3 ms·
I wish that they had taken this opportunity to discard the use of OAuth. These are native applications, not web applications, and there's near zero security val
by nupark2 14y ago
I wish that they had taken this opportunity to discard the use of OAuth. These are native applications, not web applications, and there's near zero security value to using OAuth.
When mixing OAuth and native applications written by non-nefarious parties, the only entity you're preventing from reading the user's password is the user themselves.
However, if a nefarious party writes a native app, they can easily acquire the password even if you do use OAuth.
It's a case of bad UX being pushed on users due to fundamental cultural misunderstandings between the web teams declaring authentication requirements, and the native developers who want to provide the best UI.
Twitter is absolutely doing this correctly by providing xAuth for use by native applications.