Contact Get Listed About Us
» Get the feed! Get the Twellow Blog Feed

Twellow And Your Twitter Password

Locked DoorThere has been much talk as of late on several high-profile blogs about a phishing scam and other security issues associated with Twitter and applications that access the Twitter API, such as Twellow. Here at Twellow we are not ignorant of the concerns many of our users have regarding this issue, so I’d like to explain how Twellow uses your sensitive Twitter information, specifically your password.

Twitter API Lead Developer Alex Payne has stated: “If you’re storing the password securely and only using HTTPS, I’d say you’re doing right by your users. In the absence of OAuth, that’s basically best practice. It’s also a pattern that’s been deemed adequate by companies like Amazon, who collect and store financial information from their customers.”

Alex states that passwords should be stored securely. Twellow does not store your Twitter password at all in our database. We only use it to send a simple HTTPS request (that means it’s a secure connection) to the Twitter servers to see if you are actually the owner of your Twitter screen name. This is the approved method for verifying Twitter credentials according to the documentation on Twitter’s API site. Upon verification of your Twitter account, the password is discarded by our system.

Twellow is not a site run by a fly-by-night outfit. We are operated by iEntry, the same folks that produce WebProNews.com and hundreds of other high-traffic websites. WebProNews and the iEntry network have a long history of respected business on the web and a reputation for integrity with our clients and users.

The very nature of social media means users want to find and be found by other people, and Twitter makes this possible in ways not seen before. Authentication schemes can only go so far in protecting your data, and even OAuth would not have prevented the recent security breaches at Twitter. It is ultimately up to you to choose which entities are worthy of your trust. Educate yourself to security risks versus the benefits of interacting in free society. Use that amazing mind which you are blessed with to study and think things out for yourself. I trust my writings here will assist in some small degree with your efforts.

Matthew Daines
Twellow Lead Developer

Update: Twellow now also uses your password to allow you to easily follow or unfollow people directly within our system. Again, your password is not stored in our database, and requests made to Twitter in your behalf are via secure channels.

[del.icio.us] [Facebook] [Google] [LinkedIn] [Sphinn] [StumbleUpon] [Twitter] [Yahoo!] [RSS]

4 Responses to “Twellow And Your Twitter Password”

  1. Learn internet marketing strategy Says:

    Really this information is very useful and thanks for sharing it.

  2. Hubertus Rank Says:

    How Can I register? I don’t understand this procedure?

  3. Kirk Nickey Says:

    I have recently set up two twitter accounts today.
    Then, tried to register them with you using exactly the
    right user name,password,and email.(yes two different emails)
    and they both did not work. Can U help me?
    Do I have to wait to the information to process? (or is it
    done right away.

    Kirk Nickey
    772-545-4999

  4. Matthew Daines Says:

    Hello Kirk,

    In order for our system to find your info on Twitter make sure you have posted at least one “what are you doing?” update to each Twitter account. Also make sure you are not marked as “protected” in your Twitter settings.

    If you have an update posted, are not protected, and are entering the correct Twitter credentials, then it is possible Twitter is experiencing technical problems on their end. These types of problems usually clear up after a few hours, so you might try registering at a later time.

    Cheers,
    Matthew Daines
    Twellow Lead Developer

Leave a Reply

Please stay on-topic! Your entry will be discarded if it is not relevant to this post.

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a