IIRC, he was responsible about the hole by telling the company first and trying to work with them to get it fixed. He released the info after they were unresponsive. I think that's proper way to handle that.
But this thing with Yahoo isn't really the same. One is a security breach while the other is trying to abuse a service.
I like hacks and fun experiments. The idea of putting extra content in pictures is interesting but OP was talking about setting up a system around it to put it into wide spread use.