5 ms·
There's still a culture of too-much-access (we might need it in the future!!) that needs to be addressed here. Perhaps once we're all super used to these inters
by imajes 16y ago
There's still a culture of too-much-access (we might need it in the future!!) that needs to be addressed here. Perhaps once we're all super used to these interstitials, then it'll become a no-brainer to come back to them and request info.
Personally, i think we should go even further; lets request sunset/timeout clauses on access. I'm willing to give the kanye analyzer two weeks access to my twitter account, but after that, i want my token rescinded.
- tptacek 16y agoI agree, but I think that's an issue Twitter needs to take up with app developers; there's no dialog you can design that enables them to punt that concern to end-users.
- baconner 16y agoAbsolutely right. LinkedIn is doing this. access for one day, one week, ... when granting permissions.
- deno 16y agoHere's screenshot of how it looks: http://developer.linkedin.com/servlet/JiveServlet/downloadImage/38-1039-1130/400-276/oauth_window_screenshot.png http://developer.linkedin.com/servlet/JiveServlet/downloadIm... However the reason LinkedIn does it is probably because the nature of information accessed is very fragile. Similar, but slightly different solution, I'd suggest, would be to track by provider if application is actively used and perhaps revoke token after some period of time (or at least present user with that data on their profile settings page).