| Pages: [1] 2 3 4 :: one page |
| Author |
Thread Statistics | Show CCP posts - 1 post(s) |

cosmoray
Cosmoray Holdings Corp
|
Posted - 2011.02.24 03:30:00 -
[1]
After reading several reviews about collateral and security, I realise I haven't been audited since 2008 for my first business. I plan to rectify this.
When I return from travelling (I may be back Friday) I will release my API details on MD, allowing EVERYONE to conduct there own audit of me.
You get to see my highs and lows, my collateral holding, my loans, my trades, ........ EVERYTHING
Over the weekend, I will announce time, I will release the LIMITED API code. I will also make the FULL API code available to well known auditors if they want it.
I will post in this thread the time that I will release the API codes. Then you get to have some fun.
TRUE TRANSPARENCY!!!
|

Misty McGinnity
|
Posted - 2011.02.24 04:05:00 -
[2]
>implying you have only 1 account.
|

Brock Nelson
Caldari T2 Technologies Unlimited SRS.
|
Posted - 2011.02.24 05:10:00 -
[3]
Honestly...you shot down the purpose of an audit as soon as you made this thread. No audit since 2008 is enough time for you to hide whatever it is that needs hiding.
At this point, it only serves to verify a few facts about the business you run.
|

Ray McCormack
Nordar Innovations.
|
Posted - 2011.02.24 05:15:00 -
[4]
Hardly everything if you're only releasing your limited code to the public and the full code only to that seething mass of ego that MD 'auditors' have become.
Also, you'll be amazed at how little interest there will be even in releasing your full code. With AATP's API being public, the dozens of people constantly demanding public oversight very vocally but never with any real follow up action failed to notice the BPOs being unlocked and contracted to another corp several weeks ago.
So all well and good offering this, but with the few drama mouths on this forum being all bark but no bite it's yet another weapon in the arsenal of the smoke and mirrors tactician. Just like 'audits', and 'trustees', and 'boards'.
Not in the Exchange, don't invest! |

Brock Nelson
Caldari T2 Technologies Unlimited SRS.
|
Posted - 2011.02.24 05:28:00 -
[5]
I agree with Ray, all you're doing is just bowing to people who's trying to bring you down.
|

Liberty Eternal
|
Posted - 2011.02.24 10:04:00 -
[6]
I'm sure all Cosmoray's investors will be pleased as it's a step in the right direction not just for him but for MD as a whole.
And Ray - you still posting here?
|

Jackie Fisher
Syrkos Technologies Joint Venture Conglomerate
|
Posted - 2011.02.24 10:18:00 -
[7]
Originally by: Liberty Eternal I'm sure all Cosmoray's investors will be pleased as it's a step in the right direction not just for him but for MD as a whole.
I doubt his current investors give a flying **** about it but I think some of his clients might be concerned that this doesn't compromise their confidentiality.
Joint Venture Conglomerate |

RAW23
|
Posted - 2011.02.24 10:34:00 -
[8]
Originally by: Liberty Eternal I'm sure all Cosmoray's investors will be pleased as it's a step in the right direction not just for him but for MD as a whole.
And Ray - you still posting here?
I think this kind of step is more helpful for future investors (either directly in Cosmo or indirectly through using him as a third party) than current ones in that it will allow for some kind of asset assessment. However, given that most of Cosmo's isk is, I understand, invested or loaned out privately it will be difficult to know what his actual NAV is.
Same applies to Ray. The value of making your api keys public is partly derived from making sure that the public know this, a fact that your communication strategy of acting as an information blackhole hardly supports. But the principle value of public api keys would be simply for new investors to confirm that you have what you say you have before investing. As to monitoring, this seems completely pointless given that you don't respond to basic information requests by your shareholders and there are, to my knowledge, no structures in place to stop you doing whatever you feel like. Despite all this, it is not a bad thing that the api is available for those who wish to avail themselves of it.
|

Breaker77
Gallente Reclamation Industries
|
Posted - 2011.02.24 10:44:00 -
[9]
Originally by: Jackie Fisher
Originally by: Liberty Eternal I'm sure all Cosmoray's investors will be pleased as it's a step in the right direction not just for him but for MD as a whole.
I doubt his current investors give a flying **** about it but I think some of his clients might be concerned that this doesn't compromise their confidentiality.
Well the limited API will only reveal his characters on the account, skills, and wallet balance.
The full API to an auditor will of course reveal everything. However determining what is collateral and what Cosmo owns is impossible, but it will show who he is loaning ISK out to if there is a journal transaction for it.
|

