Facebook actually does a decent job of filtering obvious spam. They don't catch everything, but they have the ability to check comments across sites.. so if a user posts the same (or almost same) comment to 20 different sites, they have the ability to flag that. So, while very site-specific spam can get through, more generic stuff is usually eliminated before you even see it.
We're planning to use the callback for comments in one of our updates. Lots we can do with that. Again.. we're going to be focusing on comments and other social integration a bit over the next few releases. 3.2 will lay some good groundwork, but won't have all the features someone would want.. but hopefully will have something. Then, with feedback, we'll continue to refine things for 3.3, 3.4, etc.