Friday, December 17, 2010

Twitter Security Issue

So suppose you've used a temporary PC/net/notebook to run TweetDeck

Now, you release such old machine, and do a favor to yourself changing your twitter account password (as you should do with all other "static" passwords like emails, websites, etc)

I've verified that TweetDeck 0.36.1 still logs in twitter account using the old password (I don't know how long this last, if it is a kind of a temporary threat, as I've tested immediately after changing password at website)

In order to stop the old machine from being able to login into your twitter account, YOU MUST:

1- login twitter website
2- go to settings > connections
3- go to TweetDeck then click over "revoke access" - DO NOT click "undo revoke access" under any circumstances

Only after that you'll see Twitter rejecting TweetDeck old password and requiring new credentials

Note that when using Twitter website the password change takes effect immediately, leading the user to believe his account is safe.

But the thing can be worst...

This happens not only with TweetDeck, but with ALL THE TWITTER CONNECTIONS like twitter for android, linkedin, etc - as far as I've verified.

(maybe this is a known issue as I still need to check)

No comments:

Post a Comment

deixe sua opinião