Originally posted by Alt
I only say that because you could get Instagrams jacked via users tokens from apps such as like4like etc.
Originally posted by MEGALELZ
Instagrams oath system has always been terrible. It still is, Twitter's is completely different. Not sure about Facebook though.
Twitter's oath is a one use token, it dies straight after you approve the application. It's a very smart system.
Twitter requires you to setup an app, and then you need to authenticate for each app by manually approving it. I'm pretty sure the token will only work for that specific app so it's not like someone can grab the tokens from the db and just use them to post shit to your Twitter account. They would need to grab the app details and then setup something to use that to send statuses. Lots of work when I'm able to just delete the app from Twitter and make it obsolete in a matter of seconds.
I don't mind you trying to make sure I'm doing it correctly. But I do value security and privacy over everything and would never ask for your password for Twitter or even NGU for that matter. Never would I try to store your password for another site in the database; that's just preposterous. I also wouldn't bother if their OAuth implementation was broken or vulnerable; that's too much responsibility to fall back on us if we did it incorrectly.