3 ms·
the DRM-like application keys leads to some obvious underhand scenarios. if the app key is compromised, the key is revoked and no twitter access. if you extrac
by dododo 16y ago
the DRM-like application keys leads to some obvious underhand scenarios.
if the app key is compromised, the key is revoked and no twitter access. if you extract the twitter oauth key from a competitor's desktop/android/iphone/etc app and post it on the internet, twitter will kill your competitors twitter application until they distribute a new key. rinse + repeat.
i wonder if twitter will revoke their own app key.
- tptacek 16y agoIf you're saying it's "DRM-like" to have a problem that requires software protection to try to solve, I understand this comment. But if you're saying that Twitter's OAuth scheme is inherently DRM-like, no, it isn't. It makes perfect sense for web apps, and it's been shoehorned into native apps, but the core problem Twitter is dealing with (how can we shut off malicious clients) is totally orthogonal to OAuth or DRM.
- dododo 16y agoi agree it makes sense for web apps. but for apps installed in developer-untrusted environments, using app keys (and requiring their "protection"--good luck with that) is reminiscent of the dvd/bluray shenanigans.
- caf 16y agoThe whole concept of remotely distinguishing "malicious clients" from "perfectly cromulent clients" is quite DRM-like. It's analgous to the problem of distinguishing authorised video screens from unauthorised video duplicators.
- deleted 16y ago[deleted]