I suppose I didn't articulate that point correctly. Facebook has a policy that basically says "if you find an exploit don't do it to real people, use a test account to reproduce it". So regardless of whether it's the CEO or Jane Doe, it sets a bad precedence that reproducing the exploit in a (real) environment is a very dangerous thing.