Earlier quoted context omitted.
If I authorize an app to scrape an entire album, that’s a good thing. This isn’t more security, this is google attempting to squeeze more monetization.
Sure, but what if you want to let an app have a single picture of you for a profile pic, but the only permission you can grant is "can view all of my photos", and then the app uploads all of your photos to their server?
How is this relevant? Wouldn’t you just grant access to the single photo? Or just create an album with a single photo?
The existing functionality was sufficient. This new functionality does not improve security.