Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy & Compliance

Twitter Makes Apps Use Encryption to Connect to API

Earlier this week, Twitter announced that all third-party applications that make data requests to the micro-blogging service’s application interface (API) must use encryption.

Earlier this week, Twitter announced that all third-party applications that make data requests to the micro-blogging service’s application interface (API) must use encryption.

In a tweet, the company announced that of Jan. 14, all data requests sent to the Twitter API would have to be done using SSL or TLS. The announcement follows through on what the company said a few weeks ago.

“If your application still uses HTTP plaintext connections you will need to update it to use HTTPS connections, otherwise your app will stop functioning,” Luis Cipriani, partner engineer at Twitter, blogged in December. “You don’t need to wait until deadline to implement this change, given that api.twitter.com already supports the recommended environment. This SSL requirement will be enforced on all api.twitter.com URLs, including all steps of OAuth and all REST API resources.”

Reuven Harrison, CTO of Tufin Technologies, said apps that do not enforce SSL should not be used.

Advertisement. Scroll to continue reading.

“Why? Because without SSL, your data and credentials are in the clear and it’s very easy for hackers to see them,” he said. “For example, it is a very common hacker exploit to taking advantage of user logins to non-SSL apps in unsecure WiFi networks in a café or restaurant to steal the user’s log-in information for mischievous purposes. Once these credentials are collected, hackers can use this data to get access to sensitive information, steal identities and log into other user accounts such as your bank account, especially when passwords are shared.”

With the move, Twitter is following the footsteps of Facebook and Google, which started requiring SSL for applications back in 2011.

Dan Cornell, CTO of Denim Group, called the move part of a positive larger trend of major sites using HTTPS and SSL by default, noting that Yahoo also made the switch.

“This doesn’t solve every security problem – it actually only addresses a very narrow set of them – but it represents a movement in a good direction,” he said.

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...

Cloud Security

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Application Security

Security researchers at Google’s Project Zero have picked apart one of the most notorious in-the-wild iPhone exploits and found a never-before-seen hacking roadmap that...