<rss version="2.0">
  <channel>
    <title>Freezerpants.com - Posts Tagged with privacy</title>
    <link>http://freezerpants.com/category/privacy/</link>
    <description>A logahead powered blog</description>
    <language>en</language>
    <lastBuildDate>Mon, 13 Oct 2008 20:18:15 +0000</lastBuildDate>
<item><title>Twitter Bug</title><link>http://freezerpants.com/2008/05/06/twitter_bug</link><description>&lt;p&gt;A few moments ago I discovered a bug in the way twitter handles protected updates.&lt;/p&gt;

&lt;p&gt;Apparently, if you search for a username, it will provide you with that users most recent tweet. This could easily be exploited through scrapes to provide  a &quot;feed&quot; of a users &quot;protected&quot; updates.&lt;/p&gt;

&lt;p&gt;So much for privacy. One more reason to hate twitter.&lt;/p&gt;

&lt;p&gt;For the curious, here is how it&amp;#039;s done,&lt;/p&gt;

&lt;p&gt;Simply enter the &lt;span class=&quot;caps&quot;&gt;URL &lt;/span&gt;in this format:&lt;br /&gt;
http://twitter.com/tw/search/users?q=USERNAME&lt;/p&gt;

&lt;p&gt;This seems sporadic with the &quot;normal&quot; twitter, but the mobile version showed the last update 100% of the time (that I tried, about a dozen from a few machines)&lt;/p&gt;

&lt;p&gt;The mobile url is:&lt;br /&gt;
http://m.twitter.com/tw/search/users?q=USERNAME&lt;/p&gt;

&lt;p&gt;You will need to be logged in for this to work.&lt;/p&gt;</description><pubDate>Tue, 06 May 2008 00:46:00 +0000</pubDate></item>  </channel>
</rss>