Thread · 3 tweets · 16 Nov 2022

If you're running a news site and you embed tweets, I hope you realise that Elon Musk, a famously petulant man-child who openly hates independent reporting, has direct and hard to detect control over the entire pages that have embeds, including hitting your backend as your users?
↺ 14
Third-party code embeds are always an attack vector, the fact that they're common on the Web is an endemic problem that we'll have to fix eventually. But I would suggest that the threat level here is more elevated than the ambiant "the Web is poorly architected for security."
↺ 3
In addition to the attack vector, there's the problem of archival: a lot of these articles are going to become meaningless or to lack important context if the tweets are pulled.
↺ 3