In this particular case, the bit about IDS isn't that ground breaking, it's just that the IDS checks for the malformed heartbeat request at the start of a packet, so instead he sends it at the end of a packet, namely appending it to the SSL handshake request. It's not like any hacker ever won't figure it out. I do agree with responsible disclosure for actual security holes, but this isn't it.