Live data from Hacker News

How to send DMs on Twitter without permission

homakov.blogspot.com

21–30 of 60 posts

Re: How to send DMs on Twitter without permission

#21
post #6

People in various forums (a couple on HN, SO, Egor's blog, Twitter itself) seem to be saying something like "this isn't really a bug". It's definitely a bug. Twitter requires clients to ask for the DM permission before they can send DMs. With Egor's approach, clients can privilege-escalate themselves to send DMs even if they never asked for that permission (although they still need to be authorized to send tweets). A…

This kind of bug falls in grey area I believe. It's more a legacy feature that should be turned off.

Nonetheless, I think it's wrong to have that feature still working.

Re: How to send DMs on Twitter without permission

#22
post #19
post #16

Earlier quoted context omitted.

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

Not only that, but if Twitter was feeling cruel, they could drag him through court (if he's based in the US). That would be a nuclear option, but, when your future welfare is on the line, you really shouldn't screw with companies.

Twitter obviously wouldn't drag a hacker to court. I'm saying, in general, don't do this, because other companies might. http://en.wikipedia.org/wiki/Randal_L._Schwartz#Intel_case

Re: How to send DMs on Twitter without permission

#23
post #19
post #16

Earlier quoted context omitted.

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

i would replace "company" with "huge company with resources". If it wasn't twitter but e.g. some startup, sure I'd report it like everyone does.

But twitter is like saying "back off, we are huge and we don't pay researchers a cent". So let it be

Re: How to send DMs on Twitter without permission

#24
post #19

Earlier quoted context omitted.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

Not only that, but if Twitter was feeling cruel, they could drag him through court (if he's based in the US). That would be a nuclear option, but, when your future welfare is on the line, you really shouldn't screw with companies. Twitter obviously wouldn't drag a hacker to court. I'm saying, in general, don't do this, because other companies might. http://en.wikipedia.org/wiki/Randal_L._Schwartz#Intel_case

Hm, are you sure cracking password and writing about a bug which you didn't exploit on other users are the same thing?

Re: How to send DMs on Twitter without permission

#25
post #19
post #16

Earlier quoted context omitted.

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

> People really shouldn't orient their moral systems around money.

Neither do corporations, but whenever you hear anyone say "corporations shouldn't base their moral systems around money", then it's all about "free market", "profit" and "shareholder values".

I'm not saying I'd do the same in this case, but it's a bit of a stretch to assume people-people morals apply to people-corporate situations.

Re: How to send DMs on Twitter without permission

#26
post #14
post #11

Earlier quoted context omitted.

Where is he "as famous"? On HN? Or somewhere else (if so where?) where he is "as famous as PG on HN". If you mean he is as famous on HN as PG is on HN I don't think that is the case.

He means that the following are equivalent: * How famous PG is in HN * How famous homakov is in HN

Who is PG? Parental Guidance?

Re: How to send DMs on Twitter without permission

#27
post #3

It only allows you to send DMs to those users you can already message - which is a small mercy. This part of Twitter's "Get Better" problem - where they've allowed SMS commands to be activated via non-SMS interfaces - http://techcrunch.com/2012/05/26/twitter-get-better/ Of course, it doesn't help that Twitter's permissions system is really poorly thought out. An app which only wants to read your Tweets also has WRITE…

So twitter should replace R&W DM to just R DM permission, because W DM comes automatically with R&W Tweets. Isn't it.. so wrong?

Re: How to send DMs on Twitter without permission

#28
post #19
post #16

Earlier quoted context omitted.

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

Well given that homakov has found this bug, there are a few possibilities:

A. Homakov could do nothing. This leaves Twitter in the same state that it is now, but it if everybody did this, it is likely that nefarious people would find and exploit bugs in Twitter

B. Homakov could donate his time, as a skilled and highly-trained professional consultant, to a $32bn publicly-traded company

C. Homakov could practice full disclosure

This isn't even close to blackmail. This is a security consultant publishing a vulnerability that he discovered on his own time, that apparently Twitter's internal security team missed. That might be embarrassing for Twitter, but tha'ts hardly homakov's problem as a third party.

Re: How to send DMs on Twitter without permission

#30

This is in line with a long laundry list of horribleness about user experience as related to DMs in my opinion. They don't work as expected, and quite honestly to me it feels like Twitter is running a campaign to destroy peoples' love of the DM in search of a Solution, maybe in preparation for a dm 2.0 or something. Some of the experience elements of DM have been fixed on the iPhone, but last I checked, the problems…

Taking into account this bug and twitter's response - they don't differ DMs from tweets much. Privateness of DM doesn't mean it to them what it means to us.
Post reply on HN