<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet Business &#38; Marketing Strategy - Andy Beard &#187; oauth</title>
	<atom:link href="http://andybeard.eu/tag/oauth/feed" rel="self" type="application/rss+xml" />
	<link>http://andybeard.eu</link>
	<description>Internet Marketing, Lead Acquisition, Online Business Strategy and Social Media with Original Opinion and Loads of Attitude</description>
	<lastBuildDate>Sun, 12 Feb 2012 06:16:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Twitter&#8230; About Password Security &amp; OAuth</title>
		<link>http://andybeard.eu/2926/twitter-passwords.html</link>
		<comments>http://andybeard.eu/2926/twitter-passwords.html#comments</comments>
		<pubDate>Sun, 15 Aug 2010 08:22:18 +0000</pubDate>
		<dc:creator>Andy Beard</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[web 2.0]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[tell-a-friend]]></category>
		<category><![CDATA[tellafriend]]></category>
		<category><![CDATA[viral inviter]]></category>
		<category><![CDATA[viral marketing]]></category>

		<guid isPermaLink="false">http://andybeard.eu/?p=2926</guid>
		<description><![CDATA[
<p>People sharing Twitter passwords with rogue friend apps has been a problem for a few years &#8211; I have written quite a few posts warning people of the dangers of sharing passwords with insecure apps, and have also been critical of giant social networks continuing the practice of scraping data from other services using standard password authentication.</p>
<p><a href="http://andybeard.eu/2926/twitter-passwords.html" class="more-link">Read more on Twitter&#8230; About Password Security &#038; OAuth&#8230;</a></p>
<div class="topsy_widget_data topsy_theme_brick-red" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fandybeard.eu%252F2926%252Ftwitter-passwords.html%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FanAAEW%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Twitter...%20About%20Password%20Security%20%26%20OAuth%22%20%7D);"></div>


	Tags: <a href="http://andybeard.eu/tag/oauth" title="oauth" rel="tag">oauth</a>, <a href="http://andybeard.eu/tag/tell-a-friend" title="tell-a-friend" rel="tag">tell-a-friend</a>, <a href="http://andybeard.eu/tag/tellafriend" title="tellafriend" rel="tag">tellafriend</a>, <a href="http://andybeard.eu/tag/viral-inviter" title="viral inviter" rel="tag">viral inviter</a>, <a href="http://andybeard.eu/tag/viral-marketing" title="viral marketing" rel="tag">viral marketing</a><br />
]]></description>
			<content:encoded><![CDATA[
<p>People sharing Twitter passwords with rogue friend apps has been a problem for a few years &#8211; I have written quite a few posts warning people of the dangers of sharing passwords with insecure apps, and have also been critical of giant social networks continuing the practice of scraping data from other services using standard password authentication.</p>
<p>Thus I am glad to see <a href="http://techcrunch.com/2010/08/13/oauthpocalypse/">Twitter will switch off</a> access to their API using standard authentication of username and password, and providing access only by OAuth.</p>
<p>For that I applaud the Twitter team for taking a positive step for online security.</p>
<h2>Do As I Say, Not As I Do?</h2>
<p>Twitter are still scraping friend information from email accounts.</p>
<p><img src="http://cdn5.andybeard.name/wp-content/uploads/twitter-find-friends.png" alt="Twitter Find Friends" title="twitter-find-friends" width="600" height="454" class="aligncenter size-full wp-image-2927" /></p>
<p>It doesn&#8217;t matter what they claim they scrape, or that they claim to not store the information</p>
<ul>
<li>Not using OAuth is now totally hypocritical</li>
<li>Twitter have been hacked in the past</li>
<li>A few hundred million people giving up their email passwords is quite a valuable target</li>
</ul>
<p>I realise Facebook only fixed their Friend Finding / Tell-A-Friend system after they purchased Octazen (and shut it down to new customers), but if Twitter expect their developers to use OAuth, the least they should do is use it themselves.</p>
<h2>Update</h2>
<p>Just saw this in Facebook &#8211; I know that Skype contacts are hardly the key to your online business like a Gmail account, but I thought they were finally past all this account scraping crap.</p>
<p><img src="http://cdn5.andybeard.name/wp-content/uploads/facebook-privacy-sucks.png" alt="Facebook privacy" title="facebook-privacy-sucks" width="529" height="211" class="aligncenter size-full wp-image-2931" /></p>
<p>Facebook sucks for privacy again&#8230; well even more&#8230; well you know.</p>
<div class="topsy_widget_data topsy_theme_brick-red" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fandybeard.eu%252F2926%252Ftwitter-passwords.html%22%2C%20%22shorturl%22%3A%20%22http%3A%2F%2Fbit.ly%2FanAAEW%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Twitter...%20About%20Password%20Security%20%26%20OAuth%22%20%7D);"></div>


