View all newsletters
Sign up to our newsletters

Support 110 years of independent journalism.

11 June 2014updated 09 Jun 2021 9:31am

Using Tweetdeck? Log out right now, or someone might take control of your computer

An old error has re-emerged, and it could cause trouble for those using Twitter's dashboard application.

By Ian Steadman

If you use Twitter dashboard client Tweetdeck, listen up – somebody, somewhere, has made a mistake, and you should log out right now until it’s fixed. You should also revoke the access Tweetdeck has been granted to your Twitter account, which can be done by going into settings, going to the apps section, and clicking “revoke access” next to Tweetdeck.

What’s happened here is that the thing that lets Tweetdeck know what’s what in a tweet has changed. Think of it this way: a website doesn’t look like a website to a web browser, but instead is rendered from lines of code. (Chrome and Forefox users can see the source code of any website by right-clicking and choosing “view source”.) What should happen with Tweetdeck is that it interprets each tweet as a block of plain text, which it then displays as a tweet in one of its columns. The problem is that, when a tweet contains code, it isn’t.

So, for example, this tweet…

…will cause Tweetdeck to display a pop-up alert box with the text “XSS in tweetdeck” in it. (That your web browser doesn’t do it is a sign that it’s not an idiot, like Tweetdeck.)

In short, Tweetdeck is interpreting any code that anyone writes in a tweet as a valid Javascript command, and will run it. This means that someone could, in theory, make your web browser do something you wouldn’t expect it to simply by having Tweetdeck open. This is very bad. Similar bugs in Tweetdeck in 2010, 2011 and 2012 caused havoc, and in the most severe cases allowed people to apparently take control of other users’ accounts.

Until Twitter – which owns Tweetdeck – pushes out an update (and they’re usually pretty quick at these, but ohmygod how did a bug like this get pushed out?), there’s a great explanatory video from Tom Scott that goes into what’s known as cross site scripting, “the number one vulnerability on the web today”:

Content from our partners
Unlocking the potential of a national asset, St Pancras International
Time for Labour to turn the tide on children’s health
How can we deliver better rail journeys for customers?

Select and enter your email address Your weekly guide to the best writing on ideas, politics, books and culture every Saturday. The best way to sign up for The Saturday Read is via saturdayread.substack.com The New Statesman's quick and essential guide to the news and politics of the day. The best way to sign up for Morning Call is via morningcall.substack.com Our Thursday ideas newsletter, delving into philosophy, criticism, and intellectual history. The best way to sign up for The Salvo is via thesalvo.substack.com Stay up to date with NS events, subscription offers & updates. Weekly analysis of the shift to a new economy from the New Statesman's Spotlight on Policy team. The best way to sign up for The Green Transition is via spotlightonpolicy.substack.com
  • Administration / Office
  • Arts and Culture
  • Board Member
  • Business / Corporate Services
  • Client / Customer Services
  • Communications
  • Construction, Works, Engineering
  • Education, Curriculum and Teaching
  • Environment, Conservation and NRM
  • Facility / Grounds Management and Maintenance
  • Finance Management
  • Health - Medical and Nursing Management
  • HR, Training and Organisational Development
  • Information and Communications Technology
  • Information Services, Statistics, Records, Archives
  • Infrastructure Management - Transport, Utilities
  • Legal Officers and Practitioners
  • Librarians and Library Management
  • Management
  • Marketing
  • OH&S, Risk Management
  • Operations Management
  • Planning, Policy, Strategy
  • Printing, Design, Publishing, Web
  • Projects, Programs and Advisors
  • Property, Assets and Fleet Management
  • Public Relations and Media
  • Purchasing and Procurement
  • Quality Management
  • Science and Technical Research and Development
  • Security and Law Enforcement
  • Service Delivery
  • Sport and Recreation
  • Travel, Accommodation, Tourism
  • Wellbeing, Community / Social Services
Visit our privacy Policy for more information about our services, how New Statesman Media Group may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications.
THANK YOU