told you last time the pitchforks went your way, the way you respond makes it feel like deflection. No matter how loudly you scream it's public data, you know very well where TornPal's power comes from, and it's about the magnitude. You always make it clear, both in the forums and Discord, how proud you're of the size of your operation. You can't claim it's hard work, and you had to go through a lot, and you're a professional, and you even help Torn's dev themselves on performance, and this, and that, and all in between... to end with "but it's public data, anyone could do the same so TornPal has no liability in it, plus, it's already in the ToS you agreed with." Own up to it. TornPal is a massive operation, you're making a lot of money from it, you're looking into ways to expand and you think being technically covered in some ToS gives you permission to provide tangential services to third-parties with a clear conscience, because people "agreed" to it. You know, you're worried about being corporation-level legal, you're not trying to be a proactively good non-profit, and it's fine. Just don't pretend otherwise.
PS. I remember suggesting that you made it clearer how API keys were being used before you even released your market monitoring features because even back then I thought you were a little too chill on using the keys without disclosure (you had the service running before a proper ToS iirc). I didn't think much of it since you said you were changing it for release, but I really think you should be more careful going forward or we're gonna keep rewatching this cycle.