Vaerah Vahrokha
Minmatar Vahrokh Consulting
|
Posted - 2011.02.24 11:56:00 -
[10]
Cosmo, you and I had a customer (BP holding iirc) who refused to have his information given to 3rd parties in any way.
I stuck thru the MD flames to honor his will, what assurance may you give that you won't disclose that?
There is also a confidential mail I sent you with screenshots of in game chat off a customer of yours (that wanted to talk with me to send you his requests since you seem to be unreachable). Giving out a full API key to unauthorized 3rd party will be a breach of his privacy AND possibly of the EULA. - Auditing & consulting
When looking for investors, please read http://tinyurl.com/n5ys4h + http://tinyurl.com/lrg4oz
|

Edwin Rothbard
Interstellar Arbitrage
|
Posted - 2011.02.24 13:00:00 -
[11]
Originally by: Vaerah Vahrokha ...breach of his privacy AND possibly of the EULA.
LOL what? 
CCPDev> Good news everyone. We released a tool that allows anyone full access to your in game Eve mails through your full API key. player123> Great! I'll start using is right away. CCPDev> You can't. player123> why not? CCPDev > Because it violates the EULA.
You are making a vield legal thread against Cosmo. Don't do that. I understand that you don't want your super secret stuff out in the open for the world to see. Fair enough. All you had to say was "Cosmo I sent you some info in confidence in game and I expect you to keep it that way."
Of course you don't really believe it to be a violation of the EULA anyways. Otherwise you would turn down doing full-API audits on the grounds they could be a possible violation of the EULA.
|

cosmoray
Cosmoray Holdings Corp
|
Posted - 2011.02.24 13:31:00 -
[12]
TBH I still don't really understand the differences between limited and full API.
I am only concerned here with account security. If I release my full API code, what are the dangers to my account?
|

Edwin Rothbard
Interstellar Arbitrage
|
Posted - 2011.02.24 13:40:00 -
[13]
Originally by: cosmoray
If I release my full API code, what are the dangers to my account?
The crappy thing is it exposes your in game Eve mails. CCP is changing the API to be more granular so can toggle the mails on or off. This is my big complaint with the current API system. What isn't clear to me is whether deleted mails still show via the API. Someone else will have to chime in over other security concerns.
|

Kalrand
GoonWaffe Goonswarm Federation
|
Posted - 2011.02.24 14:25:00 -
[14]
Originally by: Ray McCormack With AATP's API being public, the dozens of people constantly demanding public oversight very vocally but never with any real follow up action failed to notice the BPOs being unlocked and contracted to another corp several weeks ago.
Was that the big announcement?
|

Marcus Baltar
Savaran Zhayedan Spah
|
Posted - 2011.02.24 16:07:00 -
[15]
Originally by: Kalrand
Originally by: Ray McCormack With AATP's API being public, the dozens of people constantly demanding public oversight very vocally but never with any real follow up action failed to notice the BPOs being unlocked and contracted to another corp several weeks ago.
Was that the big announcement?
Probably.
Of course, the only "official" shares, AATPH, show no unlock or lock BPO votes (so where are the BPOs?) and contracts do not show with any API.
Even if you dug out the few mentions of the API on the forums I believe it goes through a proxy - the only link I found on the AATP website does not work.
Then there are the facts that a AATPH dividend was last paid in July 2010 and the last "balance sheet" in Septemner 2010 looked like this says what? Cosmoray (back to the OP) - I do not believe releasing any API puts your actual account more at risk (I think the hacking risk is the same as not releasomg it?), but the in-game information is another matter.
Deleted evemails are probably not viewable, but then are no longer available as an in-game asset/confirmation. --
|

Vaerah Vahrokha
Minmatar Vahrokh Consulting
|
Posted - 2011.02.24 16:57:00 -
[16]
Edited by: Vaerah Vahrokha on 24/02/2011 17:01:26
Quote:
You are making a vield legal threat against Cosmo. I understand that you don't want your super secret stuff out in the open for the world to see
It's not as easy as that.
A Cosmo customer (not mine, I don't recall about having heard of him before) contacted me so that I would contact him. The alledged reason is that Cosmo is not reachable. Then he said me things to tell him with screenshots to "prove" it. He did not authorize others to look at his in game chat, I don't even think the EULA would allow for it and for sure I don't want consequences even with a 1% probability it's against the EULA.
As for the secret stuff, it's nothing really that important. I would not care to have that posted anywhere but the customer lack of authorization still stands.
Quote:
Of course you can't really believe it to be a violation of the EULA otherwise you would turn down doing full-API audits on the grounds they could be a possible violation of the EULA.
It does not apply. As you may see by reading ANY of my recent (months?) audits, I always add a disclaimer about how I am against API mail phishing and will never read and much less post any mail.
The possible recipients of Cosmo's API, though, never posted any disclaimer they wouldn't. They are not bound by any term.
Quote:
TBH I still don't really understand the differences between limited and full API.
I am only concerned here with account security. If I release my full API code, what are the dangers to my account?
No dangers to your account (*). Though, a guy with full API will directly or indirectly get:
- All your eve mails including full body text. None seems to know if such text may be retrieved even if you delete all your mails on your client side.
- Where you have any office, including low sec and 0.0
- Where you have a POS
- Where you hold collateral and whose guy the collateral is
- Who you loaned money to, including people who refused to appear on the forum.
(*) Actually there are some little dangers, in case you called your account in a common, certain way. With info you will post - even for a limited API key - it's possible to attempt a brute force attack directly on your true account. It's why CCP are going to remove that info given even by the limited API key. - Auditing & consulting
When looking for investors, please read http://tinyurl.com/n5ys4h + http://tinyurl.com/lrg4oz
|

