Earlier quoted context omitted.
I think it's a stretch to call this "just" a mistake. First of all, there isn't any malicious code that has to be run to execute it, it's a simple as clicking a few buttons in the UI. Secondly, Facebook is a site with hundreds of millions of users managing billions of private photos. With the amount of revenue & number of developers they have, it's inexcusable that they can't think through a simple process like this…
I'm downvoting you for saying I think it's a stretch to call this a mistake If it wasn't on purpose, it was a mistake. Period. It might be inexcusable, as you later pointed out, but it was still unintentional. Everyone likes to hate on Facebook. If this was a YC startup, I suspect people would be more forgiving.
Evidence to the contrary: the Dropbox security fiasco (which sounded worse but was resolved in hours with claims of no malicious activity) prompted several HN entries. HNers aren't so biased as to be blind to inexcusable negligence (esp. because a large majority of us are users of those services and have personal stake.)
Facebook has a history of such "mistakes", a founder who thinks FB users are "dumb fucks" (and has reportedly maliciously used FB's password log), and all the motive in the world to be "negligent" as it's a way they can make money (as long as we don't find out).
The foolish thing to do is to assume this is still a mistake after repeated history of such "mistakes".