	Tags: <a href="http://andybeard.eu/tag/oauth" title="oauth" rel="tag">oauth</a>, <a href="http://andybeard.eu/tag/tell-a-friend" title="tell-a-friend" rel="tag">tell-a-friend</a>, <a href="http://andybeard.eu/tag/tellafriend" title="tellafriend" rel="tag">tellafriend</a>, <a href="http://andybeard.eu/tag/viral-inviter" title="viral inviter" rel="tag">viral inviter</a>, <a href="http://andybeard.eu/tag/viral-marketing" title="viral marketing" rel="tag">viral marketing</a><br />
]]></content:encoded>
			<wfw:commentRss>http://andybeard.eu/2926/twitter-passwords.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Viral Tell-A-Friend Thats Safe For Your Granny or CEO</title>
		<link>http://andybeard.eu/2196/secure-viral-tell-a-friend-2.html</link>
		<comments>http://andybeard.eu/2196/secure-viral-tell-a-friend-2.html#comments</comments>
		<pubDate>Sat, 12 Sep 2009 09:06:07 +0000</pubDate>
		<dc:creator>Andy Beard</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[Octazen]]></category>
		<category><![CDATA[tell-a-friend]]></category>
		<category><![CDATA[tellafriend]]></category>
		<category><![CDATA[viral inviter]]></category>
		<category><![CDATA[viral marketing]]></category>
		<category><![CDATA[viral optin generator]]></category>

		<guid isPermaLink="false">http://andybeard.eu/?p=2196</guid>
		<description><![CDATA[I have been ranting and raving about insecure viral Tell-A-Friend scripts for over a year, and it seemed like I was just talking to a brick wall.

