If a URL responds to any unauthorized HTTP request with data, how is the requester supposed to know that the data they received is supposed to be private or sensitive?
A better (more accurate) analogy than finding an open window/door is that of asking a government employee for data.
Kid: "Hi, what is the personal info in that file?"
Employee:
What they should say: "You are not authorised to see the contents of that file."
What they actually said: "Sure, here's all the information in that file."