The Web’s Most Sacred Rule Just Got Broken for a Social Network

You’ve probably noticed that the internet feels like a stable, unbreakable thing. It’s not. The entire internet is held together by a fragile social contract, and we just watched someone exploit it for a tweet.

Meet GET Together. It’s a social network with one terrifying twist: you don’t use a POST request to post. You use GET.

For the non-developers out there, the web runs on HTTP methods. GET means “retrieve.” POST means “create or change.” It’s a foundational rule of RESTful architecture, an unspoken law of the web. GET is supposed to be safe. Clicking a GET link shouldn’t change the world. When you use a read-only tool to write, you don’t just break the rules—you turn every caching server on the planet into your personal botnet.

By subverting this core constraint, GET Together does something both hilarious and dangerous: it weaponizes the web’s caching layer.

Think about it. If posting is just a GET request, what happens when a CDN like Cloudflare caches that URL? What happens when a search engine crawler tries to index your timeline? It accidentally posts. As one Hacker News commenter immediately pointed out: “Don’t let OpenAI find out about this.” An AI crawler just trying to read the page would inadvertently spam it with duplicate content.

This isn’t just a quirky social network; it’s a structural exploit. It bypasses traditional server-side write-rate limiting by offloading the distribution of user-generated content directly into the browsers and proxies of the users themselves. It weaponizes the implicit trust we put in HTTP verbs.

It appeals to that nostalgic, hacker-esque thrill of breaking fundamental web standards just to see if it works. We’ve spent decades building abstraction layers to protect the web from itself, assuming everyone would play by the rules. We built the web on rules we thought were laws. It turns out they were just suggestions waiting to be ignored.

GET Together might be a gimmick, but it’s a glaring reminder. The protocols we take for granted are merely social contracts. And when someone inevitably breaks them, the infrastructure we rely on can be subverted for novel functionality—or catastrophic caching failures.

FAQ

Q: What happens when a search engine crawler hits this site?

A: It accidentally spams the platform with duplicate posts. Googlebot becomes a spam bot because it's just fetching URLs, turning a read operation into an unintended write operation.

Q: What's the actual implication for web developers?

A: It proves that relying strictly on HTTP verbs for security or rate-limiting is a fatal flaw. Your caching layer can be weaponized against you if you assume GET is always a safe, idempotent retrieval action.

Q: Is this a clever hack or just bad engineering?

A: It's terrible engineering, which is exactly what makes it brilliant. It exposes the fragility of our assumed web standards in a way a textbook never could.

📎 Source: View Source