This comment seems to argue that this was intentional.
For a company of FBs size and personal data contents, I agree, they have a rather scary track record. But saying <symptom of X> implies <X> is fallacious, especially when it's also a symptom of <AAA> through <ZZZ>.
What one does this fall into?
At some point a developer coded in a resource that bypasses any privacy data, had it approved by management/coworkers (not sure what model they use) and published it live. I'm certain many people have been exploiting this longer than that forum post existed.
Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this without considering what happens if two users aren't friends.
Granted, they're probably not "trying" to undermine privacy. But they're doing a very poor job at maintaining it.
If it wasn't on purpose, it was a mistake. Period.
It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
I think the problem is that calling it a mistake downplays the issue. I'd say this is grave negligence, because besides the feature itself, it shows a lack of access control systems.
It was a mistake, but another word for a mistake is 'negligence'. The fact that something like this can happen illustrates systemic shortcomings at the company. Millions of people are depending on them to enforce the privacy restrictions Facebook claims to enforce. Facebook encourages you to store highly personal data, and as such, they have a responsibility to be more careful. Facebook prides themselves on constantly pushing changes to their software. More safeguards, testing, and perhaps slowing down the software development cycle a little would not be a bad idea.
No it isn't.
'a mistake' puts this at the same level of seriousness as other problems. This is at least a big mistake.
Evidence to the contrary: the Dropbox security fiasco (which sounded worse but was resolved in hours with claims of no malicious activity) prompted several HN entries. HNers aren't so biased as to be blind to inexcusable negligence (esp. because a large majority of us are users of those services and have personal stake.)
Facebook has a history of such "mistakes", a founder who thinks FB users are "dumb fucks" (and has reportedly maliciously used FB's password log), and all the motive in the world to be "negligent" as it's a way they can make money (as long as we don't find out).
The foolish thing to do is to assume this is still a mistake after repeated history of such "mistakes".