Blog | G5 Cyber Security

RSA Conference registration page collecting Twitter credentials

Security experts noticed something odd about the final registration page on the RSA Conference website. A promotional social media offering was collecting usernames and passwords and sending them to the conference server. Organizers have responded to a request for comments, issuing a denial that credentials were collected. They also claim OAuth was used, and state that going forward, the Twitter form will be disabled. One expert pointed out that Twitter has an OAuth flow called xAuth, which requires Twitter approval before it can be used.”]

Source: https://www.csoonline.com/article/3025449/rsa-conference-registration-page-collecting-twitter-credentials.html

Exit mobile version