Thats correct, but its gonna be very easy for anyone to serp spam any popular website by just putting up backlinks all over the internet, if there issnt a canonical or a noindex tag, it will index for sure.
SH404sef is a good solution to fix this, as it redirects to the main (but there are a few bugs with your sef_ext files, making it hard to acheive proper URLs, and i dont think its gonna be fixed in next 2 years or so). Ideally, since there is an option for permalink check there shouldnt be any id, or if its an ID, (like fb initial reg) it should be ID only no username, and it shouldnt be a wildcard url kind of a thing.