Magazine

Twitter Warns Developers That Their Private Keys and Account Tokens May Have Been Exposed – ProWellTech

Posted on the 26 September 2020 by Thiruvenkatam Chinnagounder @tipsclear
Twitter warns developers that their private keys and account tokens may have been exposed – ProWellTech

Twitter emailed the developers warning of a bug that may have exposed their private app keys and account tokens.

In the email, obtained by ProWellTech, the social media giant said the private keys and tokens may have been improperly cached in the browser by mistake.

"Prior to the fix, if you were using a public or shared computer to view developer app keys and tokens on developer.twitter.com, they may have been temporarily cached in your browser on that computer," the email read. "If someone who used the same computer after you in that temporary amount of time knew how to access a browser's cache and knew what to look for, it's possible they could have accessed the keys and tokens you viewed."

The email said that in some cases the developer access token for their Twitter account may have been exposed.

These private keys and tokens are considered secret, just like passwords, because they can be used to interact with Twitter on behalf of the developer. Access tokens are also very sensitive, because if stolen they can allow an attacker to access a user's account without needing their password.

Twitter said it has not yet seen any evidence that these keys have been compromised, but has warned developers of an abundance of caution. The email said users who may have used a shared computer should regenerate the app's keys and tokens.

It is not immediately known how many developers were affected by the bug or exactly when the bug was fixed. A Twitter spokesperson would not provide a figure.

In June, Twitter said corporate customers, such as those who advertise on the site, may have improperly stored their private information in their browser cache.

Source link

Back to Featured Articles on Logo Paperblog