Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
:Facebook can change, juggle, and ignore your privacy whenever they want to do whatever it is they want to do, but you can't even if it is to help them. So when he found a bug that would be a spammers dream then sell it to the spammers cause they would pay millions where Facebook will dick you out of 500$: