Facebook will lose way more logins from shoving more and more sponsored spam in the news feed then they will by a few milliseconds in latency from SSL.
I'll be using this in the morning to easily log into all my gmail accounts from work. When I leave work I have a logoff script that clears all my cookies. This logs me into all gmail accounts that I am logged into on my phone without having to log in several times.
Facebook API had so many breaking changes happening all the time that they decided, as a "benefit" to developers, that they would stack them all up to occur on the first of each month. This is in the name of BS called "operation developer love". And this is only for the breaking changes that get announced. The much more common scenario that ComputerGuru mentions is where stuff gets broken, acknowledged as a bug Facebook, and then never fixed. If you read the stats they publish in their blog posts, 2-3x the number of bugs get accepted than the number that get fixed, EVERY SINGLE week.
I've seen a study that shows this isn't true, especially when prompting for offline_acces. Wish I could find the link. Also, Facebook's app analytics shows you the break down of how often permissions are rejected and from what I've seen with high usage, the permissions prompted did matter. I would disagree that you should just ask for ones you might not need, especially since you can always prompt the user later for more if needed.
Facebook API does have a method where you can revoke the permission automatically (ie when you no longer need it). And also if you don't request offline_access permission, the token is only valid for an hour or two. But yes, Facebook doesn't make this very clear to the user.
The benefit is SO gets more traffic and users. Facebook benefits by off loading the management of their messy forums and rely on free crowd sourced moderation.
So Dropbox security is based on a code obfuscator? And was it an intern that let us log into any dropbox account with any password? Kidding, but seriously, they need to get more interns because one of the most requested feature for years on their site is remote wipe (https://www.dropbox.com/votebox/35/remote-destroy-purge-opti...) and they never implement it. Granted its not an entirely reliable method but its better than not offering it.
Not sure I see the point of the Email Protection app. If you care for a product like this, you would enable 2 step verification and then there is significantly less chance of this being needed.
Impossible to avoid? Not if they give an easy option to disable it which nearly every person took advantage of with Google Buzz. And people certainly will if Google enables people to connect to their accounts to Twitter, FB, LinkedIn and it is just another site filled with duplicate content like Buzz was.
It will be interesting to see if Facebook clones every single Google+ feature before Google+ is out of invite-only status. I'm guessing next will be a basic rich text status editor, to go along with the already announced video conferencing.