> 4. If, like last.fm, you were also allowing third-parties to authorize users...
... then you should stop doing that and you should start using OAuth, so the client application never sees your user's password.
... then you should stop doing that and you should start using OAuth, so the client application never sees your user's password.
[1] http://www.robertsradio.co.uk/Products/Internet_radios/STREA...