they just haven't even done anything novel. Why should we expect them to now? Facebook is very unlikely to have the usual slough of easy sql injections.
I am quite sure that someone good could find attacks against facebook. I am dubious that anonymous can.
There are many levels of intrusion. I give Anon enough credit that they might be able to cause some mayhem, maybe even some real harm. Maybe they'll take down Facebook Chat (to the great ambivalence of everyone)... but to 0wn/DDoS the main Facebook site altogether? I dunno...
It's like, I may be able to find some way to force all the toilets at CIA Headquarters to back up. That's not the same thing as compromising their spies' identities. Not all exploits are equal.
I am aware of what "attack surface" means and stand by my claim that anonymous, having done nothing novel so far, will not find attacks against facebook.