> But, for example, this guy wants to read his own messages, which is a rather popular use of Facebook. If they wanted to comply with GDPR, they could easily present him a dialog asking solely for permission to process the data necessary to show him his messages.
The normal operation of Facebook processes a lot of your information between login attempts, and not in direct response to yoour action; if they haven't gotten consent that satisfies the GDPR for that before May 25, they need to stop processing your information, which means they need to essentially completely disable and isolate your account, not just from you logging in, but from all visibility and interaction initiated by other parties.
While, in the abstract, a service they processes your information only in direct and immediate response to your UI interactions could adopt a granular permission model and seek consent for just what was necessary to handle each control interaction when you interacted with the relevant control (crappy UX, but it's possible), that's not the way Facebook works, nor is it something it seems Facebook could, with reasonable effort, be reengineered into. I'm not even sure pausing aall processing of your data until consent is received without deleting your account is something Facebook could reasonably be reengineered to do.
“Consent or delete your account” doesn't seem all that far from the choices Facebook practically has under the GDPR.