The GDPR really can't come to soon. I hope it'll finally smite these crappy companies.
The GDPR really can't come to soon. I hope it'll finally smite these crappy companies.
End users might not understand the technical details, but one should assume that if you're giving company X access to your data, company X could potentially share that data with companies Y and Z. Company X's privacy policy should cover their use (and sharing) of the data in either case, and if they didn't anticipate companies Y and Z intercepting data when this is clearly documented as a possibility in Facebook's docs, then I agree - company X should be held accountable.
If you want to talk about what people “should” know, there’s s reasonable man statute, and it definitely doesn’t include what you’re describing.
From an end user point of view - I don't think it's reasonable for a bhphotovideo.com user logging in with Facebook to assume their Facebook data is being sent to ntvk1.ru
I suspect it's not even really reasonable to expect the website owner at some of those "434 of the top million sites" to be technical enough to understand the privacy implications for their users of running both "Log in with Facebook" and 3rd party ad serving on their sites at the same time.
To be fair everyone expects MongoDB to leak data like a sieve.