Making Twitter more secure: HTTPS
Today, we're taking an important step to make it easier to manage the security of your Twitter experience - we are adding a user setting that lets you always use HTTPS when accessing Twitter.com. Using HTTPS for your favorite Internet services …
Context & Ripple Effects
The setting lands at the end of a frenetic week for Twitter: on March 12 the company issued [[a:none|new mandatory terms]] for third-party developers — drawing warnings that it was bulldozing its own client ecosystem — two days after confirming record growth and engagement, and shortly after completing the Tweetie acquisition that became its native iPhone app.
The security move also follows a week in which Twitter demonstrated what kind of service it has become: after the March 11 earthquake jammed Japanese cell networks, users turned to Twitter alongside Facebook and Mixi. A platform accessed at surge scale, from whatever device and network is available, is precisely the environment where unencrypted sessions are exposed — yet making HTTPS a user setting rather than a default leaves the burden of finding and enabling it on individual users.
First-order effects
- Users who enable the setting get HTTPS for all Twitter.com access; the default remains off, so account protection depends on each user discovering the toggle.
- Third-party client developers, already operating under the mandatory ToS issued March 12, now see the first-party site raise the security baseline their apps are measured against.
Second-order effects
- With engagement at record pace and event-driven surges pushing access onto congested and shared mobile networks, pressure builds on Twitter to flip encryption from opt-in to default.
- Rival consumer web services still shipping plain HTTP sessions face direct comparison once a top social platform normalizes one-click encryption.
Third-order effects
- If the opt-in-to-default sequence holds across the industry, transport encryption shifts from a power-user feature to a baseline expectation for consumer web services, with laggards visibly exposed on public networks.
- Security controls arriving first as settings and later enforced wholesale would make user-facing toggles the leading indicator of where platforms' defaults are heading.
The trend: Consumer web services are moving transport encryption from an expert opt-in toward a universal default, with major platforms' settings toggles marking the intermediate stage.