3 ms·
With this new setup the carrier channel is irrelevant. It could even be done in plain text (eg. no SSL). Since the request is being signed using a pre shared pu
by sehrope 13y ago
With this new setup the carrier channel is irrelevant. It could even be done in plain text (eg. no SSL). Since the request is being signed using a pre shared public/private key pair it can't be man in the middled or spoofed. At best someone interfering with your network connection (between you and Twitter) could prevent you from logging in if they mess with your network packets. They wouldn't be able to fake the authorization of a login attempt though.