Twitter has improved security for users of the site by offering an HTTPS option that will help prevent account hijacking which occurs when some users try to log in and use the service via a public Wi-Fi connection.
In a blog post to announce the news, Carolyn Penner of the Twitter communications team explained that although users have been able for some time to use Twitter via HTTPS by going to https://twitter.com, they can now turn it on permanently in their settings.
"This will improve the security of your account and better protect your information if you're using Twitter over an unsecured internet connection, like a public Wi-Fi network, where someone may be able to eavesdrop on your site activity," she said.
"In the future, we hope to make HTTPS the default setting."
Twitter users who access the service via the iPad or iPhone app will already be using HTTPS by default, she added.
Paul Ducklin, head of technology for Sophos in Asia Pacific, welcomed the news in a blog post.
He encouraged users to immediately enable the feature, partly because of the risk posed by the infamous Firesheep plug-in for Firefox, which automates the stealing of session cookies and makes it easy to hijack users' unsecured accounts via Wi-Fi.
"Unfortunately, if you log-in to Twitter over unencrypted Wi-Fi – e.g. at a coffee shop or an airport lounge – then anyone who can sniff your session cookie can pretend to be you. That means they can post tweets as you," he explained.
"Turning on full-time Twitter HTTPS keeps your session cookie encrypted throughout your login session. This is definitely what you want."
Kicking Palantir off of AWS is among their demands, too
Rafaela Vasquez was watching The Voice at the time of the crash, new evidence shows
PUBG price slashed on Steam after selling more than 50 million copies - as daily player numbers plunge
Use the same password for every website? It might be time to change them all