<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>louisgray.com - Latest Comments in louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://louisgray.disqus.com/</link><description>A Silicon Valley Blog for Early Adopters and Tech Geeks</description><atom:link href="https://louisgray.disqus.com/louisgraycom_hey_twitter_its_not_just_a_worm_its_an_app_01/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 05 Jan 2009 17:45:34 -0000</lastBuildDate><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4920367</link><description>&lt;p&gt;Where this particular instance was a third-party attack however, you have to admit OAuth would have fixed this phishing attack.  Twitter's repeated mention that it wouldn't have makes no sense.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jesse Stay</dc:creator><pubDate>Mon, 05 Jan 2009 17:45:34 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4920326</link><description>&lt;p&gt;Stiennon, I agree a screen scrape wouldn't be very hard, but how are they going to obtain the credentials in the first place?  They couldn't write a script to make users spread it for them, at least not as fast as they are with this worm.  I argue that method would be much harder and take a longer time to do on a site like Twitter.  I don't think the worm we're seeing today would still exist if OAuth were in place.  And I have yet to see Alex suggest Federated Identity or one time passwords as a solution - his only response is, "OAuth doesn't work".&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jesse Stay</dc:creator><pubDate>Mon, 05 Jan 2009 17:43:16 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4919131</link><description>&lt;p&gt;You have a point - now that we're on version 5 of the phishing scam, I have to admit that I have some very gullible or very trusting folks following me.&lt;br&gt;:\&lt;br&gt;You'd think we'd all have learned by now - don't trust strange links on the internet.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lucretia M Pruitt</dc:creator><pubDate>Mon, 05 Jan 2009 17:04:55 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4918951</link><description>&lt;p&gt;I have to agree with Stiennon on this one.  OAuth needs to be implemented but only solves third-party interactions with your account.  OAuth does nothing to prevent traditional phishing attacks where you as a human mistakenly give your credentials to a fake site.  Just like with any social media service (Facebook/Myspace) I can manually log in with stolen credentials and DM/spam friends and contacts.  OAuth is only good when a third-party application is using your credentials.  Just like how FriendFeed uses the remote key solution for third-party authentications to FriendFeed.  Having stolen FriendFeed credentials I can still logon to FriendFeed as the victim.  The remote key doesn't stop this type of attack.  Twitter needs two-factor token based authentication and OAuth for a complete solution.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom</dc:creator><pubDate>Mon, 05 Jan 2009 16:54:41 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4918204</link><description>&lt;p&gt;Agree that OAuth raises the bar, but only slightly.  First, you don't need no stinkin API to get into the original application, in this case Twitter.  You call it screen scraping, but running a script against the site is easy to do using the credentials stolen from users.   You can run the attack manually as most post phishing attacks against banks are and just as the Twitter defacements of this morning.&lt;/p&gt;&lt;p&gt;OAuth is not the way. Strong federated identity with one time password tokens is what it is going to take.  In the mean time Twitter has to improve all of their security. Evidently they had an easily discoverable UI for resetting passwords that was hacked.  Sheesh.&lt;/p&gt;&lt;p&gt;-Stiennon&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Stiennon</dc:creator><pubDate>Mon, 05 Jan 2009 16:12:43 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4914976</link><description>&lt;p&gt;I knew it was just a matter of time before twitter would be hacked. I had no idea that twitter was so open with their house keys or in this case my username and password. Hopefully this will be a good lesson for developers everywhere to place more focus on secuirty. Great article! Thanks!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AnneHaynes</dc:creator><pubDate>Mon, 05 Jan 2009 14:53:54 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4914244</link><description>&lt;p&gt;Lucretia, I think there are definitely enough users to encourage it.  The worm itself wouldn't have spread if no one clicked the link, so I think there are plenty of people that would make it worth the spammers'  while.  I don't expect it to go away, unless Twitter takes measures to make it go away.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jesse Stay</dc:creator><pubDate>Mon, 05 Jan 2009 14:23:36 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4912910</link><description>&lt;p&gt;OAuth would help - but what will kill things like this is when they find out that it's not profitable... Twitter isn't a great place for the "follow this link!!" stuff. :)&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lucretia M Pruitt</dc:creator><pubDate>Mon, 05 Jan 2009 13:01:17 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4912454</link><description>&lt;p&gt;One of the big benefits of OAuth is that the user can say that an application only gets read access to the account. So, if the API and OAuth are done correctly, you can specifiy that a 3rd party application can only read your twitter stream, not send messages on your behalf. As you stated, it does not fix everything, but the security of OAuth definitely makes it harder for someone to completely take over your account.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">robdiana</dc:creator><pubDate>Mon, 05 Jan 2009 12:28:41 -0000</pubDate></item><item><title>Re: louisgray.com: Hey Twitter, It's Not Just a Worm, It's an App</title><link>http://blog.louisgray.com/2009/01/hey-twitter-its-not-just-worm-its-app.html#comment-4944833</link><description>&lt;p&gt;Post by Jesse Stay: &lt;a href="http://www.friendfeed.com/jessestay" rel="nofollow noopener" target="_blank" title="http://www.friendfeed.com/jessestay"&gt;http://www.friendfeed.com/j...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Louis Gray</dc:creator><pubDate>Mon, 05 Jan 2009 11:09:00 -0000</pubDate></item></channel></rss>