Discussion Forum: Thread 373446

 Author: StarBrick View Messages Posted By StarBrick
 Posted: Oct 24, 2025 04:10
 Subject: (Cancelled)
 Viewed: 107 times
 Topic: Technical Issues
Cancel Message
Cancel
BrickLink
ID Card

StarBrick (7464)

Location:  Netherlands, Gelderland
Member Since Contact Type Status
Oct 18, 2008 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: StarBrick's BrickShop
(Cancelled)
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Oct 24, 2025 04:14
 Subject: Re: Brickstore Order data not importable - again
 Viewed: 53 times
 Topic: Technical Issues
 Report:
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

StarBrick (7464)

Location:  Netherlands, Gelderland
Member Since Contact Type Status
Oct 18, 2008 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: StarBrick's BrickShop
My bad, renewed the token on the 'by pass broken access'-page here

https://www.bricklink.com/v3/brickstore-access-management.page

30 days valid
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Oct 24, 2025 11:55
 Subject: Re: Brickstore Order data not importable - again
 Viewed: 42 times
 Topic: Technical Issues
 Report:
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (55527)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Technical Issues, StarBrick writes:
  Tried to download order data into Brickstore (2025.9.2, build 1356 = most recent).

Worked fine one week back, now it says what the image shows.

Nice! And you published on line your private key

Hopefully it's not valid anymore, otherwise one could do anything with your
shop Inventory!
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Oct 24, 2025 12:26
 Subject: Re: Brickstore Order data not importable - again
 Viewed: 33 times
 Topic: Technical Issues
 Report:
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

StarBrick (7464)

Location:  Netherlands, Gelderland
Member Since Contact Type Status
Oct 18, 2008 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: StarBrick's BrickShop
I think not, as THIS key resulted in the 'Error transferring etc....'

I am quite sure this key is NOT functional anymore.

Please clarify what the harm could be.
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Oct 24, 2025 12:34
 Subject: Re: Brickstore Order data not importable - again
 Viewed: 45 times
 Topic: Technical Issues
 Report:
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (55527)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Technical Issues, StarBrick writes:
  I think not, as THIS key resulted in the 'Error transferring etc....'

I am quite sure this key is NOT functional anymore.

That's the problem, you must be SURE it's not functional. It may not
work on your side (for whatever reason). Do not publish a private key - blurr
it!

I may open a ticket on BrickStore so Robert shows only few characters like for
credit card numbers like "x9Av6h........kUiom2" in this message bow,
so you're safe to take a snapshot.

One of these days someone WILL publish a functionnal key.
Then someone will come and upload Millenium Falcons UCS at 200€ brand new and
the shop will be closed for scam, and the owner will lose all PayPal fees in
refunding
 Author: StarBrick View Messages Posted By StarBrick
 Posted: Oct 25, 2025 04:54
 Subject: (Cancelled)
 Viewed: 25 times
 Topic: Technical Issues
Cancel Message
Cancel
BrickLink
ID Card

StarBrick (7464)

Location:  Netherlands, Gelderland
Member Since Contact Type Status
Oct 18, 2008 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: StarBrick's BrickShop
(Cancelled)
 Author: nbbhav View Messages Posted By nbbhav
 Posted: Oct 25, 2025 09:21
 Subject: Re: Brickstore Order data not importable - again
 Viewed: 45 times
 Topic: Technical Issues
 Report:
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

nbbhav (58)

Location:  United Kingdom, England
Member Since Contact Type Status
Sep 5, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Unplayed Parts
In Technical Issues, StarBrick writes:
  I think not, as THIS key resulted in the 'Error transferring etc....'

I am quite sure this key is NOT functional anymore.

Please clarify what the harm could be.

To clarify this further... In essence an attacker can take the text of the private
key and then use it in their own access to BrickLink. This would mean they would
have access to whatever the key allows for the owner - in this case it will likely
mean access to the shop inventory.

More generally it's access to whatever the BrickLink API allows to be read
and written. So, in theory, they might be able to list items as if the owner
had listed them as suggested by 1001bricks (ie. spoofing the compromised account.)

Without knowing more about how BrickLink has implemented this, we really don't
know how large the attack model is. For example, assuming this key is not functional,
if the key was ever reused for another user the attacker can simply wait for
it to become live again. (This would be protected against if the username is
also sent along with the key when accessing the API.)

The team who are taking care of this area of BrickLink probably ought to consider
this issue - hopefully 1001bricks has raised a ticket.