Nitter is working again
github.com
github.com
I didn't feel like playing around with Twitter's annoying certificate pinning so I just uploaded the Twitter APK to Corellium, turned on what they call the "network monitor", opened the Twitter app since it lets you use Twitter without signing in. I clicked around, searched and viewed tweets. Then I looked at the requests in the log and saw it has a similar guest token process to the website but with a few differences. Anyways, if you recreate these requests, with one IP address you can generate a few OAuth tokens with no expiry per day. These tokens are for unauthenticated users so obviously they have no write privileges but that's not what was needed here. So if you have a proxy provider with a large pool of IPs where you can buy like 1GB of bandwidth you can use a very small percent of your bandwidth allowance and get thousands of tokens/secrets easily, all with their own separate rate limits. It doesn't even matter what IP you end up using the tokens on. Then I followed https://docs.google.com/document/d/1xVrPoNutyqTdQ04DXBEZW4ZW... and the fact that /statuses/lookup.json still allows you to return 100 (!) tweets at once to reconstruct something close to what the 50% Twitter firehose would look like. And Twitter doesn't even block datacenter IP addresses! Was going to display the data at https://firehose.lol but the fact that it required a few hundred requests a second made me feel bad so I didn't end up running the program for more than a few minutes at a time and shut it down.
Looking at (a fraction of) the Firehose for a few minutes was interesting, originally I accidentally forgot to not display tweets labelled possibly_sensitive so I saw some pretty salacious material for a few seconds. Lots of Chinese gambling ads even though Twitter is blocked there, dubious investment promoters, accounts with usernames like FirstnameLastname3781264872 who would tweet three random words at each other every couple of seconds, and a handful of funny tweets.
you can also use the Googlebot user agent to see the page, despite it being a different format
Of course, because if Nitter goes down nobody bats an eye.
I quit twitter when I discovered it. Thank you.
I will admit that since I did remove it from the rotation, I don't see it that often these days, mostly when others link to it and then I navigate to a timeline.
I had my Privacy Redirect plugin redirect Twitter to 0.0.0.0 instead of nitter.lacontrevoie.fr after it got killed.
I just marked them all as read and moved on. I guess this Nitter outage may be the thing that finally pushes me to find the people I follow on other platforms.
Adding almost any restriction only hurts casual users, and attackers are rarely casual users.
one of the richest guys in the world (who's also very anti-union, btw!) buys it up in a time where inequality is getting worse and worse and social fabrics are starting to tear and makes it unusable.
no more space for organizing. one fewer threat to capital.
Putting on a secondary tinfoil hat to prevent stray signals from leaking in: the Simple Sabotage Field Manual suggests that you gum-up the works so to slow things down by a lot. You may not want to make the sabotage obvious, because it'd get fixed immediately (e.g. blow up a factory). Back to the topic: turning off the switch would result in an exodus to other platforms.
[0] https://www.theverge.com/2023/7/7/23787334/instagram-threads...
They said they won't boost these, not that these are forbidden.
Whatever Elmo is doing, it's not working
I’ve been a nitter user for 4 years now and will be as long as it works.
It’s disabled on some instances…
Because in the other github issue thread it seemed like every time they found a way around Twitter's safeguards, it was shutdown.
It seems like they've literally hard coded a token into the source code. Meaning thousands of nitter-instances, thousands of users, around the world, will use the same token.
And potentially so will the AI companies.
So I just don't see how this can work.
https://www.reddit.com/r/fossdroid/comments/10b0krt/comment/...
Or if it does work, its absurdly slow.
Twitter should provide a noscript/basic (x)html interop www portal.
Though Apple is trying to make this harder: https://developer.apple.com/documentation/devicecheck/prepar...
Hope Twitter soon lets go of the temporary login restriction too. Given that this isn't completely blocked without a login, I'd expect that to be not far from now on. From what I've collected, I hope Twitter'd start selling dumps of their public data for a bit of a win/win with AI companies and Twitter itself.
The old token was the twitter web token. I suspect the new one is one of the mobile clients. Maybe new tweetdeck. Though probably the iOS client token makes the most sense, being the hardest to rotate on a whim with app store review.
1: https://developer.apple.com/documentation/uikit/uidevice/162...
The problem is you can't use it for rate limiting because a bad actor could just generate a random ID and use that. That's why an endpoint for validating a given ID was issued for a particular vendor is required for a privacy-preserving anonymous rate limiting implementation.
Either way, you'd surely agree its a noble pursuit? Just considering the wider context here!
>Either way, you'd surely agree its a noble pursuit?
Considering it hurts Twitter's profitability by not showing ads, hurts Twitter's metrics by not having people sign in or sign up, hurts users who were accidently signed out from signing in to twitter and having a better user experience, and hurts content creators because nitter doesn't allow you to like or retweet posts. I do not see it as a noble pursuit.
There's the CFAA, which is a blatantly unfair law targeting any computer activity billionaires don't like. I hear it hasn't been used in this way for a while, and not many times ever, but if it does get used on you you'll wish you were dead, but some people seem to be okay with low-probability high-impact risks. You might even be found innocent if you convince the judge you are authorized to access public tweets. It's not like you're running an SQL injection.
There's the DMCA's anti-circumvention clause, but that's written by Hollywood billionaires for Hollywood-bought judges to abuse. Elon Musk can have a fun time trying to convince them his platform is equivalent to Disney to get a favourably corrupt judgement.
Other than that, what's stopping you from sending any request you like to access public data? You can say your user agent is Snoopy the Dog, you can say you would prefer to accept MIME type ascii/emojipoo, you can pass the server 1000 IDs at once even though it won't give you that many, and you can tell it you're the Twitter app on Android.
Remember: I am not a lawyer and this is not legal advice.
Even if the tweets are public that doesn't mean you can steal an authorization token to use an API to query for them. If you hacked into so server and downloaded /usr/bin/bash you still accessed data you were not authorized to even though it was a public binary.
Twitter's terms of service makes it clear that you aren't allowed to reverse engineer the android app to take its token and start scraping twitter.