In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the find and even make money with bug-bounty payouts: http://www.facebook.com/whitehat/.
For what it's worth, a few people were alluding to this meaning that we don't check privacy by default. In fact we do have a pretty robust default-deny system for running privacy checks. This was an edge case where it was forced to work in a way that was incorrect.
(I work at Facebook, but not on this system.)