I have written an uploader (desktop) app for YouTube to ease the upload process by use of templates. It's verfified and I've requested additional quota from time to time. And now my app has attracted the interest of spammers. In the Google Cloud platform console I can see that my credentials uses API requests I don't do with my app, like rating videos, adding subscriptions and updating channels and not a low amount of these kind of requests.
I tried already changing the password regularly (which also means deployment of a new app version), obfuscating the binary and modifiy the credential strings in the binary so that they cannot be found directly. But to be honest, it's not worth it, with the usage of fiddler e.g. you can see the password in the authentication requests within no time (I used this code as basis: https://github.com/googlesamples/oauth-apps-for-windows/blob/master/OAuthDesktopApp/OAuthDesktopApp/MainWindow.xaml.cs). And on the next day the spammers are back again.
I wonder why this double authentication is needed at all for a desktop app, it is even stated here, that on desktop apps it cannot be kept secret: https://developers.google.com/youtube/v3/guides/auth/installed-apps and all requests are OAuth authenticated (a mechanism for granting access without disclosure and transmitting of passwords, but you need to do this with the API credentials ). The YouTube accounts should be limited in quota and banned on abuse and not the app, but that is another story...
I also looked for a possibility to restrict the requests, so that no subscription requests are possible e.g. or restrict the amount of uploads per day, but the only possibility I found was limit the quota per user per minute, which I need to set to 1600 so that uploading works at all, which is not helpfull, because it is still enought the to spam over the day.
So what can I do? Request more quota every week?
Thank you in advance for your help!