Compromising Twitter's OAuth security system

Compromising Twitter's OAuth security system

ARSTECHNICA.COM - Twitter officially disabled Basic authentication this week, the final step in the company's transition to mandatory OAuth authentication. Sadly, Twitter's extremely poor implementation of the OAuth standard offers a textbook example of how to do it wrong. This article will explore some of the problems with Twitter's OAuth implementation and some potential pitfalls inherent to the standard. I will…

technologynew
3669

From the Front Page

*
  • Comments
  • Tweets (1374)

Comment

Push this comment to Twitter

Tweets

Sorry there have been no tweets in the last 7 days.

Dedipower