No it is not in different situation. If I tell you your social security number is now accidentally written in your HTML file (probably because you copied and pasted the wrong thing), and now I tell the world "hey come look at sneak's SSN" instead of waiting for you to resolve is wrong.
Now back to this gist.
Is he responsible? It depends on how the situation was played out.
Based on what OP said:
* He found this 216 days ago and wrote about it as a comment on HN
* He didn't say whether he reported that day but he recalled Instagram was making HTTP request a year prior to that day he wrote the comment
* He didn't tell us when he report this issue to FB. Yesterday? Last week?
* FB said they are aware of this situation and closed the ticket. Like someone else said here, "closing" has different meanings. I've never reported any vuln to FB so I don't know how that works. But on HackOne, particpating program can close a ticket and set the ticket to "Not Applicable" meaning someone else has already reported.
So the decision factor is:
* when was the first report submitted by OP? Yesterday? Last week? 3 months ago? 216 days ago?
* if it was very recent, OP doesn't know the exact time the last duplicate report was sent out. Give FB a little more time and ask FB again in a week or so.
I did say in my other comment fixing this issue should be pretty trivia for Instagram as an outsider, but I also should acknowledge any major change to infrastructure should have a proper audit and roll out.
edit:
One last point. If OP thinks he's doing the right thing, let it be. There are too many things unknown to me so I am just listing all the possible consideration. I have tons of bug bounty reports unfixed for 3 months on various sites and I still email those sec teams back and forth to look at progress. It's an individual decision and with every decision comes a consequence to bear.
> If I tell you your social security number is now accidentally written in your HTML file (probably because you copied and pasted the wrong thing), and now I tell the world "hey come look at sneak's SSN" instead of waiting for you to resolve is wrong.
No, sharing links to published data on the public, unauthenticated web is not wrong.
People accidentally leak password in source code. Instead of telling HN everyone come look at this embarrassing source code, first thing to do is to contact source owner to remove it. Yes, there is cache and Internet archive, but don't publish that until resolved is the proper interpretation of responsible disclosure.
STOP USING THE TERM RESPONSIBLE DISCLOSURE. It serves only to frame full, public disclosure as "irresponsible disclosure", which is false.