I'm not foolish enough to imagine that this is anything other than a blip for them - their first mover momentum and market dominance is invincible for the time being, but they don't deserve it if they keep putting users at risk as casually as they seem to be. So far, we've seen nothing too nasty (though this could be embarrassing I suppose), but it's a bad sign looking ahead.
Also, sure, every webserver could proxy the requests—but then you have to guarantee that you haven't created an open proxy, which is a much worse hole than a simple CSRF—and then you have to do some more server-side configuration every time you want to enable your views to touch a new third-party API—which excludes a lot of hosted sites, like blogs, from using any API that their server admin hasn't considered.