Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
Summary: Mana from the heavens for cloud sceptics - on a day a lot of professional photographers lost all their images due to the failure of photo hosting site Digital Railroad which went under - as Twitter users fanned their egos en masse to parade their 'twitterank' to their followers.Twitterrank has no apparent purpose beyond a sketchy numerical rating, and there are rumors circulating on Twitter this afternoon that it is basically a fishing expedition.
Mana from the heavens for cloud sceptics - on a day a lot of professional photographers lost all their images due to the failure of photo hosting site Digital Railroad which went under - as Twitter users fanned their egos en masse to parade their 'twitterank' to their followers.
Twitterrank has no apparent purpose beyond a sketchy numerical rating, and there are rumors circulating on Twitter this afternoon that it is basically a fishing expedition.
I picked up on this after seeing Tantek Çelik retweet:
@t RT @brianoberkirch Twitterank is a vast conspiracy I created to steal all of ur passwords + shame Twitter into OAuthing. + make u look vain.
At the time of this writing I'm not sure what's going on with Twitterank, but I have to say it is amazing how promiscuous web app users can be with their security details.
This sort of vanity time wasting harms Twitter's credibility as a useful collaboration and communication tool and adds credence to many IT professional's doubts about the security of online transactions.
The 'Twitterank algorithm is vewy vewy secwet' - your login details should be as well!
Have you got your twitterank yet and did you read the FAQ to see how secure this was?
Update: a screenshot of the source code by @nateritter (thanks @flashman for the tweet alerting me to this).
Not the most encouraging of images, might be worth changing your password if you checked your twitterank...
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
Twitterank
like this guy is going to be making money off of the
app, right?
RE: Gullible Twitter users hand over their usernames and passwords - did yo
I know the guy who built it. His name is Ryo. He used to
work at Yahoo!
You can email him at ryo@iloha.net if you're interested in,
you know, talking to the fellow.
Or you can read the FAQ and get some of the answers.
Both would probably be better than writing a blog post
based entirely on speculation.
Cheers,
Jesse
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
RE: Gullible Twitter users hand over their usernames and passwords - did yo
Great. Next step: talk to the guy. ryo@iloha.net
Cheers,
Jesse
RE: Gullible Twitter users hand over their usernames and passwords - did yo
What is really going on is a demonstration how an idea can spread around the twitter net globally. If someone hast gotten Twitter yet, just watching the rate in which people are curious and post back to the their account.
http://search.twitter.com/search?q=twitterank
just watch it increasing the new messages count while you are looking at it.
Wow!
If I ever get tired of watching paint dry, that'll be my next fascination.
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
Something else to watch for - people putting phony tweets up with outrageous numbers for their twitter rank. They are relatively easy to spot and even easier to check.
RE: Gullible Twitter users hand over their usernames and passwords - did yo
http://search.twitter.com/search?q=http%3A%2F%2Ftinyurl.com%2F6kmgul
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
http://www.evliving.com/2008/11/12/1669/twitterank-what-is-twitterank/
http://news.google.com/news?q=twitterank
http://blogsearch.google.com/blogsearch?q=twitterank
http://www.google.com/search?q=twitterank
Screenshot of code
screenshot at http://twitpic.com/lfm9 and http://flickr.com/photos/theritters/3026279256/
Doesn't say he's stealing passwords
Looks to me like he considered reminding users to
really evaluate how much they trust a 3rd party asking
for your password. And he's 100% right...you SHOULD be
afraid.
RE: Gullible Twitter users hand over their usernames and passwords - did yo
Twitter Influence (http://twinfluence.com/)
has gotten much more positive reaction.
http://www.socialmediatoday.com/SMC/51786
and is trade like a secret... Does the same thing
I guess Oliver Marks doesn't know much about Twitter...
RE: Gullible Twitter users hand over their usernames and passwords - did yo
Ryo, the founder of TwitterRank, addressed several of your
concerns, here: http://twitterank.wordpress.com/2008/11/13/some-
follow-up/
I trust you'll update your blog post to reflect the new
information,
Best,
Jesse
1st Tweets
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
He explains it on the home page. The problem is need for OAuth from the Twitter folks.
All this attention is creating mass twisteria!
RE: Gullible Twitter users hand over their usernames and passwords - did yo
That's Journalism.
You gotta see twitterawesomeness...
http://twitterawesomeness.com/
I'm in ur Twitterz, stealin ur credz!
It was created by @dacort:
Prof. Computer Security Consultant with a passion for breaking things and generating statistics (see http://tweetstats.com and http://ratemytalk.com).
Location: Seattle, WA
Web: http://startupsecurity.info
Twitter: twitter.com/dacort
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!
That must be why this starts with TWIT?
RE: Gullible Twitter users hand over their usernames and passwords - did you get your Twitterank yet?!