Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 18 August 2013

Watch out with API keys!

Posted on 22:00 by Unknown
Why do I get so many blog hits from a Reddit page? Because it has this very interesting leak:
This screenshot was taken by someone with higher access rights from the TEST API system, which pulls submitted API keys from the CCP server. It stores the last info it could pull down before I quit TEST. I posted summary of my accounts several times and this leak contains the 3 accounts that had TEST API keys submitted:
  • Gevlon Goblin is my highsec main, I never kept that secret. He only undocks for baiting gankers. He was training Ice Harvesting at the time of the API pull, because I'm going to mine White Glaze in the upcoming weeks. You'll hear about my mining stories tomorrow.
  • Helga Kolan is my Hek trader and I'm pretty sad that her name got out. There is a lvl2 research agent in Hek who gives courier missions that can be completed in a shuttle for corp standings. One mission a day, I've been doing them every time I log in. I guess I won't get to 9.8 Boundless Creation standings, because my fans will surely pop that little shuttle.
  • Cindy Sasen is my well-known scout/cyno pilot who started my nullsec career as an AFK cloaker in -A- space
  • Avat Goblin is my dreadnought pilot, who was in TEST (somehow the API updated after I quit).
  • Botmuncher Goblin was started when I was ganking in highsec, to have a secondary ganker so I don't have to wait out GCC. His training has stopped. Now I have a new plan for him so activated dual character training. Hopefully you'll hear from his exploits.
  • Titania Goblin is my logi pilot who was flying with TEST the most and now gets her carriers.
  • Okami Kusoni is just sitting in a trade hub to PLEX this nullsec account.
  • Botslayer Goblin is the famous ganker who killed 52B worth of miners in a month.
Well, nothing really interesting is here, why the post? The interesting thing is the lack of leak. Except for Helga's name, you couldn't learn anything from this screenshot you did not know already, because I wasn't stupid with APIs. TEST demands a very limited API key: Account Status, Character Info, Skill Queue, Skill in Training, Character Sheet, Character Info, Standings, Kill Log. These are info that you'd share with anyone. Which is the most important rule in API key management: Only give out API key about info that you wouldn't mind sharing with anyone. Consider your API-key covered info public information. Be careful, a full API key gives out practically everything about your account, including mails, locations, assets, wallet journal, everything. If there is a piece of information you wouldn't share with anyone, don't share it with anyone! If the guy asking for your API says "Only I will see it and very trustable guys" and you believe him, well, I know of a very reliable ISK doubling service in Jita you might be interested in.

Of course it doesn't mean you shouldn't give your API key, even your full API key to anyone. Since you need two accounts to play EVE unless you are very casual, have a separate moneymaking account(s) and make sure that your personal pilots are there. Have a different public nullsec/PvP account(s). Your nullsec pilots cannot have secrets anyway, I can tell without keys that your combat pilot flies alliance doctrine ships, trains for them, have doctrine ships and jump clones in staging and deployment systems outlined in your SotA. The only interesting thing they can get from even a full API key is the name of the moneymaking pilot who sent ISK or assets to the combat pilot. The solution is having a zero-skill alt in the private account(s), only this pilot should receive or send anything to your nullsec pilot(s), so the only thing they learn is the name of a zero-skill pilot. If they ask for API key of that pilot, give them a finger. Never, ever give out the API key of your personal account(s) to anyone! Being kicked from your alliance is much better than losing all your assets.

If they know the locations and assets of your moneymaking pilots, they can gank it. If they can, they will. Just think of the PL supercapital pilots who were ganked by their own FC. I'm not saying you shouldn't trust your alliance mates, just that you shouldn't trust them with everything you have. You nullsec assets should be enough for them. Combat ships are considered lost on fitting anyway. But if you keep your moneymaking assets safe, you can always rebuild after a loss.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Random | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Suffer mortals, as your pathetic password betrays you!
    One of the things we often don't put much thought into is password selection. Usually it is a loved-one's name or an easily remembe...
  • (I'm not) defining lowsec
    This is a rather short post, will be one more today, about my very first PvP action. Sugar reminded me of a problem that I read about a l...
  • The big EVE trick
    What is an easy game: where everyone can achieve what he wants easily. What is a hard game: where you can only advance by becoming better an...
  • You must station trade what you haul
    Well, actually you don't if you are fine with hauling for buy orders. This case you lose serious profit. If you are the station trader o...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Thinking about highsec POCOs
    In the next EVE patch, Rubicon, highsec customs offices will be capturable by players (actually you destroy and build your own, but it's...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • October ganking report
    October was a great month for my corporation , We Gank Because We Care. You can see the results on the killboard but since October was 31 d...
  • The proper profit metric
    Live moron of the weekend post . Did they spent the last month under a rock? People having trouble making ISK with trading. Some rather go m...
  • ur a kid!
    The title is a troll comment I get often. It doesn't make much sense. It's clearly not an argument. While we know that socials don...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ▼  2013 (242)
    • ►  November (15)
    • ►  October (25)
    • ►  September (24)
    • ▼  August (21)
      • Corporations/guilds only have their restrictions t...
      • Business Thursday: Character sell
      • T(h)ank for your pod!
      • Catalyst ganking guide
      • We Gank Because We Care
      • You can't really grief in EVE
      • Business Thursday: Blitzing mining missions
      • Sexist, racist and otherwise "mean" jokes are not ...
      • The fall of Miniluv
      • Watch out with API keys!
      • The donation board is recognition
      • Attention, pets!
      • Caldari ice mining recap
      • Thousands of fleetbears, please ignore
      • The end of TEST alliance
      • Quotes from TEST forums
      • Business Thursday: Interdict your mum!
      • Need to beat the NPC corp
      • Why can't TEST live without Sov?
      • How to make 4000+ fights smooth without supercompu...
      • Blogging is for a long term
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ►  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ►  August (26)
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ►  2011 (4)
    • ►  September (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (1)
  • ►  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile