Call now on +44 (0)1273 704 549

Never Share Your Twitter Password Again

Twitter OAuth Authorization
Uploaded with plasq’s Skitch!

A few hours ago Twitter’s OAuth private beta was launched and Inuda was one of the lucky 150 users to be chosen to test it. OAuth is an open protocol that allows secure API authorisation in a simple and standard method from desktop and web applications. What it does is allow you to connect your Twitter account to a third party service without you having to share your password with them. This means if you ever suspect an application to be doing something it shouldn’t with your Twitter account you can simply turn off their connection without having to change your password.

We managed to get a prototype up and running within a few minutes with no problems so we think it’s fair to say that you should never give your Twitter password to anyone ever again. In a few weeks all developers of Twitter applications will have access to OAuth and they’ll have no excuse other than laziness for not using it. Instead, when an application requests for access to your Twitter account you should be redirected to a page at http://twitter.com which will look something like the image shown above.

5 Tweets 10 Comments 15 Other Comments

55 Comments »

  1. Cennydd Says:

    What can one say but “about bloody time”? :)

  2. amichail Says:

    It doesn’t look like there’s a mode where the the app would not get any access to private data.Why would users trust an app that has access to their direct messages?

    This comment was originally posted on Hacker News

  3. sh1mmer Says:

    Well Twitter only has 2 modes, public and protected.An app can access anything public through the existing API anyway without authentication.

    The only difference here is that you can allow apps your trust to access your private data (or functions, like sending tweets) without giving out your password. As such it’s a big step in the right direction.

    Twitter apps have been one of the worst offenders for the username/password anti-pattern because of Twitter’s use of HTTP-Auth for the API.

    This comment was originally posted on Hacker News

  4. amichail Says:

    There are benefits to having the mode I describe:* your app can perform more API calls without IP-based rate limiting (which can be a real problem when using the Google App Engine due to shared IPs between apps)

    * you can be sure that the user is who he/she claims to be (without a DM hack), which is important for some apps

    This comment was originally posted on Hacker News

  5. @h0neyb Says:

    Seriously this is awesome! I might have to draw a Beedoodle about this!

  6. jballanc Says:

    The real story here is that OAuth has much wider and far reaching implications than just Twitter apps. I think we’ve reached the high-water mark of the number of logons and passwords we’ll need to keep track of. I see a future not that far off where everything from Credit and ATM transactions to your Facebook and HN logins are all handled by OAuth.

    This comment was originally posted on Hacker News

  7. Aaron Says:

    Brilliant.

  8. amichail Says:

    Not sure why parent was upmoded. Is there a reason why one would not want this mode added?

    This comment was originally posted on Hacker News

  9. COP Says:

    An offtopic comment on the RWW Ad on right.

    In the ad "Discover the Semantic Web – A Dow Jones Webinar" – Is that woman drawing OWL/RDF diagram?? u must be joking.. how can such a hottie do RDF? its 1:55AM EST.. may be i m hallucinating..

    ( owl:unionOf ROTFL, WTF )

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  10. marksilva Says:

    This is killer. We think there are huge opportunites & implications for brands and apps dev using OAuth for Twitter. Here are some:

    1) Multiple account management tools. Add all your accounts via oauth and use a single account to manage multiple accounts in one place. Who needs multiple accounts? All brands because they have different consumers. For instance, Dell has 18+ twitter accounts, some in 5 languages. A CPG brand may have their wild loyalists and some into them for a specific product feature or attribute.

    2) Twitter CRM. If a brand can offer an OAuth access, it will allow someone to follow specific tags or keywords from their streams without having to follow. It will also allow d-m without following to have a back-channel conversation.

    3) Instant DM/Search Alerts. If you allow an app access, it can DM you when Tix are on sale, stocks move, your boss is mentioned, etc.

    BTW, if you dev any of these tools, message me and we’ll beta/apply. Cheers! Mark Silva, Real Branding

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  11. jonursenbach Says:

    At the adoption rate it’s going, I can see Facebook Connect replacing a high amount of "secure" websites like bank accounts within the next few years; and that’s unfortunate.

    This comment was originally posted on Hacker News

  12. jason Says:

    phew, finally!

  13. Twitter’s OAuth geht in die private Beta » sicheren Authorisierung, OAuth, Twitter, Authorisierung, Wochen, Twitter-Accounts » MountainGrafix :: Der Webwork und Technik Podcast Says:

    [...] Sachen mehr Datensicherheit bei Twitter bewegt sich langsam was, denn wie drüben bei Inuda und auf ReadWriteWeb.com zu lesen ist, geht die geplante OAuth API Authorisierung für Twitter [...]

  14. Danesh Says:

    Cool feature to have.

