{"id":4545,"date":"2014-01-17T12:36:53","date_gmt":"2014-01-17T17:36:53","guid":{"rendered":"http:\/\/blog.nccomputertech.com\/?p=4545"},"modified":"2014-01-17T12:36:53","modified_gmt":"2014-01-17T17:36:53","slug":"twitter-enforces-ssl-encryption-for-apps-connecting-to-its-api-zdnet","status":"publish","type":"post","link":"https:\/\/nccomputertech.com\/techtalk\/2014\/01\/17\/twitter-enforces-ssl-encryption-for-apps-connecting-to-its-api-zdnet\/","title":{"rendered":"Twitter enforces SSL encryption for apps connecting to its API"},"content":{"rendered":"<p>Developers whose apps are still using HTTP plaintext connections to connect to Twitter&#8217;s API feeds may find their applications broken from today.<\/p>\n<p>Twitter has enforced new rules for developers to enhance privacy for end users, which from 14 January will see it block connections to all its API URLs for apps that have not enabled TLS (Transport Layer Security)\/ SSL (Secure Sockets Layer) encryption.<\/p>\n<p>Twitter alerted developers about a month ago to the new requirements, including a &#8216;black out&#8217; test run last week, which temporarily broke such HTTP-only apps and should have alerted most developers of the changes in store. The company issued another reminder yesterday.<\/p>\n<p>&#8220;Connecting to the API using the SSL protocol builds a safe communication channel between our servers and your application, meaning that no sensitive data can be accessed or tampered by unauthorized agents in the middle of this communication path,&#8221; Twitter wrote on its developer blog in December.<\/p>\n<p>The change has been enforced for all Twitter API URLs, including all steps of OAuth \u2014 which prevents user passwords from being captured in transit \u2014 and its various REST API resources.<\/p>\n<p>The new rules for developers follow Twitter&#8217;s efforts to bolster privacy for end-users, late last year enabling &#8220;perfect forward secrecy&#8221; for traffic on its main website, mobile website and API lists.<\/p>\n<p>Following Google and Facebook, Twitter enabled SSL protected sessions in 2011, while the addition of perfect forward secrecy to its SSL implementation would thwart attempts at &#8220;retrospective decryption&#8221;.<\/p>\n<p>via <a href=\"http:\/\/www.zdnet.com\/twitter-enforces-ssl-encryption-for-apps-connecting-to-its-api-7000025138\/\" target=\"_blank\">Twitter enforces SSL encryption for apps connecting to its API | ZDNet<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Developers whose apps are still using HTTP plaintext connections to connect to Twitter&#8217;s API feeds may find their applications broken [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[7,8],"tags":[325,1024,1110],"class_list":["post-4545","post","type-post","status-publish","format-standard","hentry","category-security","category-social-media","tag-encryption","tag-ssl","tag-twitter"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/papNkV-1bj","jetpack-related-posts":[{"id":6634,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/10\/15\/google-discovers-vulnerability-in-ssl-3-0-dubbed-poodle\/","url_meta":{"origin":4545,"position":0},"title":"Google discovers vulnerability in SSL 3.0 dubbed &#8216;Poodle&#8217;","author":"NCCT","date":"October 15, 2014","format":false,"excerpt":"Google has published details of a vulnerability in the design of SSL version 3.0. The attack, referred to as POODLE (Padding Oracle On Downgraded Legacy Encryption), allows the plaintext of secure connections to be calculated by a network attacker according to a Google blog post on the matter. Despite the\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":7112,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/12\/10\/researchers-say-poodle-can-be-repurposed-to-attack-tls-10-percent-of-the-servers-vulnerable\/","url_meta":{"origin":4545,"position":1},"title":"Researchers say Poodle can be repurposed to attack TLS, 10 percent of the servers vulnerable","author":"NCCT","date":"December 10, 2014","format":false,"excerpt":"A couple of months after researchers at Google uncovered POODLE (Padding Oracle On Downgraded Legacy Encryption), a vulnerability in a specific version of the SSL protocol, security firm Qualys has announced that the issue also affects implementations of the TLS protocol. Poodle allows attackers to compromise the secure