Earlier quoted context omitted.
Apps usually request that stuff for some reason, and the vast majority of users don't have enough understanding of the systems to know which permissions are safe to revoke. Breaking the app is the point of doing this. It's often not clear that, say, a FB app will post, as the user, to their own stream. I think most people don't want this, and want the app to break if it tries. You're thinking of "safety" from the per…
You're absolutely right - the point is to break the app. This is great if the user breaks the apps in exactly the ways they want, but my point is that users rarely understand the scope of the app, and may (and likely will) end up revoking permissions that break functionality they want. For example. I sign up with Foobar's Widgets with my Facebook account, and manually deny the "publish_stream" permission, because I j…
I use exactly zero FB apps primarily because I have no trust in the FB sharing model, and I don't want to spend time grooming individual permissions per app.
I also suspect that we have different notions of "abusive behavior." You're probably thinking of outright scammers. I'm thinking of overzealous developers who think their gizmo is so awesome that of course most people would want to shout about it from the hilltops.