Earlier quoted context omitted.
Not sure I'm comfortable with full disclosure as I still consider it potentially harmful (phishing mostly, or sending unsolicited emails without knowing the fb login email of a user) Maybe I should try to report it again on Hackerone, as this was reported through the old whitehat program and the guy who answered never fully addressed the issue or replied to my follow up
Sunlight it, if they won't change it. Bad publicity and bad behavior from other actors will only increase the likelihood that the bug gets fixed. If a company won't listen you've done your moral duty. The last step of responsible disclosure is publication. As a bonus, you'll probably even frontpage HN.
Plus he has given lot of pointers so it's a matter of time someone find the comment and start trial-and-error to discover how to exploit the bug.