Now in the space of just a week I have been able to highlight a solution based upon one of my own blog posts that uses a slightly ghetto, but K.I.S.S method to achieve extremely <a href="http://andybeard.eu/2128/sales-funnel.html">effective viral tell-a-friend functionality</a>, and now I want to mention another more sophisticated solution.]]></description>
			<content:encoded><![CDATA[
<p>I have been ranting and raving about insecure viral Tell-A-Friend scripts for over a year, and it seemed like I was just talking to a brick wall.</p>
<p>Now in the space of just a week I have been able to highlight a solution based upon one of my own blog posts that uses a slightly ghetto, but K.I.S.S method to achieve extremely <a href="http://andybeard.eu/2128/sales-funnel.html">effective viral tell-a-friend functionality</a>, and now I want to mention another more sophisticated solution.</p>
<p>In my last post I mention that <a href="http://andybeard.eu/series/stomper999">Stompernet</a> currently have an offer to get their <a href="http://andybeard.eu/2192/stompernet-free.html">Stomping The Search Engines STSE2 SEO Course 100% Free</a> with no credit card requirements.</p>
<p>Now if I am going to state that something is 100% free, I really want to be sure that there are no strings attached.</p>
<p>So I tested the signup procedure and created an account for my wife.</p>
<h2>Stompernet Tell-A-Friend Process</h2>
<p><img src="http://cdn5.andybeard.name/wp-content/uploads/StomperNet-Tell-A-Friend.jpg" alt="StomperNet Tell-A-Friend" title="StomperNet Tell-A-Friend" width="500" height="744" class="aligncenter size-full wp-image-2199" /></p>
<p>As you can see, lots of import options, and whilst a few of them do require username/password, the most important business centric address for online marketers, Google, uses an API hosted by Google.</p>
<p>Remember, Google Account is Key To:-</p>
<ul>
<li>Gmail (Paypal, Domain registration, Hosting)</li>
<li>Adwords</li>
<li>Analytics</li>
<li>Adsense</li>
<li>Private Calendar</li>
</ul>
<p>Entering your email and password into a form on a 3rd party site is a security liability.</p>
<p>Asking your customers to do it is a security liability for them, thus a business liability for you.</p>
<p><strong>Stompernet are the first in the &#8220;Internet Marketing&#8221; niche that I am aware of to use a legitimate, safe process for gathering contacts for use with incentive based Tell-A-Friend, and do it better than Twitter, Facebook &#038; LinkedIn.</strong></p>
<p><img src="http://cdn5.andybeard.name/wp-content/uploads/Stompernet-Need-To-Register.jpg" alt="" title="" width="500" height="409" class="aligncenter size-full wp-image-2197" /></p>
<p>Probably due to time constraints, one visible blooper is that they haven&#8217;t registered with Google (I am not sure of the procedure), and it might take a while to process.</p>
<p><img src="http://cdn5.andybeard.name/wp-content/uploads/StomperNet-Email-To-Friends.jpg" alt="StomperNet-Email-To-Friends" title="StomperNet-Email-To-Friends" width="500" height="584" class="aligncenter size-full wp-image-2198" /></p>
<p>Here is the email that gets sent to your friends.</p>
<p>It would be good if there was a way to edit it before sending</p>
<h2>I Skipped Something</h2>
<p>The observant will notice I skipped the import stage as I felt it wrong to crop the image, for impact. Whilst I am on a lot of email lists, and have a fair few contacts, I don&#8217;t think this situation is unusual.</p>
<p>This is going to be a usability issue with almost any primary email account used by an online marketer., unless they are ruthless with their email list pruning.<br />
The more <a href="http://andybeard.eu/2128/sales-funnel.html">ghetto</a> version doesn&#8217;t have this usability issue, because emails are filled out within the native email interface.</p>
<p>The script that Stompernet are using is <a href="http://andybeard.eu/Octazen.htm">Octazen</a> which looks very capable, and they list lots of social networks among their customers. They also have a WordPress plugin though I am not sure of the capabilities &#8211; something I will be looking into myself.<br />
I have no idea why so many sites still ask for passwords. Maybe they are using an old version of the script that doesn&#8217;t use the APIs for some reason.<br />
I must admit that acted as a negative advert for them &#8211; I had been to the site previously, seen the logos for Twitter and LinkedIn &#8211; remembered how bad their systems were asking for Gmail passwords, and just ignored them.</p>
<p>Oh&#8230; that list of contacts &#8211; this rivalled John Reese&#8217;s 40 page Traffic Secrets sales letter&#8230; around 40 pages in this screenshot, though that only takes us up to letter &#8220;T&#8221; &#8211; my screengrab software was having problems with a file over 30,000 pixels high.</p>
<div id="attachment_2200" class="wp-caption aligncenter" style="width: 160px"><img src="http://cdn5.andybeard.name/wp-content/uploads/Confirm-Your-email-address-999-StomperNet_1252718584302.jpg" alt="Gmail Imported Email Addresses" title="Email Addresses Imported From Gmail" width="150" height="4145" class="aligncenter size-full wp-image-2200" /><p class="wp-caption-text">Gmail Imported Email Addresses</p></div>
<div class="topsy_widget_data topsy_theme_brick-red" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fandybeard.eu%252F2196%252Fsecure-viral-tell-a-friend-2.html%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Viral%20Tell-A-Friend%20Thats%20Safe%20For%20Your%20Granny%20or%20CEO%22%20%7D);"></div>


