Earlier quoted context omitted.
facebook's communication skills were not stellar either ('this is not a bug'). If you are taking reports from users about security problems, treat every one as real until proven otherwise.
If you get over 90% fail rate? If you say you will pay 500Bucks per Bug reported, you will have a huge Fail rate, even if the Facebook Support is well Motivated after 3hours working, answering to 100Tickets you might not be able to understand something written in that way: "Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success…
a) it's called triage and b) you won't want to miss that one report that blows your security wide open.
The point is moot now, facebook says they took note and will ask for more details from now on.