On Mon, Jan 5, 2009 at 8:22 PM, Julio Biason <[email protected]> wrote:

>
> The source parameter means nothing. I can change Mitter to identify
> itself as Twiterrifc, for example. If they take a road like that, some
> spammer can change the parameter to, say, YOUR application and your
> users will flock to something else (but, most probably, spammers won't
> use any source, meaning the source it's the website itself -- which
> proves nothing.)
>

It's no reliable source of identity, but it would allow my users to let me
know if for some reason my own app has been hacked.  Again, this is perhaps
something OAuth could make even more authentic.  I'd just be happy, in the
meantime, to have the field and let apps use it as they please.
Jesse

Reply via email to