

News Archive
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
Using the Same Login Across Multiple Sites? You’re Not Welcomed at Twitter!
February 3, 2010, 7:52 am
Do you use the same username and password across multiple web sites?
Then you’re not welcomed at Twitter!
That may sound like an exaggeration, but read this statement from Twitter, then you tell me if I’m exaggerating:
The takeaway from this is that people are continuing to use the same email address and password (or a variant) on multiple sites. Through our discussions with affected users, we’ve discovered a high correlation between folks who have used third party forums and download sites and folks who were on our list of possibly affected accounts. While not all users who were sent a password reset request fall into this category, we felt that it was important to put this knowledge out there so that users would know of the possibility of compromise of their data by a third party unrelated to their Twitter account. We strongly suggest that you use different passwords for each service you sign up for…
The front-end of this story is that Twitter is forcing many users to reset their passwords after it concluded that evil torrent sites were harvesting login credentials. Although, at least one person suggests that the issue goes beyond this.
Now, here’s the thing, BILLIONS of people use the same username and password across different sites. Just think about your parents–do you really think they could handle using a different login for each site that requests one? I think not.
Perhaps it’s time to rethink the “login.” Maybe Twitter et al could lead the way in developing a new system of authentication. One idea, ask users to provide their IP address and whitelist it. Any changes that appear to take place from a different IP–say the rapid increase of Twitter accounts followed–could be “rolled back” to a previous state–one that matches the whitelisted IP, perhaps?
I dunno. You tell me. Is there a better system for authenticating social networking users?






