I came across these articles that says usernames and passwords do not necessarily mean privacy thanks to Google's cache system. If you have the knowledge, these private areas are easy to hack. I'm wondering how bbpress's privacy plugin stacks up against this hacking.
http://hackforums.net/showthread.php?tid=25040
http://www.theregister.co.uk/2008/08/22/accessing_restricted_sites/
On a slightly related issue:
I have noticed that ALL profiles in any forum are public. If you keep sequencing then, you can see each person's profile, which means even the spammers that are blocked can still be viewed with their websites, emails, and interests. This unintended promotion bothers me. If I start deleting the spammers profiles, I will just have a lot of work to do. The perfect world is that profiles that are approved should be the only ones available by sequencing.
ie.
http://www.example.com/forums/profile/1042