<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: xAuth/OAuth checked into master</title>
	<atom:link href="http://getbuzzbird.com/bb/2010/05/xauthoauth-checked-into-master/feed/" rel="self" type="application/rss+xml" />
	<link>http://getbuzzbird.com/bb/2010/05/xauthoauth-checked-into-master/</link>
	<description>The Awesome Open Source Twitter Client</description>
	<lastBuildDate>Sun, 18 Mar 2012 14:15:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Antonio</title>
		<link>http://getbuzzbird.com/bb/2010/05/xauthoauth-checked-into-master/comment-page-1/#comment-584</link>
		<dc:creator>Antonio</dc:creator>
		<pubDate>Wed, 16 Mar 2011 17:37:28 +0000</pubDate>
		<guid isPermaLink="false">http://getbuzzbird.com/bb/?p=193#comment-584</guid>
		<description>I could even agree with most of your OAuth criticism, but it&#039;s a golden standard compared to asking people for their passwords like Buzzbird and many other apps do. If you share your passwords with anything, machine or human, then you don&#039;t understand basic security or are looking forward to identity theft.

http://adactio.com/journal/1357/</description>
		<content:encoded><![CDATA[<p>I could even agree with most of your OAuth criticism, but it&#8217;s a golden standard compared to asking people for their passwords like Buzzbird and many other apps do. If you share your passwords with anything, machine or human, then you don&#8217;t understand basic security or are looking forward to identity theft.</p>
<p><a href="http://adactio.com/journal/1357/" rel="nofollow">http://adactio.com/journal/1357/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://getbuzzbird.com/bb/2010/05/xauthoauth-checked-into-master/comment-page-1/#comment-204</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 19 Jun 2010 01:40:06 +0000</pubDate>
		<guid isPermaLink="false">http://getbuzzbird.com/bb/?p=193#comment-204</guid>
		<description>Yep. I&#039;m contemplating advertising my key in the title of a blog post just to make a point of how asinine OAuth is. I&#039;ll probably remove it from git (I think Twitter requires that now), but Buzzbird is distributed as a pile of plaintext scripts. It&#039;s the furthest thing from &quot;secret.&quot; Anyone can find it with almost no effort.

Gah.Whatevs.</description>
		<content:encoded><![CDATA[<p>Yep. I&#8217;m contemplating advertising my key in the title of a blog post just to make a point of how asinine OAuth is. I&#8217;ll probably remove it from git (I think Twitter requires that now), but Buzzbird is distributed as a pile of plaintext scripts. It&#8217;s the furthest thing from &#8220;secret.&#8221; Anyone can find it with almost no effort.</p>
<p>Gah.Whatevs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://getbuzzbird.com/bb/2010/05/xauthoauth-checked-into-master/comment-page-1/#comment-203</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 18 Jun 2010 21:36:41 +0000</pubDate>
		<guid isPermaLink="false">http://getbuzzbird.com/bb/?p=193#comment-203</guid>
		<description>Oh look, I went to git-hub, and looked at your source code for Buzzbird and found a consumerKey and consumerSecret. Oh joy, now I can spoof buzzbird...

More like the Oauthflawpocalypse...

Oauth is stupid, flawed, open source desktop app unfriendly ahHhhHHHHhHhhHHhHh!!!!!!!!!!*untold violence*

Just been working on my own open source twitter client, using python + pyqt4, and I&#039;ve been ignoring oAuth for several months. The deadline for basic death appears, and now I face the security flaw brick wall, and than deadline is pushed back, but still, it&#039;s still a serious problem that needs to be resolved before August &gt;_&lt;</description>
		<content:encoded><![CDATA[<p>Oh look, I went to git-hub, and looked at your source code for Buzzbird and found a consumerKey and consumerSecret. Oh joy, now I can spoof buzzbird&#8230;</p>
<p>More like the Oauthflawpocalypse&#8230;</p>
<p>Oauth is stupid, flawed, open source desktop app unfriendly ahHhhHHHHhHhhHHhHh!!!!!!!!!!*untold violence*</p>
<p>Just been working on my own open source twitter client, using python + pyqt4, and I&#8217;ve been ignoring oAuth for several months. The deadline for basic death appears, and now I face the security flaw brick wall, and than deadline is pushed back, but still, it&#8217;s still a serious problem that needs to be resolved before August &gt;_&lt;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

