I think Apple will simply not permit applications that use these keys and are not official clients in the App Store. Looks like something that is pretty easy to automate.
You presume that one would use the keys on iPhone. No reason you couldn't run them on a Linux box in AWS...
I'm not sure why Apple would play police for Twitter, though.
Isn't Twitter integrated into Apple's mobile operating system? Such tight partnerships is plenty reason for them to play police for Twitter.
Yes and no. Apple wants to protect their Twitter partnership, but... Apple knows that there aren't any effective police in the park next door. So the question is whether Apple values their Twitter relationship enough that they're willing to cede most of the future energy and enthusiasm around third-party Twitter clients to Android.
It's possible, but I don't think it is at all an easy call.
How would Apple know that the app uses these keys? If they run something similar to strings then all you have to do is store the keys in some kind of obfuscated form.
Right but as soon as the press find out, and they will, that developer account will be banned. Most devs won't see it as worth the risk.
What responsibility does Apple have to Twitter except the notification center widget?