<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tallying Twitter&#8217;s Application Security Best Practice Violations</title>
	<atom:link href="http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Zero in a bit &#187; How To Protect Your Users From Password Theft</title>
		<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/comment-page-1/#comment-2479</link>
		<dc:creator>Zero in a bit &#187; How To Protect Your Users From Password Theft</dc:creator>
		<pubDate>Mon, 26 Jan 2009 20:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=562#comment-2479</guid>
		<description>[...] you&#8217;re rethinking password storage, it might be a good time to consider other common flubs such as password complexity and brute-force [...]</description>
		<content:encoded><![CDATA[<p>[...] you&#8217;re rethinking password storage, it might be a good time to consider other common flubs such as password complexity and brute-force [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coffee buzz</title>
		<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/comment-page-1/#comment-2435</link>
		<dc:creator>coffee buzz</dc:creator>
		<pubDate>Sat, 10 Jan 2009 03:46:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=562#comment-2435</guid>
		<description>did the Twitter Admin change his password to &quot;sadness&quot; after he was hacked?  haha... ok not funny</description>
		<content:encoded><![CDATA[<p>did the Twitter Admin change his password to &#8220;sadness&#8221; after he was hacked?  haha&#8230; ok not funny</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google inurl: still the quickest way to find 216 million flaws &#171; omg.wtf.bbq.</title>
		<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/comment-page-1/#comment-2427</link>
		<dc:creator>Google inurl: still the quickest way to find 216 million flaws &#171; omg.wtf.bbq.</dc:creator>
		<pubDate>Wed, 07 Jan 2009 17:40:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=562#comment-2427</guid>
		<description>[...] you sent them and hijack their identity and, most likely, their Twitter account because apparently they take security lessons from Oracle, which, for the uninitiated, is like taking gun safety lessons from Plaxico Burress (my 2nd round [...]</description>
		<content:encoded><![CDATA[<p>[...] you sent them and hijack their identity and, most likely, their Twitter account because apparently they take security lessons from Oracle, which, for the uninitiated, is like taking gun safety lessons from Plaxico Burress (my 2nd round [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Eng</title>
		<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/comment-page-1/#comment-2425</link>
		<dc:creator>Chris Eng</dc:creator>
		<pubDate>Wed, 07 Jan 2009 16:10:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=562#comment-2425</guid>
		<description>Fair point, but look at the chaos that ensued a while back when someone posted a fake news item on CNN&#039;s iReport about Steve Jobs&#039; health?  And that was just some Joe Schmo, not even masquerading as an official news outlet.  How much worse would it be if that had been posted on an official source such as &lt;a href=&quot;http://twitter.com/cnn&quot; rel=&quot;nofollow&quot;&gt;@cnn&lt;/a&gt;, &lt;a href=&quot;http://twitter.com/nytimes&quot; rel=&quot;nofollow&quot;&gt;@nytimes&lt;/a&gt;, or even &lt;a href=&quot;http://twitter.com/foxnews&quot; rel=&quot;nofollow&quot;&gt;@foxnews&lt;/a&gt;?  Or all three at the same time?

Twitter stopped being &quot;just a toy&quot; when corporations, celebrities, political figures, news outlets, etc. started using Twitter and other forms of social media as an official PR outlet.  Just because it&#039;s a free service shouldn&#039;t obviate the need for security.  In this day and age, users expect -- and deserve -- a certain level of security and privacy. 
</description>
		<content:encoded><![CDATA[<p>Fair point, but look at the chaos that ensued a while back when someone posted a fake news item on CNN&#8217;s iReport about Steve Jobs&#8217; health?  And that was just some Joe Schmo, not even masquerading as an official news outlet.  How much worse would it be if that had been posted on an official source such as <a href="http://twitter.com/cnn" rel="nofollow">@cnn</a>, <a href="http://twitter.com/nytimes" rel="nofollow">@nytimes</a>, or even <a href="http://twitter.com/foxnews" rel="nofollow">@foxnews</a>?  Or all three at the same time?</p>
<p>Twitter stopped being &#8220;just a toy&#8221; when corporations, celebrities, political figures, news outlets, etc. started using Twitter and other forms of social media as an official PR outlet.  Just because it&#8217;s a free service shouldn&#8217;t obviate the need for security.  In this day and age, users expect &#8212; and deserve &#8212; a certain level of security and privacy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sven Türpe</title>
		<link>http://www.veracode.com/blog/2009/01/tallying-twitters-security-best-practice-violations/comment-page-1/#comment-2422</link>
		<dc:creator>Sven Türpe</dc:creator>
		<pubDate>Wed, 07 Jan 2009 11:27:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=562#comment-2422</guid>
		<description>Shouldn&#039;t you mention that Twitter ist just a toy? Surely there are many things in the security text book that they could do. But would they make sense for a toy?</description>
		<content:encoded><![CDATA[<p>Shouldn&#8217;t you mention that Twitter ist just a toy? Surely there are many things in the security text book that they could do. But would they make sense for a toy?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

