<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Securism Blog &#187; twitter</title>
	<atom:link href="http://blog.securism.com/tag/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securism.com</link>
	<description>Simple Security.</description>
	<lastBuildDate>Fri, 23 Jul 2010 18:17:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Gnome Do Microblogging Plugin Authenticates Over Clear Text</title>
		<link>http://blog.securism.com/2009/01/gnome-do-microblogging-plugin-authenticates-over-clear-text/</link>
		<comments>http://blog.securism.com/2009/01/gnome-do-microblogging-plugin-authenticates-over-clear-text/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 21:52:04 +0000</pubDate>
		<dc:creator>Ben Hagen</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.securism.com/?p=178</guid>
		<description><![CDATA[I love the Gnome productivity tool Gnome Do. Its great! What&#8217;s not so great is the fact that the installation default Twitter plugin &#8220;Microblogging (Twitter)&#8221; version 1.0 authenticates to Twitter over clear text. In general, its a great plugin&#8230; easy to post updates and wonderful balloon popups when friends post their&#8217;s&#8230; but this is a [...]]]></description>
			<content:encoded><![CDATA[<p>I love the Gnome productivity tool <a href="http://do.davebsd.com/">Gnome Do</a>. Its great! What&#8217;s not so great is the fact that the installation default Twitter plugin &#8220;<a href="http://do.davebsd.com/wiki/index.php?title=Microblog_Plugin">Microblogging (Twitter)</a>&#8221; version 1.0 authenticates to Twitter over clear text. In general, its a great plugin&#8230; easy to post updates and wonderful balloon popups when friends post their&#8217;s&#8230; but this is a killer problem.</p>
<p>I&#8217;ve filed a bug report with the plugins group <a href="https://bugs.launchpad.net/do-plugins/+bug/323364">here</a>.</p>
<p>With the ubiquity of wireless networks and the ease of promiscuously monitoring wireless networks, it is no longer acceptable to authenticate over clear text. Twitter shouldn&#8217;t allow authentications over none SSL channels, and applications shouldn&#8217;t support them even if non-SSL is supported. I discovered this while a friend was toying around with Kismet at a local cafe. I typically connect to an OpenSSL VPN whenever I use public networks, but due to the nature of the plugin it connects before I have a reasonable chance to enable the VPN&#8230; hence my friend captured my password. Fun.</p>
<p>I would also like to take this oppurtunity to remove any liability from myself for anything posted to my Twitter account in the future <img src='http://blog.securism.com/wordpress/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securism.com/2009/01/gnome-do-microblogging-plugin-authenticates-over-clear-text/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
