>A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”.
Maybe not the best usage of the word scraping.
CA had access to the data without having to scrape the front end.
For this extension, it is by consent of the user
For scraping, I agree. Facebook should try their best to stop people accessing personal data of people they don't know. They do make reasonable attempts, it's less than trivial to set up fake accounts on scale but not impossible. Their "bulk uploads" feature is designed in such a way that it doesn't link email addresses to profiles (or at least as easily), unlike LinkedIn and Twitter. Saying that, it's up to the user to set their privacy settings but I would much prefer the defaults (if they still aren't, I don't use FB) were automatically set to non-public. I've seen an implementation that used headless browsers and thousands of FB accounts to scrape millions of profiles.