42 Points

Today we have been made aware that Twitbin, the twitter client for firefox (we wrote about twitbin here ), fails the most basic password security tests. The problem is that it stores your username and password in plain text in a browser cookie. This is very bad practice.

Thanks to YABFOG's post for making us aware of this.

It is recommended that you uninstall Twitbin until such time that they provide proper security for your credentials.

Oct 24, 2007

Share this post on:

Similar Twittown Posts You Might Enjoy:
Comments
Twittown Comments
Submitted by Twitter Traffic Machine Review (not verified) on Jul 28, 2009 18:41 says:

Hi Thanks for the warning

Submitted by Dan (not verified) on Nov 18, 2007 00:00 says:

Brian, you beat me to it. All fixed in Twitbin. http://www.yabfog.com/wp/2007/10/26/twitbin-fixes-security-flaw

Submitted by Brian Breslin (not verified) on Oct 25, 2007 04:22 says:

Hey Twittown,
We've released a patch to this issue, it has already been uplaoded, and is live on the servers. All one has to do to get the update is clear their cache and their cookies.
Thanks for your patience,
Brian