What approaches do other OAuth providers take to this problem? Revoking all OAuth tokens on a password change/reset takes away a good chunk of the value that many people get from using OAuth.
Every OAuth site has a "log in with Twitter" feature, correct? Maybe Twitter could organize things such that, when you change your password, you're automatically logged out of every OAuth site?
Agreed, but would it be difficult to have a checkbox marked "revoke all permissions to use my account from all applications" to the reset password menu?
That's overkill. Perhaps, one day, there will be a need to suspend all oAuth authorizations while a rogue app is identified.