If I try to force it as an applet on a 3rd party site:
<embed type="java" src="http://facebook.com/profiles/12345/evil_applet.jpg">
The java plugin should refuse to load it since it doesn't have a java mimetype. I'm guessing from the article that the java plugin will load it anyway, which I believe is a bug in the java plugin.
I don't think the websites should have to try to filter beyond verifying that it's a valid image file. Besides the fact that re-encoding jpg images reduces their quality, it is conceivable that it won't even solve the problem.
In a perfect world, the java plugin would not have this bug, but in the real world it might not be a bad idea for websites to try to filter out this specific attack in order to pretect their users.