Comment Re:How is this different (Score 1) 142
There is one major error that I haven't seen anyone point out yet.
In the general sense, XMLHttpRequest does not introduce XSS risks: you can't make off-domain requests with XHR.
"It is better to have tried and failed than to have failed to try, but the result's the same." - Mike Dennison