My desire for OAuth on Twitter is simple.
As a developer of twitter-related utilities, I don't want to store my
user's twitter credentials.
As has been stated in this thread, even asking for those credentials
is creating bad habits amongst Twitter's user base.
I would never store a user's password for MY site in cleartext, yet
the current API requires me to retrieve an unencrypted credential for
twitter access.

OAuth won't solve identity security issues. I'm not hoping to fix
Twitter's security - just my own practices.
The current pressure Twitter is getting is obviously from users who
have unrealistic expectations about what a new credential system will
mean.
But, in spite of the uninformed panic, there really is an urgent need
for this.

Reply via email to