If NYT are correct then we can kiss goodbye to APIs that are used by any services that are not explicitly written and signed by the service provider. In the extreme that means you won't be able to log in to facebook on the web, only via a facebook app, because there's no guarantee that a 3rd party web browser isn't stealing data. That goes for any and every service dealing with personal data, and we pretty much lose the open web.
I want to protect user's data as much as anyone, but if a user deliberately installs a 3rd party app and enters their credentials into it, then they are consenting to that having access to their data under that app's privacy policy/terms. This should be obvious to all users, especially where GDPR advice has been implemented.