I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".
Easy. The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements. The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.…
Facebook's would most probably not call it off. Or just resurface the same thing at another time with another name or excuse.