I was directly involved in one of those 'incidents' several years back where FB gave our app a special API that others did not have. This was because it was easier for us to build the 'FB experience' for their users, than it was for FB themselves. It was clean, legit, above board and secure.
It's astonishing how different the 'media narrative' is from reality, and it confirms my belief that the press runs on such narratives (i.e. building up, crashing down) because in both directions the truth is inflated for dramatic, i.e. click-bait reasons.
Our large company built a very good FB app that effectively was 'FB' on our platform. It was FB branded - for users, it was effectively the 'real' (and only) FB. Obviously that app had to have special APIs.
Everyone involved from top to bottom was pro. We didn't store data, nor did we want or need to. The way the tech was setup (data goes to app), we didn't really have the option. Users logged into their own accounts and retrieved their data, it's not like we could just access data arbitrarily.
Everything was pro and above bar - and nobody in the equation - a lot of us regular, conscientious people - thought for a second that anything was wrong or irregular in any context.
In fact - the whole situation could be described as: "FB hired 3rd parties to develop some code", which surely they do in some circumstances.
Nobody was harmed in any way, and there really wasn't risk of anyone being harmed.
I understand that with 2018 hindsight, we might look at things a little differently, but in reality, I think we'd have still done it. Perhaps there would have been more checks and assurances (i.e. FB takes ownership of code and actually publishes the app), but in reality it was (and would still be) fine.
As far as the Cambridge story - this is also misleading because the API's that were used there were available to the entire world and everyone knew exactly what they were. Were there tech people screaming foul? The press? Not really, they seemed reasonable, until it seemed that some bad agents were getting a little unscrupulous, and so FB did the right thing and altered the APIs to make them more secure. Security polices change all the time, in this case they tightened up given some field data. That's it.
It's really a story about Cambridge's scammy behaviour, and possibly lies to FB on where that data was, not about FB.
I don't like Facebook, I don't use it, I don't like being 'productized' etc. etc. - but I don't feel that the information in these scenarios has been properly handled by the media.
Because there are legitimate issues with privacy in the new world order in 2018 that are finally coming to bear, and we definitely want to re-evaluate our situation with FB, basically, we go and dig up 'something that happened 10 years ago in which nobody was harmed' to build a 'kind of misleading narrative' around the the 'legitimate issue'.