Right now, the player id is something like https://www.torn.com/profiles.php?XID=XXXXXXX . This starts at 0000001 and the rest are player profiles. This makes scraping very easy and can be exploited, The docs state they will know if a non API request is sent, but that isn't true, there are many ways around it.
How can this be a problem?
scanning through all the public stats(health, level) of every player on torn, and mapping out weak targets(less health, high level.. etc) on mass scale, etc.
Previously there was a little bug where torn didn't strip off EXIF data from images, which can possibly have player's location, device name etc. This could've been scraped easily on a mass scale as well. But they fixed this recently. which is good.
What's the solution?
Encrypt/Hash the user id with a key. from the current 7 digits number to a hash. This can be a permanent solution to this possible exploit.
so, from
https://www.torn.com/profiles.php?XID=XXXXXXX to https://www.torn.com/profiles.php?XID=lpf/nDYR7Yt98PuzbZtAyQ==
AES encryption, with the key = torn.
User experience?
The user experience will be the same. You'll only see a different URL when you visit their profile, searching will be the same. but will be based on their name than their userid.
How can this be a problem?
scanning through all the public stats(health, level) of every player on torn, and mapping out weak targets(less health, high level.. etc) on mass scale, etc.
Previously there was a little bug where torn didn't strip off EXIF data from images, which can possibly have player's location, device name etc. This could've been scraped easily on a mass scale as well. But they fixed this recently. which is good.
What's the solution?
Encrypt/Hash the user id with a key. from the current 7 digits number to a hash. This can be a permanent solution to this possible exploit.
so, from
https://www.torn.com/profiles.php?XID=XXXXXXX to https://www.torn.com/profiles.php?XID=lpf/nDYR7Yt98PuzbZtAyQ==
AES encryption, with the key = torn.
User experience?
The user experience will be the same. You'll only see a different URL when you visit their profile, searching will be the same. but will be based on their name than their userid.