{"id":8254,"date":"2013-05-20T14:44:33","date_gmt":"2013-05-20T04:44:33","guid":{"rendered":"http:\/\/michaelwyres.com\/?p=8254"},"modified":"2013-05-20T14:44:33","modified_gmt":"2013-05-20T04:44:33","slug":"news-limited-seeks-excess-access-to-your-social-media-accounts","status":"publish","type":"post","link":"https:\/\/michaelwyres.com.au\/mwdc\/2013\/05\/news-limited-seeks-excess-access-to-your-social-media-accounts\/","title":{"rendered":"News Limited Seeks Excess Access To Your Social Media Accounts"},"content":{"rendered":"<p>With the News Limited mastheads moving to the &#8220;<a target=\"_blank\" href=\"http:\/\/en.wikipedia.org\/wiki\/Paywall\">metered paywall<\/a>&#8221; model for their online activities, I curiously checked out what sort of information they might want to sign-up as a registered user.<\/p>\n<p>I was a bit surprised.<\/p>\n<p><\/p>\n<p>When signing up using your Twitter account, they want access to &#8220;read tweets from your timeline&#8221;, &#8220;see who you follow, <b>and follow new people<\/b>&#8220;, &#8220;<b>update your profile<\/b>&#8220;, and &#8220;<b>post tweets for you<\/b>&#8220;.<\/p>\n<p>I wouldn&#8217;t be too fussed about &#8220;read tweets from your timeline&#8221; and &#8220;see who you follow&#8221;, as unless your profile is private\/locked, they can just do that anyway.<\/p>\n<p>Anyone can.<\/p>\n<p>I find to be able to &#8220;post tweets for you&#8221; something of a worry.  It means they can post anything they like and have it appear to have <i>come from you<\/i>.<\/p>\n<p>I&#8217;m sure they don&#8217;t want to do anything malicious with that power, most likely wanting to just post links to stories you&#8217;ve enjoyed, and liked through icons on their various sites.<\/p>\n<p>The crux of the problem here is that if anyone breaks into their systems and steals all the <a target=\"_blank\" href=\"http:\/\/en.wikipedia.org\/wiki\/Oauth\">OAuth<\/a> keys people give to News Limited by signing up this way, those hackers might not be so nice.<\/p>\n<p>A big collection of Twitter OAuth keys would be most attractive to hackers.<\/p>\n<p>How confident can we be that their systems are secure enough to protect all those keys from being stolen and misused?<\/p>\n<p>However, I find giving them the ability to &#8220;update your profile&#8221; and &#8220;follow new people&#8221; a bit stunning actually.<\/p>\n<p>Why would they be interested in updating your profile?  Why do they want to be able to make you follow new people?<\/p>\n<p>As for following new people, News Limited presumably want to get you to follow their various Twitter accounts automatically &#8211; but what possible purpose would they have for updating your profile?<\/p>\n<p>Now, of course, we don&#8217;t know if they would ever use those powers explicitly, but then it gets back to the safety of those keys.<\/p>\n<p>If someone gets a hold of them, all hell could &#8211; (and probably would) &#8211; break loose.<\/p>\n<p>A hacker might get to use YOUR account to spread whatever message they want, to all your followers.<\/p>\n<p>In an extreme case, a Murdoch-governed media entity might even try to spread propaganda through your account, in the lead up to an election.<\/p>\n<p>Far fetched?  Maybe.  Probably.<\/p>\n<p>But we know the Murdoch press around the world don&#8217;t necessarily follow <a target=\"_blank\" href=\"http:\/\/en.wikipedia.org\/wiki\/News_International_phone_hacking_scandal\">the bounds of decency or the law<\/a>.  The same Murdoch who is <a target=\"_blank\" href=\"http:\/\/www.theage.com.au\/opinion\/political-news\/the-real-word-about-whitlam-20130408-2hh5k.html\">known to have actively &#8220;assisted&#8221; in the downfall of the Whitlam Government in 1975<\/a>:<\/p>\n<blockquote><p>&#8220;So did Rupert Murdoch and prime minister Malcolm Fraser, who were working hand in glove in an effort to destroy Whitlam politically.&#8221;<\/p><\/blockquote>\n<p>If you&#8217;ve signed up this way already, you should <a target=\"_blank\" href=\"https:\/\/twitter.com\/settings\/applications\">consider revoking the access<\/a> you have given them.  They seek similar access through Facebook signup.<\/p>\n<p>Unless I trust News Limited completely &#8211; (both to be good citizens, and to protect their data) &#8211; I wouldn&#8217;t be authorising them &#8211; (or anyone who steals their data) &#8211; to basically become me on my social media accounts.<\/p>\n<p>I don&#8217;t, and neither should you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the News Limited mastheads moving to the &#8220;metered paywall&#8221; model for their online activities, I curiously checked out what sort of information they might want to sign-up as a registered user. I was a bit surprised. When signing up using your Twitter account, they want access to &#8220;read tweets from your timeline&#8221;, &#8220;see who [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[379,420,475,561],"class_list":["post-8254","post","type-post","status-publish","format-standard","hentry","category-media","tag-newslimited","tag-paywall","tag-security","tag-twitter"],"_links":{"self":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts\/8254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/comments?post=8254"}],"version-history":[{"count":0,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/posts\/8254\/revisions"}],"wp:attachment":[{"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/media?parent=8254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/categories?post=8254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michaelwyres.com.au\/mwdc\/wp-json\/wp\/v2\/tags?post=8254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}