Earlier quoted context omitted.
It's more or less public knowledge. You can find it yourself by running "strings" on the Twitter app binary. Any attempts on Twitter's part to limit the disclosure of these tokens would almost certainly invoke the Streisand Effect.
Couldn't another app use these tokens and take advantage of lax api limits ?
The Chrome app Hotot too. https://chrome.google.com/webstore/detail/hotot/cnfkkfleeioo...