3 ms·
Couldn't agree more. As much as I dislike Gruber's style (all snark, all the time) the man is intelligent. How he does not see that less sharing of credentials
by Getahobby 15y ago
Couldn't agree more. As much as I dislike Gruber's style (all snark, all the time) the man is intelligent. How he does not see that less sharing of credentials equals better security is beyond me. This is clearly a security win. Definitely a usability loss but welcome to infosec. That is the battle.
- bandushrew 15y agoIt is a security win (and Im pretty sure gruber sees that). His point is that the interface is a usability loss, and a big one.
- Getahobby 15y agoHe goes out of his way to say it doesn't increase security.
- protomyth 15y agoHow is it a security win in a native app? The app controls the web view and can get at the password. It is the illusion of security with the added confusion of acting different than other services (like e-mail).
- bandushrew 15y agoQuite right. I was momentarily blinded by the idea of being able to grant specific access rights to specific applications without giving them password access, but clearly if they control they web view you are doing this by, not much has been gained.
- Pahalial 15y agoTwitter's API does not only service native (smartphone) apps. xAuth is always abysmal security; OAuth provides in some cases some increased security.
- darklajid 15y agoWhich is the whole point of the argument: OAuth makes sense for browser based applications/access from one web application to another. It makes no sense for native apps since those can still grab your credentials in a wild variety of ways. If you agree with that, then you should see that the change from "Choose xAuth or OAuth, based on preference and usage" to "Use OAuth unless you are the official Twitter client, if it makes sense or not" is questionable.
- Getahobby 15y agoThese two arguments are separate. A malicious app that steals credentials (wait, in Gruber's world these apps are vetted, right?) is going to steal credentials whether it uses xauth or oauth. A non malicious app that uses xauth could in theory be exploited to reveal credentials whereas if it just used oauth it wouldn't be an issue of the same magnitude. It is a security win. You can argue the magnitude of the win all you want.