So how does this work? Does hnbutton.appspot.com do some clever proxying, or something? Or does HN just have a very easily exploitable XSRF vulnerability?
[0] https://bountify.co/blog/host-your-own-hacker-news-button-se...
EDIT: This is a submission from a while ago that does, in fact, upvote itself.