It's more that if literally any other site on the internet were found to have any type of CSRF vulnerability, people here would be going on and on and on about how this is web dev 101, only a complete idiot wouldn't know about/secure against CSRF attacks, etc.
Whereas here, when it's HN with a CSRF issue, "eh, it would break some third-party clients if we patched this".
Tell me more about this world in which HN's users shield its developers from criticism.
We fixed the reported vulnerability and have a fix for the remaining issue ready if it's needed. There's no "eh" here; it's a question of what the right tradeoff is.