To me, this demonstrates that had Wes not reported the AWS keys, then Facebook would never have rotated them. I would argue that the fact Facebook found need to take action to resolve Wes' third vulnerability submission, could be considered an admission to its legitimacy as a bug. Therefore concluding that the bug is indeed worthy of a bounty.
Not Valid After: Thursday, 31 December 2015 11:00:00 pm Australian Eastern Daylight Time
Maybe they'll upgrade it to something better than: Signature algorithm SHA1withRSA WEAK
It doesn't explain why Instagram has been happily using a known-compromised wildcard ssl key for two weeks now.
Makes you wonder who actually values and protects Instagram's user privacy more - the researcher or the Facebook CSO...
No, I don't wonder about this at all.
What a coincidence...
Instead, he sat on the keys for over a month, and in the meantime used them to download everything he could find onto his personal computer. Simply testing that the keys were live and disclosing this immediately would have been more than enough proof of a bug here.
Edit: downvoters - please explain how using keys to access production systems for over a month without disclosing is acceptable white-hat behavior?