FiloSottile / HNTitles

Tweet probabilistically generated HN post titles.
https://twitter.com/HNTitles
29 stars 3 forks source link

Consumer key and secret leaked #3

Closed adamdecaf closed 5 years ago

adamdecaf commented 5 years ago

See: https://github.com/FiloSottile/HNTitles/blob/master/tweep.py#L12

From: https://twitter.com/vietlq/status/1065930252180811776

FiloSottile commented 5 years ago

2013 me believed they were useless without the corresponding secrets, and 2018 me found it plausible enough not to rotate them. Was I wrong?

adamdecaf commented 5 years ago

I'm not sure and I'd assume if they were leaked your api account would have been taken over years ago.

The docs mention you could programmatically retrieve the access key: http://docs.tweepy.org/en/v3.5.0/auth_tutorial.html (at the bottom)

FiloSottile commented 5 years ago

I'm going to assume that it's been fine until now and it will keep being fine. It's not a sensitive account anyway. But thanks for the ping!