Show HN: I built a service to find cool people on Github
githubfriends.swizec.com
githubfriends.swizec.com
Relevant: http://swizec.com/blog/small-trick-for-seamless-base64-passw...
His post was about sites that DO NOT do OAUTH, and the only way to store passwords to interface with those sites. He clearly states how insecure it is, and the base64 thing is only to prevent you from reading their password accidentally.
Twitter, however, DOES use OAUTH. There's no need to store your twitter password on his side at all.
His auth page is down right now so I can't check, but I'm betting that it ends up at a twitter.com OAUTH page that is perfectly safe.
When dealing with security, this sort of practice should be avoided at all costs e.g. a sacrifice to the functionality of your product.
I don't understand how that could happen. Twitter's OAuth implementation seems fairly sound.
Where would you look instead?
Could be cool to get a list of alternative ways to twitter and facebook.
Are other sites having profiles that could be accessed such as SO etc?
I'm not sure where you'd get a list like this (maybe you'd just create your own) but I think linking people to common languages (i.e. python guys to python guys) and similar projects/interests they like would have a higher correlation.