I am surprised this is standard behavior. So if I allow user X to see my photos it means that user has a right to publish all my photo urls. It doesn't look good to me.
It's different because in this case if someone dumps all your photo links Facebook can in theory just assign them new random secret IDs, whereas if someone uploads your photos to a hosting site there's nothing they can do about it. In other words, from a security perspective, it is in no way worse.
Comments
I am surprised this is standard behavior. So if I allow user X to see my photos it means that user has a right to publish all my photo urls. It doesn't look good to me.
How is that any different from being able to save the photo as a file and upload it to a free image hosting site? From a security point of view?
Since it can be easily circumvented anyway, disallowing sharing static photo URLs would be the real "pseudo security", in my opinion.
It's different because in this case if someone dumps all your photo links Facebook can in theory just assign them new random secret IDs, whereas if someone uploads your photos to a hosting site there's nothing they can do about it. In other words, from a security perspective, it is in no way worse.
Clearly this is something that that makes this issue even more dangerous.