Former. Also App developers posting their API keys and Consumer Secret keys. So, theoretically, this would allow a malicious person to control all the authorized accounts with that app (and these were big name apps). Autotweeting, DMing, access private messages, etc.