Live data from Hacker News

Stop Sharing Your Twitter Credentials

blog.twitpay.me

11–20 of 34 posts

Re: Stop Sharing Your Twitter Credentials

#11
post #9
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

http://duckduckgo.com/?q=pw

Seems like a spam account. Created 10 minutes ago to promote duckduckgo.com.

Re: Stop Sharing Your Twitter Credentials

#12
post #7
post #4

Earlier quoted context omitted.

Agreed on the password manager. I've got 1Password in Safari, and the "Generate Password" option is so easily available it becomes second nature.

Sounds like that would make it much harder to switch browsers...

That's why I use SuperGenPass, it works on every browser, it's open source (it's Javascript) it's handy and it even works on my phone. I've got a different password for almost every site now and I don't even have to know them.

Re: Stop Sharing Your Twitter Credentials

#14
post #2

"since they don’t yet offer OAuth" OAuth wouldn't solve the problem though, it'd just move it somewhere else. Use a different login for each site - use a password manager.

Only a tiny fraction of users are ever going to find out what a password manager is, so you really haven't addressed the article's point.

Re: Stop Sharing Your Twitter Credentials

#15
post #5
post #3

Earlier quoted context omitted.

That's a good point. OAuth would at least centralize the problem towards a more trusted source and limit the number of places the credentials would be stored. I trust Google or Facebook to have more safeguards in place than a webapp that popped up yesterday. As for password managers, I totally agree people should use them, but as a practical matter, most non-tech people do not.

You trust Google to control all your logins ;) I have a cautionary tale to tell about that one...

For a huge percentage of all Internet users, a Google or Yahoo compromise is game-over; they're going to lose their bank account, and then their social, and their identity (if they lose the lottery). So centralizing on Google or Yahoo is a sensible plan.

As for your cautionary tale, I'm pretty familiar with the players here, axod. Why don't you tell us?

Re: Stop Sharing Your Twitter Credentials

#16

Continue to share your twitter credentials with sites you trust, but stop once they implement OAuth. Consider the rampant use of twitter clients. Should you stop using them? Stop trying new ones? No.

You're sidestepping the point of the article. Ivan Kirigin is not going to get screwed over by a website that asks for his Twitter password. But my mom might, because it is extremely likely that one of these fly-by-night Twitter add-on apps will lose their database to some stupid SQLI bug. My mom almost certainly uses the same password for Twitter and Yahoo Mail.

Moreover, each app that asks for passwords for another service adds social proof that this is how we build applications. It isn't.

Re: Stop Sharing Your Twitter Credentials

#17
1. Twitter users give any odd site their Twitter username and password. 2. Twitpay and Twitter now have the ability to pay other Twitter users via simple tweets.

So all someone has to do is create a Twitter-app that collects username and password for 10,000 users and randomly starts paying themselves. What could go wrong?

Re: Stop Sharing Your Twitter Credentials

#18
post #15
post #5

Earlier quoted context omitted.

You trust Google to control all your logins ;) I have a cautionary tale to tell about that one...

For a huge percentage of all Internet users, a Google or Yahoo compromise is game-over; they're going to lose their bank account, and then their social, and their identity (if they lose the lottery). So centralizing on Google or Yahoo is a sensible plan. As for your cautionary tale, I'm pretty familiar with the players here, axod. Why don't you tell us?

Google shut off my account for a week and I lost access to everything google controls - adsense, adwords, gmail, google code, youtube, blogger, google apps, google for domains etc etc They shut it off because "Someone tried to log in to it unsuccessfully"

Probably for the average person though as you say, centralizing control is probably easiest until something like that happens to them.

Wouldn't an idea be to centralize this with your ISP? The ISP already knows who you are, seems like they would be a good authority on handling authentication to websites for you. (OK, doesn't work for when you're using some hotel wifi etc)

Re: Stop Sharing Your Twitter Credentials

#19
post #16

Continue to share your twitter credentials with sites you trust, but stop once they implement OAuth. Consider the rampant use of twitter clients. Should you stop using them? Stop trying new ones? No.

You're sidestepping the point of the article. Ivan Kirigin is not going to get screwed over by a website that asks for his Twitter password. But my mom might, because it is extremely likely that one of these fly-by-night Twitter add-on apps will lose their database to some stupid SQLI bug. My mom almost certainly uses the same password for Twitter and Yahoo Mail. Moreover, each app that asks for passwords for another…

My comment is directed to this community.

I agree 100% that asking for passwords is a very bad practice, and users shouldn't be trained to do it. They should fix it immediately.

I suppose people could stick to twitter.com and sms - but to me, the defacto twitter world has clients. They are important. I want people to use them. Give your password to sites you trust, Mom.

Post reply on HN