That the service may be unreliable and it's one more point of failure is just one of the reasons why it's a bad idea to depend on FB (or Twitter, or G+ login) for your logins, and this is why their attempt to subsume the web with corporate corrals will ultimately fail.
Probably you are talking about redundancy where, I agree, it does go down.
As for which risk is the most important risk, well, that's up to your business to decide. But nothing is without risk, all you can do is choose which to expose yourself to.
It depends on your line of business, but if you compare the benefits of making user signup faster, lowering acquisition barriers and getting access to the social graph of users against the risks of depending on one of the top infrastructures in the cloud, I think it may well be worth the trouble.
You can packup your application and move it to Amazon/Rackspace/DigitalOcean, but if you use Facebook login exclusively or use a third party API for a core service and they decide to change (as GP suggests), you're fucked.
Also, reliability is one factor out of several, it is not the only, or even the primary, risk with using something like FB login.
Probably not.
If you want to take advantage of this market then there are ways to use Login with Facebook without being wholly dependent. Basically if you have full account management, but you allow third-party authentication that ties into that account, especially allowing multiple OAuth providers to be linked to a single of your internal accounts (eg. see how Stack Overflow works), you can significantly mitigate the downside.
The purist and old-school web head and open standards guy in me hates it, but you can't argue with the business case for it.
There is a simple solution to this. STOP ASKING USERS TO SIGN UP! Do your REALLY need to collect the users e-mail? Do REALLY need them to have an account at all? If you do, then when they register don't ask for their e-mail address if it isn't necessary, or at least make the e-mail address an optional field. Hacker News never asked for my e-mail, because there is no need for them to have it. I probably wouldn't have made an account if it did require an e-mail address.
As you say with FB login there are ways to mitigate that risk, but to take one example - if FB charge for the service in future at 0.01c per use, many of your users will still want to login with FB because it's easier for them, and you'll be stuck with the bill. This happened with sites using google maps in 2012 when they started charging - each of these decisions has to be weighed up individually as a risk, but I think login is too important to delegate to another site and a significant addition of complexity and risk.
That said, your example doesn't demonstrate much risk at all. What are the incentives for FB to start charging for this? It just doesn't make any sense for them to give up that data and that control to try to squeeze existing site operators out of a buck. I mean, never say never, but the risk is much less than it was with Google Maps where you always had to be asking what Google was getting out of this expensive and difficult-to-build-your-own service.
It's naive to assume that a company will defend their subsidiary. I am not condoning how they treated you but your assertion of the app has nothing to do with Facebook is incredulous.
Using it for logins is really questionable. But if you are, for example, building a game for Facebook, it gives you many advantages, so occasional downtime is not really the biggest issue. Let's check the things you wrote about in gaming context:
- charging for the service later TRUE (viral is dead, you pay for the ads to get new players in)
- cut you out of a relationship with your own customer - somewhat FALSE (you can request e-mails from your customers, and have a direct contact afterwards). Even with fan pages, they are not cuting you out, but merely asking to pay to get your message to them
- require you to use their store TRUE, but every other platform does the same
- copy your idea and give it for free. FALSE - Facebook never made a game AFAIK
- squezee you margins. TRUE. I do notice that Cost Per Install for my games is getting higher the more I advertize, and that it suddenly jumped from about $0.15 per install to $0.50 per install a few days ago - about the same time when they switched to the new payment user interface.
OAuth dialogs don't load and the graph API is down too.
Today's unofficial but fun to pronounce related word is "specificity".
Also affects the like buttons across the web, see the error on an old TC article here: http://cl.ly/image/2Q3V1X240D12