Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you have any evidence this is a Twitter flaw and not a 3rd party app?


If the twitter security model allows third party apps access to verified high profile accounts without auditing the security of that app it is still a flaw in Twitter's processes.

Twitter after all has a lot higher risk than the 3rd party app, it is in their interest to make sure partners dealing with high profile accounts or partners handling a large volume of accounts are also secure.


OP's point holds. A third party likely has a less-rewarding bug bounty, doesn't it?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: