STEAM GROUP
TF2 Outpost by Fanbyte
Membership by invitation only
STEAM GROUP
TF2 Outpost by Fanbyte
4,423
IN-GAME
31,500
ONLINE
Founded
7 August, 2011
Language
English
Showing 1-7 of 7 entries
9
Suggestion & Questions : Scambots on Outpost
Well I dont know much about how steam operate their system , neither how the Outpost uses the steam API ,sure I'm implyng lot of things and there are a Lot of other things I don't know about but it seems to me that the Issue of Scambots should be pointed out and handled.

As for why a bot can add you even after you haven't made a trade since 1 year I might just suggest this because lot of different things , either because you're from Outpost staff (which makes you a priority target) ,or a friend of yours has been phished by a bot and acquired you from his friendsllist , or because you've got added because you're an user from outpost, and I pass many other examples.
(I understand the point that outpost isn't the main place where phishers get their accounts from, but by making it harder for them to use outpost as such , it would imo be an improvement overall towards making outpost safer( less scamadds in general because of a trade for someone who's using outpost))

Altough I know there have surely been lots of security features added to outpost (as the one you've mentionned for queryng too much steam ID's at a time) :
-Have there been some real securing improvement towards scambots from steam or Outpost in the past years?
(not like : yes, but all what those features did was just accomplish to annoy users even more)

Also what would you suggest then to improve Outpost(or steam) overall against Scambots and which other features should be implemented for being able to accomplish that?

:steamwings:Tonculte:steamwings:
For the first one you presume only logged in users are banned with their IP address as the account aswell, but take the case that someone without an account (the script used for the bots) just needs to trackdown the offers owner steamaccount and add him directly on steam by just checking every trade and the Trader and adding them into a Database which will be used as a source for adding the user saved in it.Basically it saves the SteamID first and then the Id is reinjected for adding the user without using the browser or the Add function of the Add Button.

For the second I cant really express myself on this , I just find it ridiculous not securing the way the services are used in general.

For the third one I would reiter my proposition by letting the choice to the trader to show the trades to people below lvl10 (or any lvl given) and anon users.IMO Yes it would be discriminatory , but if a Trader has the choice to chose whom he wishes to trade with and filter people he doesnt wants to trade with it would be a proper feature and actually be the choice of the trader and not the website itself.I can relate that it would force lot of people to lvl up their accounts , but so do the people who own many fake accounts that have a lvl ranged between
0-7.It would be for mysellf more a security feature .

For the Fourth one I just think these security measures ain't efficient enough to filter out those people who manage to scam people by using simple scripts to acquire Data on their Target/s.
Because as I see it the default user has to use the webbrowser and use function/button on the website. The "hacker" more like "skiddy" just takes a path without involving using the browser and is "scanning" the website on the available elements which includes the link of the Traders Steam ID.The path for acquiring the user /user/xxxx/resolve/community seems more that the script is requesting the Link which returns the steam ID link which doesnt seems to have any checks inbetween for veryfing the users authenticity/acces method and gives a path for saving in mass users trading/registered on the website in a Database.
I might be ignorant on some points maybe but this seems the most logical case imo.

Fifth one If it ruins the Sites's SEO by just showing public offers i might resuggest by giving the option to privatise the profiles on the site itself which means they will show a custom name on the site for the steam user and adding or see the steamprofile is hidden. Altough it will still be possible to post messages in trades or the profile itself. This option could aplly with Public,registered users only , Friends only , Private. [A bit like FB]

Sixth one It might be true the phisher are actively banned , but as soon as a phisher account is banned , a new one is created by the owner of the old one. It's for that matter if the website or Information is requested on the site that it cannot be requested by software or programms not conventionnaly used for this (which excludes browsers unconventionnaly and conventionnaly used and includes unwanted scripts/programms downloading entire webpages for the purpose of scanning & reuse them).

So globally I'd suggest to giving the option to limit how much you want to share on the website with other users but still giving the ease to make trades as they are now.

If I said some nonesense just enlighten me please ;)
:steamwings:Tonculte:steamwings:


2
HELP! pls i got hacked
9
Suggestion & Questions : Scambots on Outpost
487
New Layout Discussion
Showing 1-7 of 7 entries