  15. Twitter OAuth « Wir sprechen Online. Says:

    [...] IT, Net, OAuth, Security, Twitter, Web Twitter launches OAuth in a private beta among 150 users; http://tr.im/fwaehttp://tr.im/fwaf   [...]

  16. Gerrit Eicker Says:

    RWW: “Twitter OAuth – oft promised but lagging in delivery – had begun to take on a mythical status, leaving many to wonder if it would ever be released. Now, that naysaying could be coming to swift end. It appears that Twitter OAuth has been released into the wild as part of a limited beta. – Why is this important? It means that Twitter applications now have a way to verify user identity without asking for a username and password. Those credentials remain the private property of the user – but he or she still gets access to the tool and his or her Twitter account.”

    This comment was originally posted on http://wir-sprechen-online.com/)">Wir sprechen Online

  17. Matt Says:

    This is absolutely brilliant, shall ensure we get it properly integrated into out upcoming Twitter app.

  18. mike ashworth Says:

    This is great news as as someone already pointed out, about time.

    Good to see Inuda in there with testing this stuff out.

    Mike

  19. Alex Schleber Says:

    Very important and not a moment to soon. The current state of affairs was endangering Twitter app growth, b/c some recent apps had clearly been designed to harvest logins, thereby putting everyone under suspicion.

    Follow me on Twitter, I follow back:
    Twitter.com/AlexSchleber

  20. hype.yeebase.com Says:

    Twitter hat jetzt OAth integriert…

    Endlich hat Twitter für die ersten Betanutzer OAth integriert. D.h., man muss seine Passwörter nicht mehr bei den einzelnen Mashups eingeben….

  21. AndrewDucker Says:

    I can’t see banks handing over authentication to anyone.

    This comment was originally posted on Hacker News

  22. madmotive Says:

    An extra point. Apps can choose to be read only our read/write when they are set up. Will be interesting to see how many opt to be read only.

    This comment was originally posted on Hacker News

  23. Jonathan Markwell Says:

    Rick – Thank you for the link to my blog post! Great to see so much interest in it.

    Mark – Looks like your as excited as we are about this! :) Our company, Inuda, is now focusing on Twitter application development. We’re also currently running a private beta of a tool that does much of what you are looking for in a Twitter app. It’s called SocialPlume (featured in the screenshot above). We have a holding page up at http://socialplume.com Please get in touch if you’d like to be one of the first users.

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  24. Rodney Rumford Says:

    I am really glad to see this auth coming as there are some unscrupulous developers that exploit user password for a variety of uses. This was much needed and was only a matter of time before it became critical.

    Users need this to feel comfortable using apps built off of the api. This will bode will for the long term vision of twitter as a platform. ’bout time ;)

    Large brands and companies that want to build apps off of the api have expressed concerns regarding privacy from a legal standpoint and this will alleviate those concerns.

    http://twitterbusinessbook.com

    Cheers!

  25. Twitter OAuth Spotted in the Wild | google android os blog Says:

    [...] if it would ever be released. Now, that naysaying could be coming to swift end. It appears that Twitter OAuth has been released into the wild as part of a limited [...]

  26. sh1mmer Says:

    Unless Twitter change their rate limiting model it makes sense to be be read-only still. This allows you to tap into the 100reqs/hr Twitter allocates to users rather than using up the IP rate limiting for generic requests.

    This comment was originally posted on Hacker News

  27. sh1mmer Says:

    OpenID actually has support for extensions that can allow you to require additional requirements of the AP (authorizing party). This means a bank could, for example, ask for multi-factor authentication from the AP.I doubt banks will accept generic identity providers in the near future, but I can see them allowing known players in the consumer internet space to provide multi-factor identification.

    At the least they could let you identify yourself with another provider and then add additional factors on their side.

    This comment was originally posted on Hacker News

  28. Adam Says:

    Awesome – can’t wait for access so we can get TimePoke using Twitter/OAuth!

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  29. Twitter OAuth Spotted in the Wild | Spin Valley Post Says:

    [...] if it would ever be released. Now, that naysaying could be coming to swift end. It appears that Twitter OAuth has been released into the wild as part of a limited [...]

  30. marksilva Says:

    Follow-up thought: oAuth is going to become the default and users will avoid sites asking them for their login/pw. I’m already starting to postpone using services until they implement it.

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  31. Twitter to Support Oath please UBC Support OpenID and OAuth I beg. Says:

    [...] all the heavy weights are going moving towards adoption of OpenID and OAuth. Twitter today started beta testing OAuth why should you care? Well for one pretty much all Twitter users use some sort of client to [...]

  32. Marc’s Voice » Blog Archive » Compendium of coolio posts - blogging Feb ‘09 Says:

    [...] This is the benefits of oAuth [...]

  33. SearchCap: The Day In Search, February 12, 2009 Says:

    [...] Never Share Your Twitter Password Again, Inuda.com [...]

