In my opinion this should be looked at as a learning experience for web developers. We need to take these issues/exploits into account when building websites. I'm pretty sure PG accounts for XSS attacking, no? If we trust each, shouldn't we trust each other enough not to post malicious code? Unfortunately it just doesn't work like that. Security by obscurity is never the answer!
This was a CSRF attack, which is mostly unrelated to XSS.
This is not how the community functions however. The community functions by being made up of a group of people who believe in courtesy. It is not vulnerable to any sort of software hack, instead it is vulnerable to the slow drift towards thoughtlessness.
The lack of trust is not trusting the community not to abuse an explained hack, and the whole is made dumb by the fact that anyone can figure out the hack for themselves even if it wasn't explained to them.
Sharing the trick is entirely reasonable: small hacks like this are something to be proud of, given that you've acted in a reasonable way (e.g. contacted the site and informed them before telling others, not actually using it game the system, etc.)
Could have gone that way. Didn't.
Maybe they thought that if they wanted to, they can do better, but they never did.
It doesn't really involve anyone else.
I'm sick of security. I wish we could make things without worrying about the myriad ways there are to destroy a thing?
What did xach have to gain by doing this experiment that he would have lost by emailing PG quietly, beyond the childish feeling of destroying a good thing?
He did say it wasn't cool - which is a fact.
What xach did wasn't cool, although perhaps inevitable on a public site.
Obviously that's not the definition we use here. If you haven't figured that out by now, perhaps this isn't the place for you.
God forbid anybody here should have a sense of irony.