REST lesson learned: Avoid hackable URLs
blog.ploeh.dk
blog.ploeh.dk
Switching to opaque, meaningless strings for your URLs does not solve your problem. URLs leak, they risk being recorded and published (e.g. Referer: headers on weblogs), and so people will find them anyway.
You still need access controls and all you have achieved by making your URLs complicated is to create more work for you and your users.