  34. Ron Bailey Says:

    Looks cool. Hopefully they’ll widen the beta soon.

  35. hakn Says:

    It’s called SocialPlume (featured in the screenshot above). We have a holding page up at muhabbet mIRC Please get in touch if you’d like to be one of the first users.

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  36. Jeroen de Miranda Says:

    Robust and reliable implementation of OAuth at Twitter will lead to:

    - more visible usage by prominent users: with OAuth they will trust to use Twitter in combination with the many third party add-on applications that are out there;

    - faster and broader acceptance in the corporate world, by enabling in a more trusted way integration with corporate systems (CRM systems is just one example; another might be HRM systems).

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  37. keskinmercan Says:

    i didint interest about it Dekorasyon Granit Granit

    This comment was originally posted on http://searchengineland.com/)">Search Engine Land: Must Read News About Search Marketing & Search

  38. Hootsuite:增强版Twitter多帐号管理专家 | 天涯海阁 | Web2.0Share Says:

    [...] ä¸è¿æä¸ç´å¯¹äºTwitterçç¬¬ä¸æ¹åºç¨æ²¡æç±»ä¼¼äºFriendfeed䏿 ·çéªè¯æ¹å¼ï¼æ¯æ¬¡é½è¦è¾å¥twitterç¨æ·ååå¯ç ï¼å¯¼è´æçææºæ¯æ¬¡ç»å¥Twitteré½è¦éè¾ç¨æ·ååå¯ç ï¼ä¸è¿è¿ç§å±é¢ä»¥åå°ä¸å»ä¸å¤è¿äºã [...]

  39. sbostedor Says:

    About damn time!

  40. claus Says:

    OAuth på vej til Twitter http://tinyurl.com/dgskbs

    This comment was originally posted on Twitter

  41. domderrien Says:

    After Twitter+OAuth http://bit.ly/srrCR, GAE+OAuth http://bit.ly/3J2zA, now Dojo+OAuth http://bit.ly/Tw1Mg: need 48 hrs/day to exploit them!

    This comment was originally posted on Twitter

  42. Casey McKinnon Says:

    Here! Here!

    This comment was originally posted on http://blog.rickrey.com/)">OMGRICK

  43. Rick Rey Says:

    Yeah Mike, me too. I could probably hack something together, but it would take waaay too long and it wouldn’t be remotely elegant. BUT I could design a front-end if someone had the chops to build the app.

    Also yes, SCHED is pretty sweet. Looking forward to the SXSW ‘09 update coming soon.

    This comment was originally posted on http://blog.rickrey.com/)">OMGRICK

  44. mike1630 Says:

    I’ve never heard of SCHED before – awesome site :) and yes, this would be a kick ass tool… for any event. I wish I knew how to do this stuff…

    This comment was originally posted on http://blog.rickrey.com/)">OMGRICK

  45. AndrewPWilson Says:

    Like idea of http://tweetake.com/ for Twitter backup, but again password reqd. Wish OAuth was here: http://tinyurl.com/dgskbs

    This comment was originally posted on Twitter

  46. geraldaungst Says:

    @mcleod Only because I’d heard of this: . So I’m waiting for this: http://bit.ly/srrCR

    This comment was originally posted on Twitter

  47. geraldaungst Says:

    @mcleod Only because I’d heard of this: http://bit.ly/13o1PZ. So I’m waiting for this: http://bit.ly/srrCR

    This comment was originally posted on Twitter

  48. Henrik Lied Says:

    I’ve created a Twitter oAuth app which is available for everyone. Check it out at my labs: http://bit.ly/twitter_oauth

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  49. Tyler Says:

    FINALLY!

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  50. 055 - Andrew Burnett on SEO, Twitter, Talk 107 Says:

    [...] in this podcast. Specifically I was thinking about OAuth. Further information can be found here and [...]

  51. söve Says:

    Our company, Inuda, is now focusing on Twitter application development.

    This comment was originally posted on http://www.readwriteweb.com/)">ReadWriteWeb

  52. HE Says:

    I am really glad to see this auth coming as there are some unscrupulous developers that exploit user password for a variety of uses. This was much needed and was only a matter of time before it became critical.

    Users need this to feel comfortable using apps built off of the api. This will bode will for the long term vision of twitter as a platform. ’bout time ;)

    Large brands and companies that want to build apps off of the api have expressed concerns regarding privacy from a legal standpoint and this will alleviate those concerns.

    http://twitterbusinessbook.com

    Cheers!

  53. ugg Says:

    The service makes it easy for people to find the real you online and can improve your rank on search engines.

  54. izdelava strani Says:

    I’ve read somewhere that the biggest threat is a poor use of password rather than the malicious shareware or suff. But this OAuth looks very useful.

  55. Ashley Says:

    Thanks for the warning. I had my Twitter hacked once and it stunk.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Additional comments powered by BackType