Bad idea: Add an API call to revoke gslt and disable all tokens linked
to that phone number for 24 hours- with no authentication besides
knowing the gslt. why?

1. protects against leaks of tokens (bots can scan github etc for them
and revoke)

2. makes token sharing sites much less viable- anybody who gets a
token from one of those can screw them over. ATM they amortize the
cost of a phone number across many users- thus needing to share tokens
or phone numbers. If anybody could pay 4 cents to shut down all the
servers using a shared GSLT- suddenly tokens cost way more because you
can't share phone numbers anymore.

On Mon, Nov 21, 2016 at 10:37 AM, dedimark <dedimark...@gmail.com> wrote:
> Hello CSGO team
>
> please make Scan time period to every 1-2 h or 1-2 scans every day
>
> because
> http://hlmod.ru/threads/avtomaticheskoe-obnovlenie-tokena-1-token-3-rub.36324/
> This tool grab token for 0.04686$ when token is banned
>
>
>
> --
> View this message in context: 
> http://csgo-servers.1073505.n5.nabble.com/Re-visiting-Banned-Plugins-GSLTs-and-Ban-Waves-tp11935p12188.html
> Sent from the CSGO_Servers mailing list archive at Nabble.com.
>
> _______________________________________________
> Csgo_servers mailing list
> Csgo_servers@list.valvesoftware.com
> https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers

_______________________________________________
Csgo_servers mailing list
Csgo_servers@list.valvesoftware.com
https://list.valvesoftware.com/cgi-bin/mailman/listinfo/csgo_servers

Reply via email to