The link doesn't work.  Also note my other response, there is actually an API for that already. 

I think this " OAuth authorization is much more robust and recommended for production use. " should be emphasized a bit more :) This might lead to people getting the idea that rolling their own encryption related code is an acceptable idea :/