Breaker77
Gallente Reclamation Industries
|
Posted - 2011.02.24 22:20:00 -
[17]
Originally by: Vaerah Vahrokha
- Where you hold collateral and whose guy the collateral is
When did contracts get an API?
There is no way in hell to tell if the 100,000 units of Item X are yours or collateral. It just shows up as an asset at a certain location.
|

Vaerah Vahrokha
Minmatar Vahrokh Consulting
|
Posted - 2011.02.24 22:40:00 -
[18]
Originally by: Breaker77
Originally by: Vaerah Vahrokha
- Where you hold collateral and whose guy the collateral is
When did contracts get an API?
There is no way in hell to tell if the 100,000 units of Item X are yours or collateral. It just shows up as an asset at a certain location.
You might find it odd, but not all those who give collateral to hold use a contract. Some want a direct trade. - Auditing & consulting
When looking for investors, please read http://tinyurl.com/n5ys4h + http://tinyurl.com/lrg4oz
|

Breaker77
Gallente Reclamation Industries
|
Posted - 2011.02.24 22:47:00 -
[19]
Originally by: Vaerah Vahrokha
You might find it odd, but not all those who give collateral to hold use a contract. Some want a direct trade.
True, though I prefer contracts as I have a record just in case of a computer failure on my end.
|

SencneS
Rebellion Against Big Irreversible Dinks
|
Posted - 2011.02.24 23:00:00 -
[20]
Awesome!! go back about a year or two and on this forum is my limited API released and hasn't changed since it was originally generated.. It'll be nice to know another known face in MD isn't scared of releasing their API to the public..
Only took a couple of years extra time to do what you where pushed EBANK directors to do.. Congratulations for not being a hypocrite 
Yeah, I took the liberty of poking a stick because I raised the to challenge then, and proposed you do the same, but it never came about... until now 
Amarr for Life |

Misty McGinnity
|
Posted - 2011.02.24 23:00:00 -
[21]
Originally by: Ray McCormack Hardly everything if you're only releasing your limited code to the public and the full code only to that seething mass of ego that MD 'auditors' have become.
So all well and good offering this, but with the few drama mouths on this forum being all bark but no bite it's yet another weapon in the arsenal of the smoke and mirrors tactician. Just like 'audits', and 'trustees', and 'boards'.
The bold part summarizes this thread well. much lol's
|

Breaker77
Gallente Reclamation Industries
|
Posted - 2011.02.24 23:14:00 -
[22]
Originally by: Misty McGinnity
Originally by: Ray McCormack Hardly everything if you're only releasing your limited code to the public and the full code only to that seething mass of ego that MD 'auditors' have become.
So all well and good offering this, but with the few drama mouths on this forum being all bark but no bite it's yet another weapon in the arsenal of the smoke and mirrors tactician. Just like 'audits', and 'trustees', and 'boards'.
The bold part summarizes this thread well. much lol's
/me looks around the thread /me doesn't see anyone demanding his full API key.
Hell I wouldn't even think of asking for his full API key. I could care less.
|

Misty McGinnity
|
Posted - 2011.02.24 23:31:00 -
[23]
Originally by: Breaker77
/me looks around the thread /me doesn't see anyone demanding his full API key.
Hell I wouldn't even think of asking for his full API key. I could care less.
u seem mad.
i was only pointing out that what ray posted was a very clever troll against auditors. your response makes me think that you are indeed a little bit butthurt.
|

Breaker77
Gallente Reclamation Industries
|
Posted - 2011.02.24 23:41:00 -
[24]
Originally by: Misty McGinnity ray...clever
Should never be used in the same post.
|

