<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.16538-</id>
  <updated>2011-08-16T16:34:01Z</updated>
  <title>Comments for Cartoon: The Worm Has Turned</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=16538" title="Cartoon: The Worm Has Turned" />
    <published>2009-09-27T18:10:27Z</published>
    <updated>2009-09-27T17:41:15Z</updated>
    <title>Cartoon: The Worm Has Turned</title>
    <summary>Last week&apos;s flurry of Twitter DM spam from hacked or phished accounts wasn&apos;t the first instance of that and won&apos;t be the last. As long as people are willing to trust their Twitter log-in information to third parties - and don&apos;t look carefully at URLs before they log into websites - and as long as...</summary>
    <author>
      <name>Rob Cottingham</name>
      
    </author>
    
    <category term="Cartoons" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/imgTwitter.jpg" width="150" height="49" />Last week's flurry of Twitter DM spam from hacked or phished accounts wasn't the first instance of that and won't be the last.</p>

<p>As long as people are willing to trust their Twitter log-in information to third parties - and don't look carefully at URLs before they log into websites - and as long as a small number of bad actors want to pee in the social media swimming pool, this kind of thing will continue happening.</p>]]>
      <![CDATA[<p>And it's not just the log-in-here-and-we-will-steal-your-password.com's of the world you have to worry about. Legitimate third-party services whose security isn't up to snuff could be compromised, and your credentials could be stolen from them. <a href="http://www.readwriteweb.com/archives/why_twitters_new_oauth_matters.php">Twitter's use of OAuth</a> is a big step forward... although the rash of Mobster World spam shows that that isn't a perfect solution either.</p>

<p>Apparently there's no substitute for ruthlessly and constantly policing your own feed, thoroughly investigating services before you sign up for them, double-checking the URL every time you are about to enter info into a form, and regularly purging your <a href="http://twitter.com/account/connections">OAuth settings</a> of services you no longer use.</p>

<p>Also, to be safe, change your password regularly... you don't have to be obsessive about it: every three hours or so should be enough. And because erring on the side of caution is always a good idea, fake your own suicide and change your identity at least once a year.</p>

<p>And you thought Twitter was going to be <em>fun</em>? Slacker.</p>

<p><img src="http://www.readwriteweb.com/images/cartoon_worm_sep09a.gif" width="450" height="498" /></p>

<p><a href="http://www.socialsignal.com/n2s">More Noise to Signal.</a></p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:161413</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c161413" />
    <title>Comment from su arıtma cihazı on 2009-10-06</title>
    <author>
        <name>su arıtma cihazı</name>
        <uri>http://www.prolinesuaritma.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.prolinesuaritma.com">
        <![CDATA[<p>Thanks</p>]]>
    </content>
    <published>2009-10-06T19:50:46Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:160763</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c160763" />
    <title>Comment from iş elbisesi on 2009-10-02</title>
    <author>
        <name>iş elbisesi</name>
        <uri>http://www.ilaydaiselbiseleri.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.ilaydaiselbiseleri.com">
        <![CDATA[<p>2000 yılından bu yana <a href="http://www.ilaydaiselbiseleri.com" rel="nofollow">iş elbiseleri</a>, promosyon ve bilumum proje bazında ve teklif bazında hizmet vermekteyiz. Kurucusu ve sahibi olduğum firmamın bu günlere gelmesinde büyük emeği geçen iş ortaklarıma, derin tecrübelerine ve siz değerli iş ortaklarımıza büyük teşekkür borçlu olan firmam, çalışanları ve ben her gün ve her projede daha bir çok yeniliği tekrar tekrar amatör ruhla kuçaklamaktayız. <br />
İlayda <a href="http://www.ilaydaiselbiseleri.com" rel="nofollow">iş elbisesi</a> Adına Saygılarımla Kürşat Kanburoğlu</p>]]>
    </content>
    <published>2009-10-02T08:55:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:160055</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c160055" />
    <title>Comment from Rob Cottingham on 2009-09-28</title>
    <author>
        <name>Rob Cottingham</name>
        <uri>http://www.socialsignal.com/n2s</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.socialsignal.com/n2s">
        <![CDATA[<p>@blaine - Great comment, and no disagreement from me - I'm leery of authorizing pretty much anything for fear that one of those cringe-worthy "I just became a GOLDEN UNICORN in PRINCESS WORLD!!!" tweets will go out under my name. Er, just an example. Purely hypothetical.</p>

<p>Any of the more technically-minded folks here want to weigh in on Twitter, OAuth and granularity?</p>]]>
    </content>
    <published>2009-09-28T19:43:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:160041</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c160041" />
    <title>Comment from Simon Firth on 2009-09-28</title>
    <author>
        <name>Simon Firth</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Why are the Americans obsessed with making money all the time</p>

<p>We have a saying in the U.K.  What you never have you never miss <br />
And as long as you have good health, enjoy life to the full, spend what you have and enjoy <br />
And remember when you are dead you cant take your money with  you</p>]]>
    </content>
    <published>2009-09-28T18:49:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:159986</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c159986" />
    <title>Comment from Blaine Cook on 2009-09-28</title>
    <author>
        <name>Blaine Cook</name>
        <uri>http://romeda.org/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://romeda.org/">
        <![CDATA[<p>One way Twitter can mitigate some of this is to support more nuanced permissions, and lean on developers to only request elevated access when they need it. For example, disqus does not need read/write access to my Twitter feed, but asks for it anyways.</p>

<p>Most applications should never have access to send DMs (client software being the notable exception), and many shouldn't have access to send updates at all. In any event, these actions should be configurable by users, so even if an app developer wants to be able to send DMs, the user should be able to over-ride that privilege.</p>

<p>I don't authorise many applications, because the increased openness that OAuth has enabled means that app developers are taking greater liberties with the account once they have access. Changing this dynamic would be great for users, and great for Twitter, not to mention broaden people's understanding of how OAuth can be a powerful tool beyond addressing the password anti-pattern.</p>]]>
    </content>
    <published>2009-09-28T14:28:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:159949</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c159949" />
    <title>Comment from Moshe on 2009-09-28</title>
    <author>
        <name>Moshe</name>
        <uri>http://itok.in</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://itok.in">
        <![CDATA[<p>I've heard people that creates hundreds of fake accounts only for spamming/advertising, or to fake popular users with many followers. <br />
That puts Twitter in a very bad light, and expecially if they want to compete with Facebook as "Single-Sign-On" service, like Facebook Connect.</p>

<p>I'm developing a service that is currently using Facebook connnect only, and because of articles like this one, twitter is a big question mark</p>

<p><a href="http://itok.in" rel="nofollow">http://itok.in</a></p>]]>
    </content>
    <published>2009-09-28T09:27:03Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16538-comment:159879</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16538" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/cartoon_the_worm_has_turned.php#c159879" />
    <title>Comment from acido folico on 2009-09-27</title>
    <author>
        <name>acido folico</name>
        <uri>http://www.acidofolico.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.acidofolico.net">
        <![CDATA[<p>Great post and draw. Thank you for sharing.</p>]]>
    </content>
    <published>2009-09-27T22:23:39Z</published>
  </entry>

</feed>
