So now, I leave you with this. Facebook has not disabled the IE8 XSS Filter. As a result, you can create a non-malicious link which invokes the XSS protection in IE8. This causes the resulting page to be significantly distorted.

This page is the result of visiting the link (shown below) as an authenticated user. To be clear, this is not a FaceBook design flaw. This is simply IE8 modifying the response within your browser to attempt to protect you against the benign search value of "IE8%3Cscript%3E"
http://www.facebook.com/search/?ref=search&q=IE8%3Cscript%3E&init=quick
-Michael Coates