--
Julio Biason <julio....@gmail.com>
Twitter: http://twitter.com/juliobiason
The source parameter means nothing. I can change Mitter to identify
itself as Twiterrifc, for example. If they take a road like that, some
spammer can change the parameter to, say, YOUR application and your
users will flock to something else (but, most probably, spammers won't
use any source, meaning the source it's the website itself -- which
proves nothing.)
Again, not a proper solution. My client is open source and the app-key
would be visible to anyone very easily. And no, I do not intend to
make it close just for the sake of "protecting the key."