Indeed. People need to learn how to use their apps. The new Android allows you to block most features.
One of the best security features you can use is to access FB not from the mobile app (DELETE IT! and for smart's sake DONT HAVE IT ON YOUR HOBBY PHONE - caps for emphasis
).
Use your phone's browser if you want to use FB, you will avoid all of the app permissions. Takes a second longer, but you'll avoid the mobile app, which has things that render it unusable if you want to be secure.
Some folks also recommend an app called TINFOIL to mask a lot of FB settings, I don't use it myself, but you might check it out.
BTW, I have a lot of friends in IT security, and the most vulnerable aspect of any system is the USER, and using devices for private exchanges that they are wholly ignorant and uneducated about using. There are lots of resources to familiarize yourself with basic security on the net. I'll post some good ones when I have the time.
or.... ask Google