::Trend Micro Threat Resource Center::

28 October 2010

Think your Twitter Direct Message is private? Think again

Twitter has established itself as a means of broadcasting information to wide group of people all at once. But, for those times where you want to talk more intimately, Twitter also has the ability to send a Direct Message (DM) that is private between the two parties. Well, it's supposed to be private, but the reality is perhaps not as secretive as one might expect.

While the DMs are ostensibly private, the reality is that any apps that have been approved to access your Twitter account can also see those "private" messages.

There are only two types of account access authorisations: read-only, or read-and-write. In either case, the fact that the app has been granted permission to access the account at all means that all Twitter messages, including DMs are accessible to the app. In the event of read-and-write approval, the app could also delete your messages, or send messages out on your behalf.

Perhaps you should think twice next time before blindly approving some random app to access your Twitter feed. You can find out which apps have access to your Twitter messages by logging in to your account on the Twitter site. Click on Settings, then Connections. The fine print for each entry displays the type of access authorized (read-only or read-and-write), and a link is provided to "Revoke Access" for any that seem shady or unwarranted.

It may be a tad paranoid to worry about whether the admin of a given app is abusing the privilege you have granted and is sifting through your private DMs. But, just to be safe you should exercise some discretion with the apps you grant that authority to, and remember that your DMs may not be as private as you might think.