This seems fairly similar to the Cambridge Analytica revelation—it seems they’re reporting on access specifically granted to these apps by the user, but the data is not technically restricted from access the way you might expect when humans are involved. That is, the person isn’t authorized on access beyond having the app credentials. Does anyone else understand this? Does that sound correct?
If I am correct, we’re going to be facing a long list of shocking APIs. I also wonder why the article doesn’t mention SOX, which might provide some liability for public companies looking at PII.