3 ms·
What stops the sites from just creating another API key (and call it something obfuscated if they were using something obvious before). Or, just run strings on
by gorena 11y ago
What stops the sites from just creating another API key (and call it something obfuscated if they were using something obvious before).
Or, just run strings on the Twitter iOS app bundle... or just look at traffic in Charles...
- nailer 11y agoNothing, but breaking the ToS means they'll always be shut down before they can become big.
- user_0001 11y agoI haven't read the story or followed it all. But I create API key for site: xyz.com where I use the stream API to get all tweets from users a-z Then I push those to site zyx.com There is no way for twitter to know what API generated those tweets. Especially if site xyz.com DOES obey the delete notifications (which also triggers site zyx.com to go into action in checking the deleted tweet) I don't see how this is a total non-story
- gorena 11y agoThey would be able to be shut down if they're using Twitter's own API keys - or iOS's built-in keys. These types of things can typically be easily found with strings or a proxy (Charles).
- x0054 11y agoA better question would be what would stop a site from creating hundreds of Twitter accounts and doing some good old scraping.
- gorena 11y agoThat would work, but just finding a key with strings is much less effort (no code changes required).