This is certainly no worse than what Facebook's collecting, and their opt-out controls mean there's not a lot to be worried about.
If you're really paranoid about privacy you should be concerned about Google, not Twitter. Try counting the number of websites with Google Analytics or AdSense (or Google-hosted jQuery, or a +1 button...)
How are they tracking unique activations? IMEI numbers seems the most likely possibility to me, but I wouldn't think Google would keep a list of all the numbers on their servers.
So there's a way to establish two-way communication with an Android device, without enabling any permissions. But it's a very obvious system (works by launching intents, just like every other Android function), so it's hardly something that would work in any kind of stealth mode. Interesting hack, but not really as serious a vulnerability as the name might suggest.
So if I route my traffic through a Russian host, suddenly it becomes a terrible danger? Sounds like a pretty badly informed investigation team, who leaped to conclusions without justifying their claims properly.
On Chrome 14 (Linux), when I click "eval" it doesn't show the alert dialog. Even leaving the default text there. It's an interesting concept though, would definitely be good to see an explanation of how it works.
If you're really paranoid about privacy you should be concerned about Google, not Twitter. Try counting the number of websites with Google Analytics or AdSense (or Google-hosted jQuery, or a +1 button...)