Live data from Hacker News

Stop Sharing Your Twitter Credentials

blog.twitpay.me

31–34 of 34 posts

Re: Stop Sharing Your Twitter Credentials

#31
post #17

1. Twitter users give any odd site their Twitter username and password. 2. Twitpay and Twitter now have the ability to pay other Twitter users via simple tweets. So all someone has to do is create a Twitter-app that collects username and password for 10,000 users and randomly starts paying themselves. What could go wrong?

Twitpay doesn't let you link it with a credit card or anything. You have to authorize the paypal payment anytime you want to add money to it, so the only money someone could take that way is the money you leave in your account.

Re: Stop Sharing Your Twitter Credentials

#32
post #26
post #18

Earlier quoted context omitted.

Google shut off my account for a week and I lost access to everything google controls - adsense, adwords, gmail, google code, youtube, blogger, google apps, google for domains etc etc They shut it off because "Someone tried to log in to it unsuccessfully" Probably for the average person though as you say, centralizing control is probably easiest until something like that happens to them. Wouldn't an idea be to centra…

Few months ago, someone I know (nontechnical) lost their password on a public blog server. Unfortunately, like most people, they used the same password on their Yahoo mail account. Inside of a day, they: * Got locked out of their Yahoo mail account for a week * Lost their GoDaddy account, got locked out of it, and had it redirected to a gay porn site * Lost their bank account, had thousands in fraudulent charges rack…

Wasn't this a targeted attack against a security blogger?

Re: Stop Sharing Your Twitter Credentials

#33
post #32
post #26

Earlier quoted context omitted.

Few months ago, someone I know (nontechnical) lost their password on a public blog server. Unfortunately, like most people, they used the same password on their Yahoo mail account. Inside of a day, they: * Got locked out of their Yahoo mail account for a week * Lost their GoDaddy account, got locked out of it, and had it redirected to a gay porn site * Lost their bank account, had thousands in fraudulent charges rack…

Wasn't this a targeted attack against a security blogger?

Yes. Under normal circumstances, the attackers would have silently harvested all the victim's accounts and sold them in Estonia.

Re: Stop Sharing Your Twitter Credentials

#34
With every twitter account I feel like squatting on (and, oh , btw, yes everyone does it), I create a not-too-close gmail account for use with just that twiter account (for verification), and use that to test the 3rd party apps that "Must" have your twitter creds in order to work. What I have found, by trial and eror, is that over half of ALL the currently available (and some beta) 3rd party apps work PERFECTLY WITHOUT any signup or twitter cred. So why do THOSE particular 3rd party apps need the info? I doubt they need it for future growth of the app or "extra features" later.
Post reply on HN