10 ms·
The service seems counter intuitive. You advertise "The safe way to manage your company’s Twitter accounts." yet using the service would mean giving access to a
by tommi 13y ago
The service seems counter intuitive. You advertise "The safe way to manage your company’s Twitter accounts." yet using the service would mean giving access to a third party. We all know that security is hard and you're creating online password manager - if it will be popular, it will gain unwanted attention.
Sure, you are using an access token and not a password for the accounts, but that's not explicitly said anywhere. I suggest you improve the trustworthiness of Echelon on the landing page.
- jalada 13y agoThe landing page mentions that you don't have to share passwords, which is what makes it inherently securer than...well...sharing passwords. Agreed that perhaps it could be clearer that by using access tokens, access can be revoked at any time via Twitter directly which removes the risk (compared to people stealing passwords).
- tommi 13y agoSee, I'm bit confused here. I understood it so, that as a user of Echelon, as I wouldn't have to give the Twitter account password to colleagues. But what about to Echelon itself? How can I be sure that the Echelon won't be compromised and all hell wouldn't break loose? Does the account have one Echelon app authorized which then works as a middleman to the users?
- rsoto 13y agoSince only the tokens are stored on Echelon's server, any compromise might do some damage (tweets, bio change, etc), but you will not lose the account's password. So that's a pretty good tradeoff if you ask me.
- deleted 13y ago[deleted]
- jenandre 13y agoThey don't use https anywhere, not even on the oauth redirect back with the token in the header... isn't that.. bad? How much you want to bet they are doing 0 encryption of the tokens they are storing on their servers.