-
Website
http://www.louisgray.com/live/ -
Original page
http://blog.louisgray.com/2008/11/twitterank-can-have-my-password-no.html -
Subscribe
All Comments -
Community
-
Top Commenters
-
charlieanzman
61 comments · 11 points
-
Jesse Stay
221 comments · 71 points
-
Ari Herzog
43 comments · 23 points
-
ChangeForge | Ken Stewart
135 comments · 18 points
-
drewolanoff
64 comments · 54 points
-
-
Popular Threads
-
For All the Gloom Around RSS, Readers Continue to Climb in '09
20 hours ago · 19 comments
-
Growing Grumblings on Tech News Don't Answer Incentives Problems
4 days ago · 33 comments
-
iTunes, Sirius Seem Antiquated After Spotify iPhone Trial
5 days ago · 15 comments
-
FTC Disclosures Made Simple For Bloggers With Conflicts
2 weeks ago · 57 comments
-
My iPhone Data Consumption Workflow
4 days ago · 6 comments
-
For All the Gloom Around RSS, Readers Continue to Climb in '09
admitted defeat, and gone around switching a few passwords. But it
doesn't look like that's the case. I do know my FriendFeed API key by
heart as well, but the best part is that my iPhone has it saved as a
previous address, so sending pics via e-mail from there is a cinch.
@jesseluna on Twitter.
My issue is that what Twitterank is doing isn't too much different than other services, and it's not malicious. The author is here: http://twitter.com/ryochiji
Get Twitter on OAuth and this issue all goes away.
However, this is a good situation for Twitter to take note of and to work on implementing OAuth so we don't have to worry about someone actually running off with data.
require Twitter credentials. The issue here was that the service was
unknown, new, and had some odd comments in the source page that had
people uncomfortable. After that, it was just typical lemming behavior.
What!!!! Neiman-Marcus sells cookies? Microsoft is going to pay me to
surf the Web!!!
...which is hilariously ironic, considering they bought some guy's JOKE tweet and immediately assumed it was the twitterank guy.
All they had to do was a simple whois search on the domain, and they could have even called the guy who made the site.
People are such sheep - everyone follows the herd first getting their "rank," then they all collectively go into a frenzy over ZDNet's paranoid and unresearched speculation. It took me about 30 seconds to find the guy, and I'm a complete n00b compared to what I'd expect from the people at ZDNet. Of course, that's just one guy on the blog - talking out of his arse, like most bloggers. ;)
Craig
www.budgetpulse.com
In my experience many web developers have a poor idea of security, after all even long established web apps have security flaws like the ones in WordPress or this one I found in phpMyAdmin ( http://www.phpmyadmin.net/home_page/security.ph... )
http://techtantra.net/2008/11/10-applications-t...
IMO the real take-away here are - Twitter needs to implement OAuth and users need to be a little more careful who they give their credential to.