TweetFollow @simoncolijn

Twitter authorization leak.

You all know those apps which want to authorize with your Twitter account. Well, after seeing this you might to think twice when being asked!

These apps are actually authorized to read your private messages. And when they save your 'secret token' they are able to check your data at any time. It's just a simple test, so your data won't be stored, shared or whatsoever!

This feature in the Twitter authorization is pretty insane and I don't get it why that leak is still open! This page is to show how insecure Twitter Authorization is.
So (re)tweet this page and let's hope Twitter will fix it anytime soon!

First..

Check out these images, in the backend of my app it says I will only be able to read your 'normal' content, not your private messages. Sure, it does take some minutes to fix it...


Second and last..

See how it works →