	Tags: <a href="http://andybeard.eu/tag/oauth" title="oauth" rel="tag">oauth</a>, <a href="http://andybeard.eu/tag/octazen" title="Octazen" rel="tag">Octazen</a>, <a href="http://andybeard.eu/tag/tell-a-friend" title="tell-a-friend" rel="tag">tell-a-friend</a>, <a href="http://andybeard.eu/tag/tellafriend" title="tellafriend" rel="tag">tellafriend</a>, <a href="http://andybeard.eu/tag/viral-inviter" title="viral inviter" rel="tag">viral inviter</a>, <a href="http://andybeard.eu/tag/viral-marketing" title="viral marketing" rel="tag">viral marketing</a>, <a href="http://andybeard.eu/tag/viral-optin-generator" title="viral optin generator" rel="tag">viral optin generator</a><br />
]]></content:encoded>
			<wfw:commentRss>http://andybeard.eu/2196/secure-viral-tell-a-friend-2.html/feed</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>Twitter Security Hypocrisy</title>
		<link>http://andybeard.eu/2059/twitter-security-hypocrisy.html</link>
		<comments>http://andybeard.eu/2059/twitter-security-hypocrisy.html#comments</comments>
		<pubDate>Wed, 15 Jul 2009 21:56:45 +0000</pubDate>
		<dc:creator>Andy Beard</dc:creator>
				<category><![CDATA[marketing]]></category>
		<category><![CDATA[web 2.0]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[taf]]></category>
		<category><![CDATA[tell-a-friend]]></category>
		<category><![CDATA[tellafriend]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://andybeard.eu/?p=2059</guid>
		<description><![CDATA[Twitter get Gmail and Google Apps hacked, but expose their customers to a similar danger]]></description>
			<content:encoded><![CDATA[
<p><a href="http://blog.twitter.com/2009/07/twitter-even-more-open-than-we-wanted.html" target="_blank">If Twitter were really serious</a> about the dangers of sharing access to Gmail accounts, and thus their personal documents on Google Apps, they wouldn&#8217;t continue to encourage people to hand over their email passwords just to tell their friends about Twitter or find existing friends on the service.</p>
<div id="attachment_2060" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-2060" title="twitter-security" src="http://cdn5.andybeard.name/wp-content/uploads/twitter-security.png" alt="Allow Twitter to Scrape Your Personal Information In Gmail" width="500" height="328" /><p class="wp-caption-text">Allow Twitter to Scrape Your Personal Information In Gmail</p></div>
<p>I have written extensively about the problems associated with <a href="http://andybeard.eu/1556/twitter-viral-hell-with-launch-tree.html">Viral Tell-A-Friend</a> systems. People are becoming careless with personal and business security, and soon adding an email and password to a box will be as common as handing over an email address&#8230; but with dire consequences.</p>
<p>My opinion,<a href="http://www.techcrunch.com/2009/07/15/our-reaction-to-your-reactions-on-the-twitter-confidential-documents-post/"> Techcrunch shouldn&#8217;t publish what they found in Twitter&#8217;s undie drawer</a>&#8230; but only with the provision that they remove the hypocritical viral tell-a-friend, and encourage other startups to do the same&#8230; until they learn to use APIs correctly.</p>
<p><a href="http://dopplr.com">Dopplr</a> manage  to use APIs for TAF without the massive funding, and Gigya seem to have some API support.</p>
<p>Let something good come of this, and get all major social sites to stop scraping 3rd party accounts as well.</p>
<div class="topsy_widget_data topsy_theme_brick-red" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fandybeard.eu%252F2059%252Ftwitter-security-hypocrisy.html%22%2C%20%22style%22%3A%20%22small%22%2C%20%22title%22%3A%20%22Twitter%20Security%20Hypocrisy%22%20%7D);"></div>


	Tags: <a href="http://andybeard.eu/tag/api" title="api" rel="tag">api</a>, <a href="http://andybeard.eu/tag/gmail" title="gmail" rel="tag">gmail</a>, <a href="http://andybeard.eu/tag/google" title="Google" rel="tag">Google</a>, <a href="http://andybeard.eu/tag/oauth" title="oauth" rel="tag">oauth</a>, <a href="http://andybeard.eu/tag/taf" title="taf" rel="tag">taf</a>, <a href="http://andybeard.eu/tag/tell-a-friend" title="tell-a-friend" rel="tag">tell-a-friend</a>, <a href="http://andybeard.eu/tag/tellafriend" title="tellafriend" rel="tag">tellafriend</a>, <a href="http://andybeard.eu/tag/twitter" title="twitter" rel="tag">twitter</a><br />
]]></content:encoded>
			<wfw:commentRss>http://andybeard.eu/2059/twitter-security-hypocrisy.html/feed</wfw:commentRss>
		<slash:comments>38</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: basic
Database Caching 33/53 queries in 0.012 seconds using disk: basic
Object Caching 1083/1116 objects using disk: basic
Content Delivery Network via cdn5.andybeard.name

Served from: andybeard.eu @ 2012-02-13 00:46:20 -->
