I think one of the reasons the URLs are like that is that Plex does not yet do SSL by default thus ALL of your specific movie activity would be encrypted and easy to guess.
Moot point, as auth tokens/cookies are currently sent along with the URL.
Not a moot point, since the suggested url is easily guessable, where the current is not. Sure they can both be harvested and reused, but only one of them is open to extrapolating more valid urls from a single capture or worse, a port/service scan.
That said, the current (in)security of PMS troubles me.