Estel Arador
|
Posted - 2011.02.25 00:01:00 -
[25]
Originally by: Vaerah Vahrokha Giving out a full API key to unauthorized 3rd party will be a breach of his privacy AND possibly of the EULA.
Originally by: Vaerah Vahrokha He did not authorize others to look at his in game chat, I don't even think the EULA would allow for it and for sure I don't want consequences even with a 1% probability it's against the EULA.
VV, you're full of ****e.
Firstly, the EULA is not an agreement between players but between CCP and individual players, so cosmoray only has to make sure he sticks to his agreement with CCP, and CCP gave him the API key as a safe way to release information on his character - it is up to him to decide who he wants to release it to.
Secondly the EULA explicitly mentions that you "have no expectation of privacy regarding communications you make in the Game, whether through private in-Game messaging, during chat, or in chat rooms". Of course that's in there because CCP logs all conversations, but regardless of intention, this statement you and everyone else agreed to is still very much the opposite of what you're claiming would be in the EULA.
Next time you refer to a document, try reading it first.
|

Vaerah Vahrokha
Minmatar Vahrokh Consulting
|
Posted - 2011.02.25 00:27:00 -
[26]
Quote:
VV, you're full of ****e
1) Never got why you are so depressingly confrontative (or worse) in the large majority of your replies to anyone.
2) CCP tends to forbid to repost even simple in game things, I don't want a 3rd party private convos being forwarded to another 3rd party that could even publish it in a nonconsensual way.
If I am overly conservative about EULAS and such, I will just exceed in safety. Not going to exceed in the opposite.
- Auditing & consulting
When looking for investors, please read http://tinyurl.com/n5ys4h + http://tinyurl.com/lrg4oz
|

Selene D'Celeste
Caldari The D'Celeste Trading Company ISK Six
|
Posted - 2011.02.25 00:29:00 -
[27]
Edited by: Selene D''Celeste on 25/02/2011 00:36:28 Estel hit the nail on the head. Giving out an API would never be against the EULA, unless it was stolen and you were violating the EULA via impersonation.
Originally by: SencneS Awesome!! go back about a year or two and on this forum is my limited API released and hasn't changed since it was originally generated.. It'll be nice to know another known face in MD isn't scared of releasing their API to the public..
Only took a couple of years extra time to do what you where pushed EBANK directors to do.. Congratulations for not being a hypocrite 
Yeah, I took the liberty of poking a stick because I raised the to challenge then, and proposed you do the same, but it never came about... until now 
Aside from the fact that a limited API key is pretty useless with regards to security, have you even done anything in the past two years that didn't involve speaking without thinking, let alone anything useful? ______________________________
|

Vaerah Vahrokha
Minmatar Vahrokh Consulting
|
Posted - 2011.02.25 00:35:00 -
[28]
Originally by: Selene D'Celeste Estel hit the nail on the head. Giving out an API would never be against the EULA, unless it was stolen and you were violating the EULA via impersonation.
In case saying it 3 times was not clear enough, he can give the API to whoever he wants. It's the possibility that a 3rd party would phish his mail via API and post "confidential" screenshots sent in a trust relationship that don't fly with me. - Auditing & consulting
When looking for investors, please read http://tinyurl.com/n5ys4h + http://tinyurl.com/lrg4oz
|

Misty McGinnity
|
Posted - 2011.02.25 00:36:00 -
[29]
Originally by: Vaerah Vahrokha
Quote:
VV, you're full of ****e
1) Never got why you are so depressingly confrontative (or worse) in the large majority of your replies to anyone.
2) CCP tends to forbid to repost even simple in game things, I don't want a 3rd party private convos being forwarded to another 3rd party that could even publish it in a nonconsensual way.
If I am overly conservative about EULAS and such, I will just exceed in safety. Not going to exceed in the opposite.
implying you have something to hide.
|

Selene D'Celeste
Caldari The D'Celeste Trading Company ISK Six
|
Posted - 2011.02.25 00:38:00 -
[30]
Originally by: Vaerah Vahrokha
Originally by: Selene D'Celeste Estel hit the nail on the head. Giving out an API would never be against the EULA, unless it was stolen and you were violating the EULA via impersonation.
In case saying it 3 times was not clear enough, he can give the API to whoever he wants. It's the possibility that a 3rd party would phish his mail via API and post "confidential" screenshots sent in a trust relationship that don't fly with me.
While that would be something that cosmoray should consider and could reflect poorly on him, this isn't an EULA issue since it's all part of CCP defined functionality for accessing information, and as yet we don't have a way to fine-tune the API. Luckily that should be here within the next year. I just wanted to clarify, anyway =) ______________________________
|
| |
|
| Pages: [1] 2 3 4 :: one page |
| First page | Previous page | Next page | Last page |