Any idea where these came from? Was Twitter actually hacked somehow (and if so, why only 55k)? Or was 3rd-party software that collected Twitter credentials hacked? Can 3rd-party software even collect credentials at all or is OAuth the only authentication flow that works today?