So now, I leave you with this. Facebook has not disabled the IE8 XSS Filter. As a result, you can create a non-malicious link which invokes the XSS protection in IE8. This causes the resulting page to be significantly distorted.
data:image/s3,"s3://crabby-images/16d17/16d17f49c397bd0572881adcde4d77eae8abd96d" alt=""
This page is the result of visiting the link (shown below) as an authenticated user. To be clear, this is not a FaceBook design flaw. This is simply IE8 modifying the response within your browser to attempt to protect you against the benign search value of "IE8%3Cscript%3E"
http://www.facebook.com/search/?ref=search&q=IE8%3Cscript%3E&init=quick
-Michael Coates