Comment Re:Does this actually say anything? (Score 1) 143
XSS is done on the target site.
CSRF is done on a different site.
Real Users find the one combination of bizarre input values that shuts down the system for days.