Devil’s advocate on Twitter’s OAuth change
marco.org
marco.org
When they surprised us with this, they claimed it was because most users didn't realize that they gave up that level of access to their account. This change allows them too, but at the cost of bad UX for mobile and native apps, while breaking all existing apps so far.
They moved the deadline back 2 weeks. That gives you less than 4 weeks to make the changes and if it's iOS, you have to get the app approved by Apple which takes 1 to 3 weeks (accounting for one possible reject and Apple being slow).
Then you have to hope that all your users upgrade right away and when they do upgrade they have to reauth everything again with the crappy experience.
These UX issues were what drove the design of xAuth in the first place durning the basic auth switch. xAuth was manually approved and was for clients and not for services that had a web side. These clients are more likely to need DM than most simple web app tools, but xAuth retroactively and going forward doesn't get DMs.
This will break TweetBot, older Seesmic clients, Twitalator, Twitterific, TweetDeck, TwitDroid, etc. Even the official Twitter client (formally Tweetie) would break because it uses xAuth but I'm sure they are hard coding exceptions for different clients.
This is to clarify permissions users are giving third parties. With the official client, there is no third party.
An interesting contention on their part, considering Twitter clients don't exactly hide the fact that they handle direct messages within the apps.
Thats seems like the point.
I don't know if Twitter's particular changes here are desirable or not. But if company is also providing a messaging utility that millions of people contribute content to and that other provide enhancements to, then "we" sure as heck should criticizing what it is does, deciding whether it is worth "our" while and so forth. If "we" don't, "we" will become serfs to those convenient information providers.
Certainly, "twitter isn't ours" so we can't sue them or immediately fire whoever made this decision. Our options include accept-whatever-without-a-beep(or-a-tweet), criticize and suck-it-up as well as criticize-and-abandon. And latter options seem reasonable.
Remember this quote: "If you are not the customer, you are the product."?
What happens to businesses who ignore their customer base? They lose them. I hope you don't operate your own business with an attitude such as that.
If you want to look at it as they're losing inventory, fine. There's no difference.
Stupidity would be breaking their own clients, too. Stupidity doesn't seem to adequately explain their commitment to going forward with this change, so we turn to Occam's Razor. The simplest apparent explanation for the observed behavior is that they want to discourage the use of third-party clients.
in between you have 11 days to test.
* http://donpark.org/blog/2009/01/24/android-client-side-oauth
This time it was just a twitter-dick-move©, but tomorrow it could be a security vulnerability being exploited massively in the wild and you will not be able to provide a timely response.
i'm not saying that the android model is better. i'm all for no control. i'd ditch both if i could.
My sympathy is limited towards Twitter app developers -- you were warned a while ago, you've had plenty of time to figure out the new system, and it's really not that painful.
xAuth is OAuth but doesn't require a web based interaction to authorize. With xAuth, apps ask for a username and pass but get a token and only store the token (instead of storing the username and pass like with basic auth). This was created to help with UX of non-webapps like mobile and desktop. The first release of xAuth was Seesmic Look which was after basic auth was in the count to shutdown. xAuth is only given to apps that are approved by Twitter that prove that they are not a web service and need the improved UX.
The issue is that these apps are usually clients that desktop and mobile and probably need DM access, but xAuth clients can't ask for DM access (they are only allowing that access to clients that web auth).
xAuth is now having functionality removed with very little warning.
* Twitter supported basic auth only.
* Twitter forced all new apps, including native apps, to use OAuth. Existing basic auth apps were allowed to continue working without modification.
* Twitter rolled out xAuth specifically to allow native app developers to provide non-shitty user experiences.
* Twitter finally forced all apps off of basic auth. I don't think there's a single native app that chose the web-based OAuth workflow over xAuth.
They were at one point in a position to move forward with only the OAuth web flow, but they chose to roll out xAuth after they were requiring all new apps to use the OAuth web flow.
Now they're taking away privileges from xAuth apps without providing a solution to the problem xAuth was created to solve in the first place. And they're giving developers 2 weeks to figure out what to do and do it.
It's not surprising that developers are upset.