If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…
1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides s…
Not paying someone over minor violations that they only did to get your attention to the fact that something was definitely important to you is not good practice when running a bounty for bugs.