• Twitter

Saved searches

  • Remove
  • Verified account @
Suggested users
  • Verified account @
  • Verified account @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Čeština
    • Dansk
    • Deutsch
    • EnglishUK
    • Español
    • Filipino
    • français
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • română
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Русский
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • हिन्दी
    • বাংলা
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in New to Twitter? Join Today »
    Log in

    Forgot password?
    Already using Twitter via text message?

  1. Egor Homakov ‏@homakov Dec 14

    Twitter trick - you can ask your readers to tweet about your post, but in fact send a DM. Example https://twitter.com/intent/tweet?text=d+homakov+u+smart …

    Expand Collapse 0 replies 10 retweets 3 favorites
  2. DaKnOb ‏@DaKnObCS Dec 14

    @homakov @l33tdawg I discover this over a year ago and none bats an eye.. :P

    Expand Collapse 0 replies 0 retweets 0 favorites
  3. Egor Homakov ‏@homakov Dec 14

    @DaKnObCS disclosure post? what twitter said btw?

    Expand Collapse 0 replies 0 retweets 0 favorites
  4. DaKnOb ‏@DaKnObCS Dec 14

    @homakov Twitter declared it a feature added originally for SMS and then left on web version

    Expand Collapse 0 replies 0 retweets 0 favorites
  5. Egor Homakov ‏@homakov Dec 14

    @DaKnObCS do you understand where the vulnerability is? That oauth apps can send DMs w/o permission to do that

    Expand Collapse 0 replies 0 retweets 0 favorites
  6. DaKnOb ‏@DaKnObCS Dec 14

    @homakov More specifically an employee told me “OAuth DM permission is for read access”

    Expand Collapse 0 replies 0 retweets 1 favorite
  7. Egor Homakov ‏@homakov Dec 14

    @DaKnObCS WTF. Are they crazy. so, technically, Write access to /direct_messages should come by default with timeline access

    Expand Collapse 0 replies 0 retweets 0 favorites
    DaKnOb ‏@DaKnObCS Dec 14

    @homakov I was told DM access is only needed to read. (I reported this like 10 times hoping one will get through)

    0 replies 1 retweet 1 favorite
    • Retweet 1
    • Favorite 1
    • Raghu Srinivasan Maruf Alam
    6:58 AM - 14 Dec 2013
    1. Egor Homakov ‏@homakov Dec 14

      @DaKnObCS that's fun! now i don't feel any sadness about full disclosure because those guys seem crazy :|

      Expand Collapse 0 replies 0 retweets 0 favorites
    2. DaKnOb ‏@DaKnObCS Dec 14

      @homakov That’s what I thought. I discovered it by accident as I was messing with the API and I couldn’t figure out what *I* did wrong :P

      Expand Collapse 0 replies 0 retweets 0 favorites
    3. Egor Homakov ‏@homakov Dec 14

      @DaKnObCS hah, so you fuzzed "d name text" good job. I wonder if they have other commands built in

      Expand Collapse 0 replies 0 retweets 0 favorites
    4. DaKnOb ‏@DaKnObCS Dec 14

      @homakov Not as far as I know, but what stops you from trying the entire alphabet and figuring out the arguments? :P

      Expand Collapse 0 replies 0 retweets 0 favorites
    5. Egor Homakov ‏@homakov Dec 14

      @DaKnObCS why, i will end up with "it's a feature" anyway :D

      Expand Collapse 0 replies 0 retweets 1 favorite
    6. Ben Ward ‏@benward Dec 14

      @homakov @DaKnObCS In our model, the DM permission exists to ensure a user gives explicit consent for apps to *read* their messages.

      Expand Collapse 0 replies 0 retweets 0 favorites
    7. Ben Ward ‏@benward Dec 14

      @homakov @DaKnObCS Although the copy isn't explicit, Sending a Tweet and sending a DM are equivalent (and as you found, they're interwoven.)

      Expand Collapse 0 replies 1 retweet 1 favorite
    8. Ben Ward ‏@benward Dec 14

      @homakov @DaKnObCS The crux is: A user should not have to give an app permission to read their private DM inbox just so an app can send a DM

      Expand Collapse 0 replies 0 retweets 0 favorites
    9. Egor Homakov ‏@homakov Dec 14

      @benward @DaKnObCS from chats with people all o them find this "feature" illogical, maybe company could mind explaining why it's "built in"?

      Expand Collapse 0 replies 0 retweets 0 favorites
    10. Ben Ward ‏@benward Dec 14

      @homakov @DaKnObCS I refer you to my final Tweet: https://twitter.com/benward/status/411924932218458112 … The permission was added to protect users from harvesting of DMs.

      Expand Collapse 0 replies 0 retweets 0 favorites
    11. Ben Ward ‏@benward Dec 14

      @homakov @DaKnObCS We don't regard sending a Tweet or DM as distinct, either as an act or as a spam vector. Reading DMs is extra sensitive.

      Expand Collapse 0 replies 0 retweets 0 favorites
    12. Egor Homakov ‏@homakov Dec 14

      @benward @DaKnObCS my english skills can help me with understanding "harvesting of DM", wdym?

      Expand Collapse 0 replies 0 retweets 0 favorites

      Don’t miss any updates from DaKnOb

      • © 2014 Twitter
      • About
      • Help
      • Ads info

      Flag this media

      This has already been marked as containing sensitive content.

      Learn more about flagging media
      Dismiss
      Previous
      Next

      Go to a person's profile

      Saved searches

      • Remove
      • Verified account @
      Suggested users
      • Verified account @
      • Verified account @

      Retweet this to your followers?

      Are you sure you want to delete this Tweet?

      Block

      • Add a location to your Tweets

        When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more

      • Turn off location

      Profile summary

      Your lists

      Create a new list


      Under 100 characters, optional

      Privacy

      Embed this Tweet

      Add this Tweet to your website by copying the code below. Learn more

      Hmm, there was a problem reaching the server.

      Preview

      Sign up for Twitter

      Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

      Have an account? Log in »

      Two-way (sending and receiving) short codes:

      Country Code For customers of
      United States 40404 (any)
      Canada 21212 (any)
      United Kingdom 86444 Vodafone, Orange, 3, O2
      Brazil 40404 Nextel, TIM
      Haiti 40404 Digicel, Voila
      Ireland 51210 Vodafone, O2
      India 53000 Bharti Airtel, Videocon, Reliance
      Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
      Italy 4880804 Wind
      3424486444 Vodafone
      » See SMS short codes for other countries

      Confirmation

      Buy Now

      Hmm... Something went wrong. Please try again.