It may be partly informed by 1) If anyone sees a photo, they can redistribute it regardless of what our restrictions are serverside, so might as well not give users unreasonable expectations. 2) We really WANT people to share photos. That's basically what Facebook's core interaction is. 3) Implementing this additional security does not increase any metric which Facebook cares about. 4) Users occasionally rely on this feature to post pictures which they host on Facebook to other sites on the Internet, which we want to support, because it means they post photos on Facebook.
It's pretty standard practice. For example, Gmail does something very similar for attachments.
What are you referring to here?
It is undeniably possible, but the cost (money, performance) is so extreme and the benefits so small (the edge case of people sharing confidential things by copying file URLs when they are always going to be able to take a screenshot in an undetectable and sharable way)... that it just does not come out as a thing worth doing.
Then when one considers that the faster you can make file serving and the UX of the web site and app, the more responsive and higher the engagement... which means increased likelihood to click adverts too.
So you have a huge cost, with little benefit, vs a drop in speed and potential impact to advert revenue.
No reasonable company is going to say that this should be done unless there is an overwhelming business reason to do so (i.e. you are Box and storing company secrets and the liability of leaking them is extreme).