It is this way that Cambridge Analytica was able to get 50 million profiles by just paying ~270k Amazon mechanical turkers [1].
It's true that everyone agreed to everything along the way: people allowed Facebook to have the information in question, and people allowed Cambridge Analytica to access that information. But it wasn't the same people agreeing to both. The set of people agreeing to the latter was much smaller than the former.
It may be true that technically neither Facebook nor Cambridge Analytica did anything wrong (at least in collecting this information, this seems to be by far the least shady part of CA's business), but, Facebook's business is built on trust, and this is a huge hit to that trust. Arguing technicalities doesn't help.
1. https://www.nytimes.com/2018/03/19/opinion/facebook-cambridg...
Except that those users had granted that permission to the people who then granted it to CA. So, transitively (which is the only way to think about permissions), they had granted it to CA.
Now Facebook may make a different statement etc and the rules of service, privacy can allow for this. But it is not a property that is transitive in general. And it is bad publicity. (I hope.)
I can be told a secret, I do not necessarily have the permission to share, for instance, what happened in the bachelor party last Saturday right?
Of course, you can allow the authorization server to publish these details, but this is not an inherent part of OAuth. Also, there's OpenID Connect [2] which builds on OAuth and adds just this information in another token: "The ID token resembles the concept of an identity card, in a standard JWT format." (from [2]). However, you can happily use OAuth without ever publishing the user's details.
[1] https://tools.ietf.org/html/rfc6749 [2] https://openid.net/connect/
I took your comment to say "You have to allow access to your data if you're using OAuth, because that's how OAuth works", and wanted to argue against that. The OAuth protocol is so complicated because it tries to be safe and secure and so it doesn't force any data disclosure. However, I now see that you probably meant "OAuth forces you to accept these permissions explicitely". In that case, we're hopefully both right :)
I believe the reason this story is blowing up so big in the media is because most people never imagined their data being used in this way. When I login to patreon and subscribe to someone, I know exactly what I am paying. When I login to facebook and make a post, I (the average user) have no idea what it is that I am paying and/or how it can be used. I give away some factoid about myself without realizing that my angry post about Trump actually tweaks some political vector that is being calculated on me.
Consent is not enough, informed consent is the bar we have to set and it's basically impossible to say that the average facebook user is properly informed of what data they're giving, how it's being used and how much it is worth in dollar terms. Can you imagine if I could log into Facebook and see the models they've generated based on my content, and the dollar amount they've collected for that information so far. That's informed consent and somehow I doubt Facebook would be quite as profitable if people knew the actual cost they're paying.
But I disagree that if we went back in time and quizzed people clicking "yes" that the majority would really understand that recent events were the probable expected outcome of them clicking "yes".
There's a difference between consent and informed consent. And it was strongly in the interests of Facebook (and anybody who made an app using their APIs) to be very vague about the potential consequences.
Actually, there are lots of people who have no clue that such things are possible. Maybe in 20 or 30 years, everyone would become savvy enough to understand the implications of giving away their personal info freely, but we are not yet there. The people who know (younger, tech savvy etc) are in the minority. Today a big chunk of the population simply believes everything they read on FB, that is why trolling works so wonderfully
Granular permissions are also a pain point for me on Android phones. They were possible with apps on BlackBerry phones in the late 200x's, but on Androids before version 5 or 6? No, it's either give the app permission for all of requested functionality, or don't install it...