I think one of the reasons people (including me) have problems with penalizing GET parameter change is that they are obviously visible and trivial to change. They are a part of URL and pretty much designed to be modified by hand. Growing up on the Internet we learned that if we want to see e.g. the next page of the gallery or board, we don't have to look for "next" button. We just change /0/ to /1/, or ?start=100 to ?start=150 in the address bar and press ENTER. It's easier. It's quicker. It's more natural. I can't feel that there's anything wrong with changing a GET parameter. It doesn't register on an emotional level.
My personal feelings are that on the Internet you're supposed to use HTTP codes like 403 or 404 to mark places user is denied to access. IMO the space of legally accessible addresses for given user should be defined by a superspace of all URLs that return 200 Ok when that user tries to access them. If you screw up and serve sensitive data without proper access check, it should be your (legal) responsibility, not the person's who (accidentally or not) discovers this.