connection between\u2026","rel":"","context":"In &quot;Networking&quot;","block_context":{"text":"Networking","link":"https:\/\/nccomputertech.com\/techtalk\/category\/networking\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":5643,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/05\/30\/microsoft-goes-public-with-browser-development-plans\/","url_meta":{"origin":4545,"position":2},"title":"Microsoft goes public with browser development plans","author":"NCCT","date":"May 30, 2014","format":false,"excerpt":"Aiming to provide more transparency in how it develops Internet Explorer, Microsoft has launched a website to help keep developers abreast of the latest changes and plans for the browser. This site aims to put IE on similar ground with Mozilla Firefox or Google Chrome, which are open-source projects, so\u2026","rel":"","context":"In &quot;Microsoft&quot;","block_context":{"text":"Microsoft","link":"https:\/\/nccomputertech.com\/techtalk\/category\/microsoft\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/core1.staticworld.net\/images\/article\/2013\/05\/internet_explorer-100037081-gallery.jpg?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/core1.staticworld.net\/images\/article\/2013\/05\/internet_explorer-100037081-gallery.jpg?resize=350%2C200 1x, https:\/\/i0.wp.com\/core1.staticworld.net\/images\/article\/2013\/05\/internet_explorer-100037081-gallery.jpg?resize=525%2C300 1.5x"},"classes":[]},{"id":6713,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/10\/28\/rogue-tor-exit-node-server-added-malware-to-legitimate-downloads\/","url_meta":{"origin":4545,"position":3},"title":"Rogue Tor &#8216;exit node&#8217; server added malware to legitimate downloads","author":"NCCT","date":"October 28, 2014","format":false,"excerpt":"The Tor Project has flagged a server in Russia after a security researcher found it slipped in malware when users were downloading files. Tor is short for The Onion Router, which is software that offers users a greater degree of privacy when browsing the Internet by routing traffic through a\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":6202,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/08\/13\/opengl-4-5-released-with-one-of-direct3ds-best-features\/","url_meta":{"origin":4545,"position":4},"title":"OpenGL 4.5 released\u2014with one of Direct3D\u2019s best features","author":"NCCT","date":"August 13, 2014","format":false,"excerpt":"The Khronos Group today released OpenGL 4.5, the newest version of the industry standard 3D programming API. The new version contains a mix of features designed to make developers' lives easier and to improve performance and reliability of OpenGL applications. The group also issued a call for participation in its\u2026","rel":"","context":"In &quot;Technology&quot;","block_context":{"text":"Technology","link":"https:\/\/nccomputertech.com\/techtalk\/category\/technology\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/nccomputertech.com\/techtalk\/wp-content\/uploads\/2014\/08\/opengl_500-300x148.png?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":5625,"url":"https:\/\/nccomputertech.com\/techtalk\/2014\/05\/29\/truecrypt-is-not-secure-official-sourceforge-page-abruptly-warns\/","url_meta":{"origin":4545,"position":5},"title":"\u201cTrueCrypt is not secure,\u201d official SourceForge page abruptly warns","author":"NCCT","date":"May 29, 2014","format":false,"excerpt":"One of the official webpages for the widely used TrueCrypt encryption program says that development has abruptly ended and warns users of the decade-old tool that it isn't safe to use. \"WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues,\" text in red at the top\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/nccomputertech.com\/techtalk\/category\/security\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts\/4545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/comments?post=4545"}],"version-history":[{"count":0,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/posts\/4545\/revisions"}],"wp:attachment":[{"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/media?parent=4545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/categories?post=4545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nccomputertech.com\/techtalk\/wp-json\/wp\/v2\/tags?post=4545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}