4 ms·
the "internal application" is http://twitter.com/admin http://twitter.com/admin and inline admin controls on the normal pages. they might have more but in the
by anotherjesse 18y ago
the "internal application" is http://twitter.com/admin http://twitter.com/admin and inline admin controls on the normal pages.
they might have more but in the past when twitter employees has showed screenshots at talks that is what they use.
- tptacek 18y agoYeah, what I'm not following is what this has to do with OAuth and third-party applications.
- anotherjesse 18y agoAny admin user who uses a 3rd party app has to give their full credentials (username/password) to the service. And they have to store them in plain text. So if either: they are malicious, or they are attacked, the credentials are lost. I'm also assuming (not blindly) that the twitter admins use/tryout many of the tools.
- tptacek 18y agoSo that's a good point. Even if their admin tools needed to be inband, it's messed up if people are using the same creds to administer Twitter as they are in using the service or messing with third-party apps. We don't have any evidence that this is the case, but it's a good lesson to keep in mind. Thanks.