4 ms·
Surprised at the amount of agreement with this article, and the cries of "incompetence". ISTM in a desktop app context, the consumer key/secret combination eff
by allertonm 16y ago
Surprised at the amount of agreement with this article, and the cries of "incompetence".
ISTM in a desktop app context, the consumer key/secret combination effectively becomes a complicated equivalent to your browser's "User Agent" string and yes, only slightly more difficult to spoof.
So what Twitter is asking for is that in order to authenticate a user (with additional credentials) you give them a valid "user agent" that was assigned by Twitter. This at least allows them to understand, when they get traffic, who wrote the app that's sending it. It's obviously not perfect in a desktop case but then neither is user agent - but there is no perfect solution for the desktop case, and Twitter's choice allows them use a consistent mechanism for client and server apps.
(Edit: the OA responds below and says I'm wrong about this part. I'll take his word for it.)
I suspect the OA's problem is more with being a) asked to do this nasty complicated Oauth thing and b) with the idea of Twitter wanting to know who he is - and he'd rather they just let him keep on persisting user's twitter creds himself. Conflating this consumer key with DRM is a bit of a giveaway.
(Updated: The important point here is that the author's app is open-source and he chose to distribute the keys with the source code, rather than require each person who builds it from source to get their own API keys.
I think Twitter's position - that the author should not have done this - is completely reasonable.)
- Tichy 16y agoI read it as the problem being that Twitter might ban your app if they find that you published your oAuth secrets, which is impossible to avoid.
- nelhage 16y ago> So what Twitter is asking for is that in order to authenticate a user (with additional credentials) you give them a valid "user agent" that was assigned by Twitter. No. What Twitter is asking for is that you keep that "user agent" secret, even though you have to distribute it to everyone who uses your app. And they have demonstrated that they will happily block that user agent value if you don't do so. I would be perfectly happy identifying my app to Twitter, and I'm more than happy using OAuth -- it's technically a much better choice than plain passwords. I'm not happy that I have to fulfill an impossible requirement or have my app disabled, and more so that that requirement isn't applied to Twitter themselves or to the other large players they have partnerships with.
- cageface 16y agoNo. What Twitter is asking for is that you keep that "user agent" secret, even though you have to distribute it to everyone who uses your app. And they have demonstrated that they will happily block that user agent value if you don't do so. If they're relying on that "user agent" key for anything important they're asking for trouble.
- allertonm 16y agoIf someone spoofs your user agent and sends a ton of traffic to Twitter, what would you rather they do? It's like when someone spoofs your credit card - the bank blocks it, and sends you a new one. Inconvenient, yes - but better than the alternative.
- nelhage 16y agoIf someone spoofed my user-agent and was spamming with it, and they blocked it, I would be annoyed, but I hope I would be understanding that they were doing what they need to maintain their service, and I was unfortunate collateral. When they pre-emptively ban my user-agent because someone might steal it and spam with it, but don't apply the same rules to themselves and their partners, then I get annoyed.
- allertonm 16y agoThe important point here is that your app is open-source and you chose to distribute the keys with the source code, rather than require each person who builds it from source to get their own API keys. I think Twitter's position - that you should not have done this - is completely reasonable.
- seanalltogether 16y agoThis really isn't much different from other OAuth providers eg Ebay. Maybe twitter is more explicit in asking that the user agent is kept secret, but many other providers ask the same thing implicitly, and are just as likely to shut off your app if others spam on your user agent. And yes Twitter is just like thousands of companies that have come before them that pay lip service to partnering companies.