Changing the main folder name is a good start, imho.
IF:
The filesystem "/albumsXXXX/" path isn't revealed in the frontend source code anywhere, either image caching for preview images is enabled or not?
EDIT:
Is it revealed when "Download" image protection is chosen and somebody downloads the image or would someone need to packet sniff the request to know the source?
>>Zenphoto is file system based and therefore the url mirrors the structure.
So the only real way to deny public access to the images would be a .htaccess deny directive for all album folders?
Hotlinking is not the problem and should be allowed if somebody has a link that can't be guessed by simple logic to guess other files in the album.
Thanks for your quick reply!