ie8 fix
madison

Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!

By | November 12, 2008, 3:00pm PST

Mana from the heavens for cloud sceptics - on a day a lot of professional photographers lost all their images due to the failure of photo hosting site Digital Railroad which went under - as Twitter users fanned their egos en masse to parade their ‘twitterank‘ to their followers.

Twitterrank has no apparent purpose beyond a sketchy numerical rating, and there are rumors circulating on Twitter this afternoon that it is basically a fishing expedition.

I picked up on this after seeing Tantek Çelik retweet:

@t RT @brianoberkirch Twitterank is a vast conspiracy I created to steal all of ur passwords + shame Twitter into OAuthing. + make u look vain.

At the time of this writing I’m not sure what’s going on with Twitterank, but I have to say it is amazing how promiscuous web app users can be with their security details.

This sort of vanity time wasting harms Twitter’s credibility as a useful collaboration and communication tool and adds credence to many IT professional’s doubts about the security of online transactions.

The ‘Twitterank algorithm is vewy vewy secwet‘ - your login details should be as well!

Have you got your twitterank yet and did you read the FAQ to see how secure this was?

Update: a screenshot of the source code by @nateritter (thanks @flashman for the tweet alerting me to this).

Not the most encouraging of images, might be worth changing your password if you checked your twitterank…

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Oliver Marks provides seasoned independent consulting guidance through the Sovos Group to companies on the effective planning of 'Enterprise 2.0' strategy, tactics, technology decisions and roll out.

Disclosure

Oliver Marks

Oliver Marks professional work is defined by an objective viewpoint of the broad spectrum of vendors and options available to his clients and readers of this blog. Oliver provides an impartial perspective of vendors and is focused on contractual affiliation with clients in order to select appropriate solutions. As such he has no business relationships with the companies or services he recommends. Oliver is a founding partner of The Sovos Group. The opinions, concepts and views put forward in this blog are solely those of Oliver Marks.

Biography

Oliver Marks

Oliver Marks is a founding partner at SovosGroup.com which provides seasoned independent consulting guidance to companies on the effective planning of 'Enterprise 2.0' strategy, tactics, technology decisions and roll out.

With extensive senior management practical experience in international enterprise collaboration, Oliver previously managed the Sony PlayStation 'WorldWide Studios' collaboration extranet, and has worked with the American Management Association, Sun, Docent/SumTotal Systems, Harvard Business School and McKinsey & Company on major initiatives around knowledge transfer and change management.

Oliver has dual US/UK citizenship and has worked on Asian, European and American global enterprise collaboration, and spoken at various conferences. He is based in San Francisco.

His personal blog is at www.olivermarks.com.
28
Comments

Join the conversation!

Just In

RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
JACOBSONR 14th Oct
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
0 Votes
+ -
Twitterank
Lacy Kemp 12th Nov 2008
Really, what is the purpose of Twitterank? It's not
like this guy is going to be making money off of the
app, right?
Hey Oliver,

I know the guy who built it. His name is Ryo. He used to
work at Yahoo!

You can email him at ryo@iloha.net if you're interested in,
you know, talking to the fellow.

Or you can read the FAQ and get some of the answers.
Both would probably be better than writing a blog post
based entirely on speculation.

Cheers,
Jesse
I read the FAQ, they are linked in the article.
Oliver,

Great. Next step: talk to the guy. ryo@iloha.net

Cheers,
Jesse
0 Votes
+ -
Hihi, people really used a serious password with twitter? Phishing? Seriously! And then they can be me on Twitter? How about changing your password either before or after using any Twitter related application?

What is really going on is a demonstration how an idea can spread around the twitter net globally. If someone hast gotten Twitter yet, just watching the rate in which people are curious and post back to the their account.
http://search.twitter.com/search?q=twitterank
just watch it increasing the new messages count while you are looking at it.
0 Votes
+ -
Wow!
MGP2 12th Nov 2008
just watch it increasing the new messages count while you are looking at it.

If I ever get tired of watching paint dry, that'll be my next fascination.
A sensible way to use it, if you feel so inclined, is to change your password, update your rank, then change your password back, (or again - to something else.)

Something else to watch for - people putting phony tweets up with outrageous numbers for their twitter rank. They are relatively easy to spot and even easier to check.
What you also can see is how a story like this spreads around the globe, too:-)
http://search.twitter.com/search?q=http%3A%2F%2Ftinyurl.com%2F6kmgul
0 Votes
+ -
Screenshot of code
nate@... 12th Nov 2008
Well the creator is either stealing your usernames and passwords (and blatantly telling everyone so) or he's an idiot and left stupid code comments that say he is..... either way, definitely looks like he's either an idiot, or shady.

screenshot at http://twitpic.com/lfm9 and http://flickr.com/photos/theritters/3026279256/
0 Votes
+ -
Doesn't say he's stealing passwords
Lisa.Brewster 12th Nov 2008
He's not blatantly saying he's stealing passwords.
Looks to me like he considered reminding users to
really evaluate how much they trust a 3rd party asking
for your password. And he's 100% right...you SHOULD be
afraid.
Interestingly enough a similar application
Twitter Influence (http://twinfluence.com/)
has gotten much more positive reaction.

http://www.socialmediatoday.com/SMC/51786
and is trade like a secret... Does the same thing

I guess Oliver Marks doesn't know much about Twitter...
Hey Oliver,

Ryo, the founder of TwitterRank, addressed several of your
concerns, here: http://twitterank.wordpress.com/2008/11/13/some-
follow-up/

I trust you'll update your blog post to reflect the new
information,

Best,
Jesse
0 Votes
+ -
1st Tweets
tweetip 12th Nov 2008
ummmm....seriously folks, chill. There are many other Twitter APIs that ask for passwords that have existed for months now, and there have been no reports of mass pw stealings from them. Check out Twinfluence and Twitter Grader.

He explains it on the home page. The problem is need for OAuth from the Twitter folks.

All this attention is creating mass twisteria!
0 Votes
+ -
You gotta see twitterawesomeness...
Dave21212 12th Nov 2008
It was up today just minutes after twitterrank hit the twitscoop cloud... fast work, and a hilarious site !

http://twitterawesomeness.com/
I'm in ur Twitterz, stealin ur credz!

It was created by @dacort:
Prof. Computer Security Consultant with a passion for breaking things and generating statistics (see http://tweetstats.com and http://ratemytalk.com).
Location: Seattle, WA
Web: http://startupsecurity.info
Twitter: twitter.com/dacort
The herd and ego in social media make for a scary combination. Herd mentality to social media shiny objects & rankings in general amuse me
0 Votes
+ -
Amen AdamZ !
I was had! Just changed my password too!!
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
Thanks nice info z d n e t I really liked your current article write more..let me add you to its favorite The articles you have on zdnet s i t e are always so enjoyable to read. Good work and I bookmarked it.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix