4 ms·
The xAuth authentication method is suspect as well: xAuth provides a way for desktop and mobile applications to exchange a username and password for
by hartror 11y ago
The xAuth authentication method is suspect as well:
xAuth provides a way for desktop and mobile
applications to exchange a username and password for
an OAuth access token. Once the access token is
retrieved, xAuth-enabled developers should dispose of
the login and password corresponding to the user.
https://dev.twitter.com/oauth/xauth https://dev.twitter.com/oauth/xauth
Asking users to trust third parties with the access details to your application? Sure they "review" the API token requests but who knows what that means.
Reading the page there seems to be a lot of talk about "keeping it simple" as if using the HTTP protocol is hard and confusing for developers. This is a bad sign, if they don't understand or care to understand something simple what are their security practices like?