People in various forums (a couple on HN, SO, Egor's blog, Twitter itself) seem to be saying something like "this isn't really a bug".<p>It's definitely a bug. Twitter requires clients to ask for the DM permission before they can send DMs. With Egor's approach, clients can privilege-escalate themselves to send DMs even if they never asked for that permission (although they still need to be authorized to send tweets).<p>Also, even worse, Twitter doesn't consider it a bug, according to the person who originally reported it (who was not Egor): <a href="https://twitter.com/DaKnObCS/status/411869431036653568" rel="nofollow">https://twitter.com/DaKnObCS/status/411869431036653568</a><p>And here's a response from Ben Ward, the Twitter web lead: <a href="https://twitter.com/benward/status/411924515459850240" rel="nofollow">https://twitter.com/benward/status/411924515459850240</a>