Rethinking authentication for twitter
scripting.com
scripting.com
Yes:
- You're still submitting your password to an untrusted entity. As soon as they have it, they can: (a) change your password and lock you out of your account (b) attempt to use that password for other services you use as most people re-use their passwords
- IP address filtering is useless. The attacker just needs access to a botnet to flood you with requests.
Something OAuth-like is the only way forward: granting revocable, fine-grained access to whatever subset of operations is required for the service in question. Bonus points for being able to undo all operations of a certain type resulting from that third-party access. (i.e. 1-click undo of all DMs, tweets, etc.)
I really hope they make this work soon.
This is exactly what is needed, and what the current "OAuth doesn't solve Phishing!" response misses.
Is there anything out there that is well known and stable?