I somehow thought that apps could no longer 'login' to social network accounts using usernames/passwords, so that they would have to use OAuth instead? There should be a way that Facebook and Twitter would prevent an app from using login information in order to bypass the 'app authorization' dialog which is supposed to be shown to users to tell them what the app can do to their account.