Twitter officially disabled Basic authentication this week, the final step in the company's transition to mandatory OAuth authentication. Sadly, Twitter's extremely poor implementation of the OAuth standard offers a textbook example of how to do it wrong. . This article will explore some of the problems with Twitter's OAuth implementation and some potential pitfalls inherent to the standard. I will also show you how I managed to compromise the secret OAuth key in Twitter's very own official client application for Android. OAuth is an emerging authentication standard that is being adopted by a growing number of social networking services. It defines a key exchange mechanism that allows users to grant a third-party application access to their account without having to provide that application with their credentials. It also allows users to selectively revoke an application's access to their account. Some of the more technical aspects of this article will be easier to understand if you have a basic familiarity with the standard and the problems that it is trying to solve. We published a primer earlier this year that you can refer to if you are looking for additional background information. The article located at arsTechnica is no longer available. . This article will explore some of the problems with Twitter's OAuth implementation and some potentia. twitter, officially, disabled, basic, authentication, final, company's, transiti. . Alex
Guarddog is firewall generation/management utility for KDE on Linux. It allows one to specify which protocols should be allowed and requires no knowledge of port numbers. It is intended for client machines and currently does not support router/gateway configurations. It can generate scripts for ipchains. . . .. Guarddog is firewall generation/management utility for KDE on Linux. It allows one to specify which protocols should be allowed and requires no knowledge of port numbers. It is intended for client machines and currently does not support router/gateway configurations. It can generate scripts for ipchains. RealPlayer support was added. Small changes were made to the GUI to fix a few layout problems. The manual is much more complete, and it now includes a tutorial and FAQ section. The link for this article located at Freshmeat.net is no longer available. . Firewatch offers an intuitive firewall control interface for GNOME, streamlining protocol configuration without requiring port expertise.. Guarddog, Firewall Management, KDE Utility, Client Security, Protocol Specifications. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.