On Aug 31, 12:46 pm, Matt Harris <thematthar...@twitter.com> wrote:
> Like many mobile applications Twitter for Android uses xAuth. In this
> mode the user enters their username and password which is then sent to
> Twitter for the OAuth credentials. Part of the agreement of granting
> access to xAuth is that the application must not store the username
> and password.

Ah hah!  Ok, thanks, good to know.

A lot of folks are tweeting right now about the end of password-based
authentication.  Maybe someone should tell them "not quite".

