Twitter said to be testing two-step security in wake of AP hack
crave.cnet.co.uk
Twitter said to be testing two-step security in wake of AP hack
1–10 of 27 posts
Re: Twitter said to be testing two-step security in wake of AP hack
#2Re: Twitter said to be testing two-step security in wake of AP hack
#3Bad news: Now you have to go the extra mile to make sure it isn't misused.
I think this still falls into the category of problems that it's good to have, barely.
Re: Twitter said to be testing two-step security in wake of AP hack
#4Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) and seemingly abandoned the idea in 2010? One of our Twitter accounts has ~30,000 followers and we have to share the password amongst the company in a spreadsheet, that sort of poor security is encouraged by a single login model, with all the previous high profile account compromises it seems strange Twitter hasn't addressed this before. Maybe someone knows why, or can speculate why?
Re: Twitter said to be testing two-step security in wake of AP hack
#5All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor.
Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting.
On the Web, the only approach that isn't a non-starter today is TOTP, what Google Authenticator uses. Unfortunately, basically zero users understand this, creating a large education issue, and frankly it's a pain in the neck for users ("why do I need to go find my phone to log in??"). The upside is it's easy for Web app developers to integrate TOTP, and it adds significantly to account security if used correctly.
Facebook and Google have offered this as an option for quite some time, and with Twitter's current prominence as part of corporate advertising, I am surprised they are this late to the party.
Re: Twitter said to be testing two-step security in wake of AP hack
#6Re: Twitter said to be testing two-step security in wake of AP hack
#7Re: Twitter said to be testing two-step security in wake of AP hack
#8Re: Twitter said to be testing two-step security in wake of AP hack
#9Maybe accounts for clients like the AP need not a two-factor system, but perhaps messages should only originate from a whitelisted set of IP addresses.
Re: Twitter said to be testing two-step security in wake of AP hack
#10A few years ago there was a strange byline on a few tweets from @spam, it said "by {username}" indicating that there was some sort of system allowing specific users to send tweets from a different account, here is a screenshot from January 2010: http://i.imgur.com/o0iVS.png Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) a…
I'm not saying that it's acceptable that Twitter leaves that in the hands of vendors/users, I'm genuinely curious and wondering why the idea was parked in the first place.
I'd guess that it is part of a future offering from Twitter, but who knows.