A wireless network is essentially a hub, rather than a switched network, and as such all hosts on one leg of the network get to see all the packets transported through it no matter what their source or destination and it is up to your network card and/or OS to filter out those that are relevant to it. In a switched arrangement (which all modern wired networks are) by contrast, the switch is bright enough to only send your NIC ethernet frames that are addressed to it.
Even if the network is passkey protected this does not stop all hosts seeing all the packets: the password and encryption are only for authentication and protecting the network from the outside, it offers no protection from other nodes on the same network leg once you have joined.
So an attack like firesheep doesn't need to inject anything pretending to be from the target node to get facebook to send it the session token - it simply sets the network interface to "promiscuous mode" so that it can see all the packets and not just those addressed to your machine. It then sifts through those packets looking for HTTP headers containing cookies destined for facebook, and reads the session token from them. Once you have that token you can make HTTP requests to facebook as if your browser is the one that opened that session, so you can post as that user and read all their stuff without knowing their password. The same goes for any other service operating over plain HTTP.
The only way around this with current wireless protocols is to use a secure transport for your communications. SSL based protocols, like HTTPS for instance, would protect the content of the communication from such inspection. The same goes for SSH, SFTP, IMAPS, and so forth. For facebook specifically you can switch on the "always user HTTPS" security option to protect yourself if using a web browser to access the service, but be aware that neither the iPhone or Android applications currently respect this setting.
If I ever connect my netbook to a public wireless network I always run all communication through an OpenVPN setup that I have - this way all packets travelling in and out of my machine are encrypted in a way that protects them from inspection by other hosts on the same access point, even if the packets themselves are not protected (by being part of an HTTPS stream for instance). This probably isn't an option for the non-technical man-on-the-street, nor does it currently protect streams direct from my phone (though I'm told OpenVPN can be made to work on Andriod, I have yet to try) if I ever let it connect to a public wireless access point, so isn't a perfect solution.