Argh, why do we vote up this crude sensationalist crap?
Twitter's OAuth has a gaping security hole
11–20 of 26 posts
Re: Twitter's OAuth has a gaping security hole
#12Seriously though, why do all the security examples and scenarios always involve an Alice and a Bob? And why is Alice always the bad guy (or chick)?
Re: Twitter's OAuth has a gaping security hole
#13That's a feature, not a bug. In twitter as far as I remember you have the opportunity to revoke tokens yourself. It's definitely not a security hole.
In general, having the average naive user administer any aspect of security beyond choosing a "secure" password is a naive expectation. You can't afford to have both parties acting naively when it comes to Internet security. For this (non-naive) audience, managing OAuth tokens makes sense and Twitter can afford to be naive. For the rest of the Internet audience this approach is probably more dangerous than convenient.
Re: Twitter's OAuth has a gaping security hole
#14Re: Twitter's OAuth has a gaping security hole
#15Seriously though, why do all the security examples and scenarios always involve an Alice and a Bob? And why is Alice always the bad guy (or chick)?
You need to read Applied Cryptography.
Re: Twitter's OAuth has a gaping security hole
#16Re: Twitter's OAuth has a gaping security hole
#17Re: Twitter's OAuth has a gaping security hole
#18Re: Twitter's OAuth has a gaping security hole
#19Re: Twitter's OAuth has a gaping security hole
#20Seriously though, why do all the security examples and scenarios always involve an Alice and a Bob? And why is Alice always the bad guy (or chick)?