Most web mail applications use the mail address as login, so they have the same security problem.
First name and other profile fields were added afaik later and are now used to display the profile/vcard. So using the user name in the url was and is much better than using the userid. Directly accessing the profile page is very easy using the name - and users prefer not to be a number.
I wonder why users choose the same username and email address - maybe one should disallow @ within the name.
thx for your response. I agree that using the name in profile url is fine and better then a number, but the use of the username (which is also used for login) in the profile url is something I don't prefer because of security and privacy reasons. Because everybody within the community can see the username of persons they don't know..